{
    "1891703": [
        {
            "ioc_value": "172.94.111.195:2404",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-08-31 08:15:10",
            "last_seen_utc": null,
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://bazaar.abuse.ch/sample/be592d36972e47ba32ba4a1cd82e2450249fd07e0752289c844e61c6dc568715/",
            "tags": "RAT,RemcosRAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1891700": [
        {
            "ioc_value": "swewart.sbs",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.kongtuke",
            "malware_alias": "TAG-124,js.LandUpdate808",
            "malware_printable": "KongTuke",
            "first_seen_utc": "2026-08-31 08:13:14",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "KongTuke",
            "anonymous": 0,
            "reporter": "monitorsg"
        }
    ],
    "1891701": [
        {
            "ioc_value": "https://swewart.sbs/api/v1/session",
            "ioc_type": "url",
            "threat_type": "payload_delivery",
            "malware": "js.kongtuke",
            "malware_alias": "TAG-124,js.LandUpdate808",
            "malware_printable": "KongTuke",
            "first_seen_utc": "2026-08-31 08:13:14",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "KongTuke",
            "anonymous": 0,
            "reporter": "monitorsg"
        }
    ],
    "1891702": [
        {
            "ioc_value": "https://swewart.sbs/api/v1/verify",
            "ioc_type": "url",
            "threat_type": "payload_delivery",
            "malware": "js.kongtuke",
            "malware_alias": "TAG-124,js.LandUpdate808",
            "malware_printable": "KongTuke",
            "first_seen_utc": "2026-08-31 08:13:13",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "KongTuke",
            "anonymous": 0,
            "reporter": "monitorsg"
        }
    ],
    "1891699": [
        {
            "ioc_value": "ira240.workers.dev",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "php.shin_webshell",
            "malware_alias": null,
            "malware_printable": "php.shin_webshell",
            "first_seen_utc": "2026-08-31 08:08:07",
            "last_seen_utc": null,
            "confidence_level": 50,
            "is_compromised": true,
            "reference": null,
            "tags": "Cloudflare,GIF,PHP,webshell,WordPress,workers.dev,wp-admin",
            "anonymous": 0,
            "reporter": "xscon"
        }
    ],
    "1891696": [
        {
            "ioc_value": "31.76.102.46:8081",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.havoc",
            "malware_alias": "Havokiz",
            "malware_printable": "Havoc",
            "first_seen_utc": "2026-08-31 08:05:05",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "havoc",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1891697": [
        {
            "ioc_value": "31.76.102.46:22",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.havoc",
            "malware_alias": "Havokiz",
            "malware_printable": "Havoc",
            "first_seen_utc": "2026-08-31 08:05:05",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "havoc",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1891698": [
        {
            "ioc_value": "1.117.77.166:888",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-08-31 08:05:05",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "supershell",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1891695": [
        {
            "ioc_value": "91.92.43.15:4444",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-08-31 07:55:06",
            "last_seen_utc": null,
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://bazaar.abuse.ch/sample/ba5b5e1cedf641a8c3281e631a2034b5e4ab4f0153dafead21d76164ed717d5b/",
            "tags": null,
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1891694": [
        {
            "ioc_value": "xiviju.workers.dev",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "php.shin_webshell",
            "malware_alias": null,
            "malware_printable": "php.shin_webshell",
            "first_seen_utc": "2026-08-31 07:52:56",
            "last_seen_utc": null,
            "confidence_level": 50,
            "is_compromised": true,
            "reference": null,
            "tags": "Cloudflare,GIF,PHP,webshell,WordPress,workers.dev,wp-admin",
            "anonymous": 0,
            "reporter": "xscon"
        }
    ],
    "1891518": [
        {
            "ioc_value": "pnd.onlineturbo88.top",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-08-31 07:47:16",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://x.com/orlof_v/status/2094133947362091245?s=20",
            "tags": "Validin,Vidar",
            "anonymous": 0,
            "reporter": "orlof_v"
        }
    ],
    "1891519": [
        {
            "ioc_value": "nsn.12naga.org",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-08-31 07:47:15",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://x.com/orlof_v/status/2094133947362091245?s=20",
            "tags": "Validin,Vidar",
            "anonymous": 0,
            "reporter": "orlof_v"
        }
    ],
    "1891520": [
        {
            "ioc_value": "ley.123ful.net",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-08-31 07:47:14",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://x.com/orlof_v/status/2094133947362091245?s=20",
            "tags": "Validin,Vidar",
            "anonymous": 0,
            "reporter": "orlof_v"
        }
    ],
    "1891521": [
        {
            "ioc_value": "chi.12naga.org",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-08-31 07:47:13",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://x.com/orlof_v/status/2094133947362091245?s=20",
            "tags": "Validin,Vidar",
            "anonymous": 0,
            "reporter": "orlof_v"
        }
    ],
    "1891524": [
        {
            "ioc_value": "104.248.41.207:34567",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.aisuru",
            "malware_alias": null,
            "malware_printable": "Aisuru",
            "first_seen_utc": "2026-08-31 07:47:10",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "Aisuru,c2",
            "anonymous": 0,
            "reporter": "Bitsight"
        }
    ],
    "1891548": [
        {
            "ioc_value": "167.99.128.245:8080",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.aisuru",
            "malware_alias": null,
            "malware_printable": "Aisuru",
            "first_seen_utc": "2026-08-31 07:47:09",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "Aisuru,c2",
            "anonymous": 0,
            "reporter": "Bitsight"
        }
    ],
    "1891567": [
        {
            "ioc_value": "https://91.98.236.89",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-08-31 07:47:08",
            "last_seen_utc": "2026-08-31 08:11:53",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "9fe37432b96b1f873dc66a38a261ef70,c2,loader,stealer,Vidar",
            "anonymous": 0,
            "reporter": "Bitsight"
        }
    ],
    "1891577": [
        {
            "ioc_value": "192.159.99.121:2580",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-08-31 07:47:07",
            "last_seen_utc": "2026-08-31 07:24:02",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "@,c2,Remcos",
            "anonymous": 0,
            "reporter": "Bitsight"
        }
    ],
    "1891579": [
        {
            "ioc_value": "192.159.99.121:25800",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-08-31 07:47:07",
            "last_seen_utc": "2026-08-31 07:27:04",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "@,c2,Remcos",
            "anonymous": 0,
            "reporter": "Bitsight"
        }
    ],
    "1891583": [
        {
            "ioc_value": "https://95.217.223.130",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-08-31 07:47:06",
            "last_seen_utc": "2026-08-31 08:10:14",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "8e3a74868d6a5ab24c7948fba102cc52,c2,loader,stealer,Vidar",
            "anonymous": 0,
            "reporter": "Bitsight"
        }
    ],
    "1891599": [
        {
            "ioc_value": "131.226.2.95:4920",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-08-31 07:47:03",
            "last_seen_utc": "2026-08-31 04:12:45",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "c2,Remcos,RemoteHost",
            "anonymous": 0,
            "reporter": "Bitsight"
        }
    ],
    "1891609": [
        {
            "ioc_value": "174.138.30.59:8080",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.aisuru",
            "malware_alias": null,
            "malware_printable": "Aisuru",
            "first_seen_utc": "2026-08-31 07:47:02",
            "last_seen_utc": "2026-08-31 03:41:22",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "Aisuru,c2",
            "anonymous": 0,
            "reporter": "Bitsight"
        }
    ],
    "1891619": [
        {
            "ioc_value": "https://46.224.87.76",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-08-31 07:47:01",
            "last_seen_utc": "2026-08-31 08:10:36",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "37a059228277b5942abd0dd5db874fd2,c2,loader,stealer,Vidar",
            "anonymous": 0,
            "reporter": "Bitsight"
        }
    ],
    "1891621": [
        {
            "ioc_value": "https://jre.12naga.org",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-08-31 07:47:00",
            "last_seen_utc": "2026-08-31 08:13:05",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "0760b4f10cfeaeccbae17783b4b59360,c2,loader,stealer,Vidar",
            "anonymous": 0,
            "reporter": "Bitsight"
        }
    ],
    "1891622": [
        {
            "ioc_value": "196.251.121.183:4433",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-08-31 07:46:59",
            "last_seen_utc": null,
            "confidence_level": 50,
            "is_compromised": false,
            "reference": null,
            "tags": "18811,c2,censys,cobalt strike",
            "anonymous": 0,
            "reporter": "sojubear"
        }
    ],
    "1891626": [
        {
            "ioc_value": "216.203.20.232:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-08-31 07:46:59",
            "last_seen_utc": null,
            "confidence_level": 50,
            "is_compromised": false,
            "reference": null,
            "tags": "1828,c2,censys,cobalt strike",
            "anonymous": 0,
            "reporter": "sojubear"
        }
    ],
    "1891647": [
        {
            "ioc_value": "167.99.194.254:9034",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.aisuru",
            "malware_alias": null,
            "malware_printable": "Aisuru",
            "first_seen_utc": "2026-08-31 07:46:58",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "Aisuru,c2",
            "anonymous": 0,
            "reporter": "Bitsight"
        }
    ],
    "1891660": [
        {
            "ioc_value": "163.245.199.241:2404",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-08-31 07:46:57",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "c2,NzQ1NzI2ODI5NzM5Mw==,Remcos",
            "anonymous": 0,
            "reporter": "Bitsight"
        }
    ],
    "1891661": [
        {
            "ioc_value": "31.97.133.166:4812",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remus",
            "malware_alias": null,
            "malware_printable": "Remus",
            "first_seen_utc": "2026-08-31 07:46:57",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "a465cd808ed9cca800749a734b591a42,c2,remus",
            "anonymous": 0,
            "reporter": "Bitsight"
        }
    ],
    "1891672": [
        {
            "ioc_value": "http://153.117.32.130:49657/Mozi.a",
            "ioc_type": "url",
            "threat_type": "payload_delivery",
            "malware": "elf.mozi",
            "malware_alias": null,
            "malware_printable": "Mozi",
            "first_seen_utc": "2026-08-31 07:46:56",
            "last_seen_utc": null,
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://honeylabs.net/lookup/153.117.32.130",
            "tags": "elf,iot,Mozi",
            "anonymous": 0,
            "reporter": "HoneyLabs"
        }
    ],
    "1891673": [
        {
            "ioc_value": "http://175.107.3.244:55339/Mozi.7",
            "ioc_type": "url",
            "threat_type": "payload_delivery",
            "malware": "elf.mozi",
            "malware_alias": null,
            "malware_printable": "Mozi",
            "first_seen_utc": "2026-08-31 07:46:55",
            "last_seen_utc": null,
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://honeylabs.net/lookup/175.107.3.244",
            "tags": "elf,iot,Mozi",
            "anonymous": 0,
            "reporter": "HoneyLabs"
        }
    ],
    "1891674": [
        {
            "ioc_value": "http://124.94.244.212:33038/Mozi.a",
            "ioc_type": "url",
            "threat_type": "payload_delivery",
            "malware": "elf.mozi",
            "malware_alias": null,
            "malware_printable": "Mozi",
            "first_seen_utc": "2026-08-31 07:46:54",
            "last_seen_utc": null,
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://honeylabs.net/lookup/124.94.244.212",
            "tags": "elf,iot,Mozi",
            "anonymous": 0,
            "reporter": "HoneyLabs"
        }
    ],
    "1891675": [
        {
            "ioc_value": "http://203.101.186.212:33774/Mozi.a",
            "ioc_type": "url",
            "threat_type": "payload_delivery",
            "malware": "elf.mozi",
            "malware_alias": null,
            "malware_printable": "Mozi",
            "first_seen_utc": "2026-08-31 07:46:53",
            "last_seen_utc": null,
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://honeylabs.net/lookup/203.101.186.212",
            "tags": "elf,iot,Mozi",
            "anonymous": 0,
            "reporter": "HoneyLabs"
        }
    ],
    "1891677": [
        {
            "ioc_value": "172.111.163.174:65070",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-08-31 07:46:52",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "c2,Nexus 27-08-26,Remcos",
            "anonymous": 0,
            "reporter": "Bitsight"
        }
    ],
    "1891685": [
        {
            "ioc_value": "172.111.163.162:65070",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-08-31 07:46:52",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "c2,Crypters&tools,Remcos",
            "anonymous": 0,
            "reporter": "Bitsight"
        }
    ],
    "1891693": [
        {
            "ioc_value": "pumykuja.workers.dev",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "php.shin_webshell",
            "malware_alias": null,
            "malware_printable": "php.shin_webshell",
            "first_seen_utc": "2026-08-31 07:24:36",
            "last_seen_utc": null,
            "confidence_level": 50,
            "is_compromised": true,
            "reference": null,
            "tags": "Cloudflare,GIF,PHP,webshell,WordPress,workers.dev,wp-admin",
            "anonymous": 0,
            "reporter": "xscon"
        }
    ],
    "1891692": [
        {
            "ioc_value": "zedypyqi.workers.dev",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "php.shin_webshell",
            "malware_alias": null,
            "malware_printable": "php.shin_webshell",
            "first_seen_utc": "2026-08-31 07:21:12",
            "last_seen_utc": null,
            "confidence_level": 50,
            "is_compromised": true,
            "reference": null,
            "tags": "Cloudflare,GIF,PHP,webshell,WordPress,workers.dev,wp-admin",
            "anonymous": 0,
            "reporter": "xscon"
        }
    ],
    "1891691": [
        {
            "ioc_value": "pujavi.workers.dev",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "php.shin_webshell",
            "malware_alias": null,
            "malware_printable": "php.shin_webshell",
            "first_seen_utc": "2026-08-31 07:16:42",
            "last_seen_utc": null,
            "confidence_level": 50,
            "is_compromised": true,
            "reference": null,
            "tags": "Cloudflare,GIF,PHP,webshell,WordPress,workers.dev,wp-admin",
            "anonymous": 0,
            "reporter": "xscon"
        }
    ],
    "1891690": [
        {
            "ioc_value": "hafagu-ce1.workers.dev",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "php.shin_webshell",
            "malware_alias": null,
            "malware_printable": "php.shin_webshell",
            "first_seen_utc": "2026-08-31 07:11:23",
            "last_seen_utc": null,
            "confidence_level": 50,
            "is_compromised": true,
            "reference": null,
            "tags": "Cloudflare,GIF,PHP,webshell,WordPress,workers.dev,wp-admin",
            "anonymous": 0,
            "reporter": "xscon"
        }
    ],
    "1891688": [
        {
            "ioc_value": "8.148.26.139:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-08-31 07:05:08",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "cobaltstrike",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1891689": [
        {
            "ioc_value": "8.148.26.139:8080",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-08-31 07:05:08",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "cobaltstrike",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1891686": [
        {
            "ioc_value": "8.148.26.139:9999",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-08-31 07:05:07",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "cobaltstrike",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1891687": [
        {
            "ioc_value": "8.148.26.139:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-08-31 07:05:07",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "cobaltstrike",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1891684": [
        {
            "ioc_value": "conectao.com.do",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-08-31 06:54:48",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": true,
            "reference": null,
            "tags": "compromised,EtherHide",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1891683": [
        {
            "ioc_value": "https://telegram.me/nag0a",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-08-31 06:53:53",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://bazaar.abuse.ch/sample/1b19bd93bc95ba908f8d13cf9e7e69776d2d82722f325d9290550aed155e56bd/",
            "tags": "o0oi1,Vidar",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1891682": [
        {
            "ioc_value": "dpiwraps.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-08-31 06:49:08",
            "last_seen_utc": "2026-08-31 06:50:30",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "31August2026,ClearFake,Commandline,DomainShadowing,Windows",
            "anonymous": 0,
            "reporter": "Gi7w0rm"
        }
    ],
    "1891681": [
        {
            "ioc_value": "xesevy.workers.dev",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "php.shin_webshell",
            "malware_alias": null,
            "malware_printable": "php.shin_webshell",
            "first_seen_utc": "2026-08-31 06:45:26",
            "last_seen_utc": null,
            "confidence_level": 50,
            "is_compromised": true,
            "reference": null,
            "tags": "Cloudflare,GIF,PHP,webshell,WordPress,workers.dev,wp-admin",
            "anonymous": 0,
            "reporter": "xscon"
        }
    ],
    "1891680": [
        {
            "ioc_value": "gebbxexd.shop-alphaboostpro.us",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-08-31 06:42:30",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,mac-0x76c7,macos",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1891679": [
        {
            "ioc_value": "consultinggetdsm.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-08-31 06:39:39",
            "last_seen_utc": "2026-08-31 06:39:45",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "31August2026,ClearFake,Commandline,DomainShadowing,Windows",
            "anonymous": 0,
            "reporter": "Gi7w0rm"
        }
    ],
    "1891678": [
        {
            "ioc_value": "441k40w4.shop-bellyflush.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-08-31 06:33:24",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,mac-0xdcf2,macos",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1891676": [
        {
            "ioc_value": "shop-bellyflush.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-08-31 06:30:19",
            "last_seen_utc": "2026-08-31 06:30:26",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "31August2026,ClearFake,Commandline,MacOS",
            "anonymous": 0,
            "reporter": "Gi7w0rm"
        }
    ],
    "1891671": [
        {
            "ioc_value": "duvokufi.workers.dev",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "php.shin_webshell",
            "malware_alias": null,
            "malware_printable": "php.shin_webshell",
            "first_seen_utc": "2026-08-31 06:15:54",
            "last_seen_utc": null,
            "confidence_level": 50,
            "is_compromised": true,
            "reference": null,
            "tags": "Cloudflare,GIF,PHP,webshell,WordPress,workers.dev,wp-admin",
            "anonymous": 0,
            "reporter": "xscon"
        }
    ],
    "1891670": [
        {
            "ioc_value": "fyhoqo.workers.dev",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "php.shin_webshell",
            "malware_alias": null,
            "malware_printable": "php.shin_webshell",
            "first_seen_utc": "2026-08-31 06:08:24",
            "last_seen_utc": null,
            "confidence_level": 50,
            "is_compromised": true,
            "reference": null,
            "tags": "Cloudflare,GIF,PHP,webshell,WordPress,workers.dev,wp-admin",
            "anonymous": 0,
            "reporter": "xscon"
        }
    ],
    "1891667": [
        {
            "ioc_value": "http://uiccvbk.click:8839/invoices",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.remus",
            "malware_alias": null,
            "malware_printable": "Remus",
            "first_seen_utc": "2026-08-31 06:02:23",
            "last_seen_utc": null,
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "remus",
            "anonymous": 0,
            "reporter": "Myrtus0x0"
        }
    ],
    "1891668": [
        {
            "ioc_value": "http://shhsift.click:7647/users",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.remus",
            "malware_alias": null,
            "malware_printable": "Remus",
            "first_seen_utc": "2026-08-31 06:02:23",
            "last_seen_utc": null,
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "remus",
            "anonymous": 0,
            "reporter": "Myrtus0x0"
        }
    ],
    "1891669": [
        {
            "ioc_value": "http://cdire.shop:9048/accounts",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.remus",
            "malware_alias": null,
            "malware_printable": "Remus",
            "first_seen_utc": "2026-08-31 06:02:23",
            "last_seen_utc": null,
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "remus",
            "anonymous": 0,
            "reporter": "Myrtus0x0"
        }
    ],
    "1891666": [
        {
            "ioc_value": "yhztr74434.workers.dev",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "php.shin_webshell",
            "malware_alias": null,
            "malware_printable": "php.shin_webshell",
            "first_seen_utc": "2026-08-31 05:41:16",
            "last_seen_utc": null,
            "confidence_level": 50,
            "is_compromised": true,
            "reference": null,
            "tags": "Cloudflare,GIF,PHP,webshell,WordPress,workers.dev,wp-admin",
            "anonymous": 0,
            "reporter": "xscon"
        }
    ],
    "1891665": [
        {
            "ioc_value": "dixibahy.workers.dev",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "php.shin_webshell",
            "malware_alias": null,
            "malware_printable": "php.shin_webshell",
            "first_seen_utc": "2026-08-31 05:37:00",
            "last_seen_utc": null,
            "confidence_level": 50,
            "is_compromised": true,
            "reference": null,
            "tags": "Cloudflare,GIF,PHP,webshell,WordPress,workers.dev,wp-admin",
            "anonymous": 0,
            "reporter": "xscon"
        }
    ],
    "1891664": [
        {
            "ioc_value": "wdccb3xe.home-power-shield.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-08-31 05:36:16",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,mac-0x0f14,macos",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1891663": [
        {
            "ioc_value": "muziwawy.workers.dev",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "php.shin_webshell",
            "malware_alias": null,
            "malware_printable": "php.shin_webshell",
            "first_seen_utc": "2026-08-31 05:34:31",
            "last_seen_utc": null,
            "confidence_level": 50,
            "is_compromised": true,
            "reference": null,
            "tags": "Cloudflare,GIF,PHP,webshell,WordPress,workers.dev,wp-admin",
            "anonymous": 0,
            "reporter": "xscon"
        }
    ],
    "1891662": [
        {
            "ioc_value": "vyivy22522.workers.dev",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "php.shin_webshell",
            "malware_alias": null,
            "malware_printable": "php.shin_webshell",
            "first_seen_utc": "2026-08-31 05:18:58",
            "last_seen_utc": null,
            "confidence_level": 50,
            "is_compromised": true,
            "reference": null,
            "tags": "Cloudflare,GIF,PHP,webshell,WordPress,workers.dev,wp-admin",
            "anonymous": 0,
            "reporter": "xscon"
        }
    ],
    "1891659": [
        {
            "ioc_value": "106.15.10.2:5672",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-08-31 05:05:06",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "cobaltstrike",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1891658": [
        {
            "ioc_value": "fyjilowu.workers.dev",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "php.shin_webshell",
            "malware_alias": null,
            "malware_printable": "php.shin_webshell",
            "first_seen_utc": "2026-08-31 05:04:38",
            "last_seen_utc": null,
            "confidence_level": 50,
            "is_compromised": true,
            "reference": null,
            "tags": "Cloudflare,GIF,PHP,webshell,WordPress,workers.dev,wp-admin",
            "anonymous": 0,
            "reporter": "xscon"
        }
    ],
    "1891657": [
        {
            "ioc_value": "prgfeg84.getdsm.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-08-31 05:03:18",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,mac-0x68dc,macos",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1891656": [
        {
            "ioc_value": "rlltn52176.workers.dev",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "php.shin_webshell",
            "malware_alias": null,
            "malware_printable": "php.shin_webshell",
            "first_seen_utc": "2026-08-31 04:52:25",
            "last_seen_utc": null,
            "confidence_level": 50,
            "is_compromised": true,
            "reference": null,
            "tags": "Cloudflare,GIF,PHP,webshell,WordPress,workers.dev,wp-admin",
            "anonymous": 0,
            "reporter": "xscon"
        }
    ],
    "1891655": [
        {
            "ioc_value": "http://flreaow.click:6527/webhooks",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.remus",
            "malware_alias": null,
            "malware_printable": "Remus",
            "first_seen_utc": "2026-08-31 04:33:23",
            "last_seen_utc": null,
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "remus",
            "anonymous": 0,
            "reporter": "Myrtus0x0"
        }
    ],
    "1891654": [
        {
            "ioc_value": "cenoci.workers.dev",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "php.shin_webshell",
            "malware_alias": null,
            "malware_printable": "php.shin_webshell",
            "first_seen_utc": "2026-08-31 04:28:19",
            "last_seen_utc": null,
            "confidence_level": 50,
            "is_compromised": true,
            "reference": null,
            "tags": "Cloudflare,GIF,PHP,webshell,WordPress,workers.dev,wp-admin",
            "anonymous": 0,
            "reporter": "xscon"
        }
    ],
    "1891653": [
        {
            "ioc_value": "fekajyzy.workers.dev",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "php.shin_webshell",
            "malware_alias": null,
            "malware_printable": "php.shin_webshell",
            "first_seen_utc": "2026-08-31 04:08:11",
            "last_seen_utc": null,
            "confidence_level": 50,
            "is_compromised": true,
            "reference": null,
            "tags": "Cloudflare,GIF,PHP,webshell,WordPress,workers.dev,wp-admin",
            "anonymous": 0,
            "reporter": "xscon"
        }
    ],
    "1891650": [
        {
            "ioc_value": "123.56.83.34:9999",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.vshell",
            "malware_alias": null,
            "malware_printable": "VShell",
            "first_seen_utc": "2026-08-31 04:05:05",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "vshell",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1891651": [
        {
            "ioc_value": "106.15.10.2:111",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-08-31 04:05:05",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "cobaltstrike",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1891652": [
        {
            "ioc_value": "106.15.10.2:4369",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-08-31 04:05:05",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "cobaltstrike",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1891649": [
        {
            "ioc_value": "pikeryri.workers.dev",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "php.shin_webshell",
            "malware_alias": null,
            "malware_printable": "php.shin_webshell",
            "first_seen_utc": "2026-08-31 04:04:03",
            "last_seen_utc": null,
            "confidence_level": 50,
            "is_compromised": true,
            "reference": null,
            "tags": "Cloudflare,GIF,PHP,webshell,WordPress,workers.dev,wp-admin",
            "anonymous": 0,
            "reporter": "xscon"
        }
    ],
    "1891648": [
        {
            "ioc_value": "f0n95tk64n.workers.dev",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "php.shin_webshell",
            "malware_alias": null,
            "malware_printable": "php.shin_webshell",
            "first_seen_utc": "2026-08-31 03:57:47",
            "last_seen_utc": null,
            "confidence_level": 50,
            "is_compromised": true,
            "reference": null,
            "tags": "Cloudflare,GIF,PHP,webshell,WordPress,workers.dev,wp-admin",
            "anonymous": 0,
            "reporter": "xscon"
        }
    ],
    "1891646": [
        {
            "ioc_value": "xocosyke.workers.dev",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "php.shin_webshell",
            "malware_alias": null,
            "malware_printable": "php.shin_webshell",
            "first_seen_utc": "2026-08-31 03:39:44",
            "last_seen_utc": null,
            "confidence_level": 50,
            "is_compromised": true,
            "reference": null,
            "tags": "Cloudflare,GIF,PHP,webshell,WordPress,workers.dev,wp-admin",
            "anonymous": 0,
            "reporter": "xscon"
        }
    ],
    "1891645": [
        {
            "ioc_value": "wequgucu.workers.dev",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "php.shin_webshell",
            "malware_alias": null,
            "malware_printable": "php.shin_webshell",
            "first_seen_utc": "2026-08-31 03:21:12",
            "last_seen_utc": null,
            "confidence_level": 50,
            "is_compromised": true,
            "reference": null,
            "tags": "Cloudflare,GIF,PHP,webshell,WordPress,workers.dev,wp-admin",
            "anonymous": 0,
            "reporter": "xscon"
        }
    ],
    "1891644": [
        {
            "ioc_value": "https://raw.githubusercontent.com/Christa6547/fling/refs/heads/main/scoop",
            "ioc_type": "url",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-08-31 03:13:17",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake",
            "anonymous": 0,
            "reporter": "threatcat_ch"
        }
    ],
    "1891643": [
        {
            "ioc_value": "dphx1pvb.en-us-glucotrustt-bites.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-08-31 03:06:11",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,mac-0x68dc,macos",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1891640": [
        {
            "ioc_value": "117.72.202.93:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-08-31 03:05:07",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "supershell",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1891641": [
        {
            "ioc_value": "117.72.202.93:8080",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-08-31 03:05:07",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "supershell",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1891642": [
        {
            "ioc_value": "106.54.41.209:21118",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-08-31 03:05:07",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "viper",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1891639": [
        {
            "ioc_value": "netiqu.workers.dev",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "php.shin_webshell",
            "malware_alias": null,
            "malware_printable": "php.shin_webshell",
            "first_seen_utc": "2026-08-31 02:53:40",
            "last_seen_utc": null,
            "confidence_level": 50,
            "is_compromised": true,
            "reference": null,
            "tags": "Cloudflare,GIF,PHP,webshell,WordPress,workers.dev,wp-admin",
            "anonymous": 0,
            "reporter": "xscon"
        }
    ],
    "1891638": [
        {
            "ioc_value": "vewiqy.workers.dev",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "php.shin_webshell",
            "malware_alias": null,
            "malware_printable": "php.shin_webshell",
            "first_seen_utc": "2026-08-31 02:52:30",
            "last_seen_utc": null,
            "confidence_level": 50,
            "is_compromised": true,
            "reference": null,
            "tags": "Cloudflare,GIF,PHP,webshell,WordPress,workers.dev,wp-admin",
            "anonymous": 0,
            "reporter": "xscon"
        }
    ],
    "1891637": [
        {
            "ioc_value": "dyveku.workers.dev",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "php.shin_webshell",
            "malware_alias": null,
            "malware_printable": "php.shin_webshell",
            "first_seen_utc": "2026-08-31 02:31:10",
            "last_seen_utc": null,
            "confidence_level": 50,
            "is_compromised": true,
            "reference": null,
            "tags": "Cloudflare,GIF,PHP,webshell,WordPress,workers.dev,wp-admin",
            "anonymous": 0,
            "reporter": "xscon"
        }
    ],
    "1891636": [
        {
            "ioc_value": "gybyce.workers.dev",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "php.shin_webshell",
            "malware_alias": null,
            "malware_printable": "php.shin_webshell",
            "first_seen_utc": "2026-08-31 02:27:34",
            "last_seen_utc": null,
            "confidence_level": 50,
            "is_compromised": true,
            "reference": null,
            "tags": "Cloudflare,GIF,PHP,webshell,WordPress,workers.dev,wp-admin",
            "anonymous": 0,
            "reporter": "xscon"
        }
    ],
    "1891635": [
        {
            "ioc_value": "vucaw13958.workers.dev",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "php.shin_webshell",
            "malware_alias": null,
            "malware_printable": "php.shin_webshell",
            "first_seen_utc": "2026-08-31 02:21:31",
            "last_seen_utc": null,
            "confidence_level": 50,
            "is_compromised": true,
            "reference": null,
            "tags": "Cloudflare,GIF,PHP,webshell,WordPress,workers.dev,wp-admin",
            "anonymous": 0,
            "reporter": "xscon"
        }
    ],
    "1891634": [
        {
            "ioc_value": "xeryxo.workers.dev",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "php.shin_webshell",
            "malware_alias": null,
            "malware_printable": "php.shin_webshell",
            "first_seen_utc": "2026-08-31 02:11:24",
            "last_seen_utc": null,
            "confidence_level": 50,
            "is_compromised": true,
            "reference": null,
            "tags": "Cloudflare,GIF,PHP,webshell,WordPress,workers.dev,wp-admin",
            "anonymous": 0,
            "reporter": "xscon"
        }
    ],
    "1891633": [
        {
            "ioc_value": "cixife.workers.dev",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "php.shin_webshell",
            "malware_alias": null,
            "malware_printable": "php.shin_webshell",
            "first_seen_utc": "2026-08-31 01:50:52",
            "last_seen_utc": null,
            "confidence_level": 50,
            "is_compromised": true,
            "reference": null,
            "tags": "Cloudflare,GIF,PHP,webshell,WordPress,workers.dev,wp-admin",
            "anonymous": 0,
            "reporter": "xscon"
        }
    ],
    "1891632": [
        {
            "ioc_value": "bp3mtp82.shop-aizenpower.us",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-08-31 01:42:15",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,mac-0x76c7,macos",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1891631": [
        {
            "ioc_value": "qa5c8tze.www-glucotrust-bites.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-08-31 01:29:51",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,mac-0xdcf2,macos",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1891630": [
        {
            "ioc_value": "m3c33sfv.rtinaclear.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-08-31 01:25:33",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,mac-0x0f14,macos",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1891629": [
        {
            "ioc_value": "rtinaclear.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-08-31 01:24:06",
            "last_seen_utc": "2026-08-31 01:24:12",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "31August2026,ClearFake,Commandline,MacOS",
            "anonymous": 0,
            "reporter": "Gi7w0rm"
        }
    ],
    "1891628": [
        {
            "ioc_value": "pkigp79697.workers.dev",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "php.shin_webshell",
            "malware_alias": null,
            "malware_printable": "php.shin_webshell",
            "first_seen_utc": "2026-08-31 01:18:52",
            "last_seen_utc": null,
            "confidence_level": 50,
            "is_compromised": true,
            "reference": null,
            "tags": "Cloudflare,GIF,PHP,webshell,WordPress,workers.dev,wp-admin",
            "anonymous": 0,
            "reporter": "xscon"
        }
    ],
    "1891627": [
        {
            "ioc_value": "lixytala.workers.dev",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "php.shin_webshell",
            "malware_alias": null,
            "malware_printable": "php.shin_webshell",
            "first_seen_utc": "2026-08-31 01:07:04",
            "last_seen_utc": null,
            "confidence_level": 50,
            "is_compromised": true,
            "reference": null,
            "tags": "Cloudflare,GIF,PHP,webshell,WordPress,workers.dev,wp-admin",
            "anonymous": 0,
            "reporter": "xscon"
        }
    ],
    "1891624": [
        {
            "ioc_value": "101.42.136.73:8080",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-08-31 01:05:06",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "cobaltstrike",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1891625": [
        {
            "ioc_value": "47.105.114.163:9999",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.vshell",
            "malware_alias": null,
            "malware_printable": "VShell",
            "first_seen_utc": "2026-08-31 01:05:06",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "vshell",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1891623": [
        {
            "ioc_value": "101.42.136.73:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-08-31 01:05:05",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "cobaltstrike",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1891620": [
        {
            "ioc_value": "353qfu36.en-trump-token.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-08-31 01:02:38",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,mac-0x68dc,macos",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1891618": [
        {
            "ioc_value": "156.251.11.58:935",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.valley_rat",
            "malware_alias": "Winos",
            "malware_printable": "ValleyRAT",
            "first_seen_utc": "2026-08-31 00:55:09",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "RAT,ValleyRAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1891617": [
        {
            "ioc_value": "156.251.11.58:936",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.valley_rat",
            "malware_alias": "Winos",
            "malware_printable": "ValleyRAT",
            "first_seen_utc": "2026-08-31 00:55:05",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "RAT,ValleyRAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1891616": [
        {
            "ioc_value": "sysyki.workers.dev",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "php.shin_webshell",
            "malware_alias": null,
            "malware_printable": "php.shin_webshell",
            "first_seen_utc": "2026-08-31 00:51:52",
            "last_seen_utc": null,
            "confidence_level": 50,
            "is_compromised": true,
            "reference": null,
            "tags": "Cloudflare,GIF,PHP,webshell,WordPress,workers.dev,wp-admin",
            "anonymous": 0,
            "reporter": "xscon"
        }
    ],
    "1891615": [
        {
            "ioc_value": "1oplympr3m.workers.dev",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "php.shin_webshell",
            "malware_alias": null,
            "malware_printable": "php.shin_webshell",
            "first_seen_utc": "2026-08-31 00:51:02",
            "last_seen_utc": null,
            "confidence_level": 50,
            "is_compromised": true,
            "reference": null,
            "tags": "Cloudflare,GIF,PHP,webshell,WordPress,workers.dev,wp-admin",
            "anonymous": 0,
            "reporter": "xscon"
        }
    ],
    "1891614": [
        {
            "ioc_value": "wuhola.workers.dev",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "php.shin_webshell",
            "malware_alias": null,
            "malware_printable": "php.shin_webshell",
            "first_seen_utc": "2026-08-31 00:48:43",
            "last_seen_utc": null,
            "confidence_level": 50,
            "is_compromised": true,
            "reference": null,
            "tags": "Cloudflare,GIF,PHP,webshell,WordPress,workers.dev,wp-admin",
            "anonymous": 0,
            "reporter": "xscon"
        }
    ],
    "1891613": [
        {
            "ioc_value": "www.forumeciv-afriquecentrale.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-08-31 00:36:51",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": true,
            "reference": null,
            "tags": "compromised,EtherHide",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1891612": [
        {
            "ioc_value": "dybecyvu.workers.dev",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "php.shin_webshell",
            "malware_alias": null,
            "malware_printable": "php.shin_webshell",
            "first_seen_utc": "2026-08-31 00:14:22",
            "last_seen_utc": null,
            "confidence_level": 50,
            "is_compromised": true,
            "reference": null,
            "tags": "Cloudflare,GIF,PHP,webshell,WordPress,workers.dev,wp-admin",
            "anonymous": 0,
            "reporter": "xscon"
        }
    ],
    "1891611": [
        {
            "ioc_value": "150.158.102.111:5003",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-08-31 00:05:05",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "cobaltstrike",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1891610": [
        {
            "ioc_value": "varygo.workers.dev",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "php.shin_webshell",
            "malware_alias": null,
            "malware_printable": "php.shin_webshell",
            "first_seen_utc": "2026-08-30 23:54:28",
            "last_seen_utc": null,
            "confidence_level": 50,
            "is_compromised": true,
            "reference": null,
            "tags": "Cloudflare,GIF,PHP,webshell,WordPress,workers.dev,wp-admin",
            "anonymous": 0,
            "reporter": "xscon"
        }
    ],
    "1891607": [
        {
            "ioc_value": "112.213.103.17:1217",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-08-30 23:50:19",
            "last_seen_utc": null,
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://bazaar.abuse.ch/sample/f6f7dbd6561e7ee6ba7e6abffdb1e5de01bf511318aade34825d888e99db645f/",
            "tags": "asyncrat",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1891608": [
        {
            "ioc_value": "112.213.103.58:5812",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-08-30 23:50:19",
            "last_seen_utc": null,
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://bazaar.abuse.ch/sample/9109d9bd117f540aed9afa6f293c1396cc18ed979056eadca97c69e3f957c14d/",
            "tags": "asyncrat",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1891605": [
        {
            "ioc_value": "101.42.136.73:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-08-30 23:46:41",
            "last_seen_utc": "2026-08-31 07:48:22",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1891606": [
        {
            "ioc_value": "101.42.136.73:8443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-08-30 23:46:41",
            "last_seen_utc": "2026-08-31 07:48:22",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1891604": [
        {
            "ioc_value": "nifibe.workers.dev",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "php.shin_webshell",
            "malware_alias": null,
            "malware_printable": "php.shin_webshell",
            "first_seen_utc": "2026-08-30 23:35:57",
            "last_seen_utc": null,
            "confidence_level": 50,
            "is_compromised": true,
            "reference": null,
            "tags": "Cloudflare,GIF,PHP,webshell,WordPress,workers.dev,wp-admin",
            "anonymous": 0,
            "reporter": "xscon"
        }
    ],
    "1891603": [
        {
            "ioc_value": "http://gofkaxz.click:8137/invoices",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.remus",
            "malware_alias": null,
            "malware_printable": "Remus",
            "first_seen_utc": "2026-08-30 23:25:18",
            "last_seen_utc": "2026-08-31 01:00:07",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://bazaar.abuse.ch/sample/71cdf126636c50a3a2b71fa730ddc3f3ab03791a35a70aa774de8652ca96a174/",
            "tags": "remus",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1891602": [
        {
            "ioc_value": "http://cdire.shop:9048/transactions",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.remus",
            "malware_alias": null,
            "malware_printable": "Remus",
            "first_seen_utc": "2026-08-30 23:25:17",
            "last_seen_utc": "2026-08-31 01:00:07",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://bazaar.abuse.ch/sample/71cdf126636c50a3a2b71fa730ddc3f3ab03791a35a70aa774de8652ca96a174/",
            "tags": "remus",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1891601": [
        {
            "ioc_value": "jycajame.workers.dev",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "php.shin_webshell",
            "malware_alias": null,
            "malware_printable": "php.shin_webshell",
            "first_seen_utc": "2026-08-30 23:16:30",
            "last_seen_utc": null,
            "confidence_level": 50,
            "is_compromised": true,
            "reference": null,
            "tags": "Cloudflare,GIF,PHP,webshell,WordPress,workers.dev,wp-admin",
            "anonymous": 0,
            "reporter": "xscon"
        }
    ],
    "1891600": [
        {
            "ioc_value": "nswpk62437.workers.dev",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "php.shin_webshell",
            "malware_alias": null,
            "malware_printable": "php.shin_webshell",
            "first_seen_utc": "2026-08-30 23:14:52",
            "last_seen_utc": null,
            "confidence_level": 50,
            "is_compromised": true,
            "reference": null,
            "tags": "Cloudflare,GIF,PHP,webshell,WordPress,workers.dev,wp-admin",
            "anonymous": 0,
            "reporter": "xscon"
        }
    ],
    "1891598": [
        {
            "ioc_value": "nerotywo.workers.dev",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "php.shin_webshell",
            "malware_alias": null,
            "malware_printable": "php.shin_webshell",
            "first_seen_utc": "2026-08-30 23:07:59",
            "last_seen_utc": null,
            "confidence_level": 50,
            "is_compromised": true,
            "reference": null,
            "tags": "Cloudflare,GIF,PHP,webshell,WordPress,workers.dev,wp-admin",
            "anonymous": 0,
            "reporter": "xscon"
        }
    ],
    "1891597": [
        {
            "ioc_value": "228dione.workers.dev",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "php.shin_webshell",
            "malware_alias": null,
            "malware_printable": "php.shin_webshell",
            "first_seen_utc": "2026-08-30 23:05:37",
            "last_seen_utc": null,
            "confidence_level": 50,
            "is_compromised": true,
            "reference": null,
            "tags": "Cloudflare,GIF,PHP,webshell,WordPress,workers.dev,wp-admin",
            "anonymous": 0,
            "reporter": "xscon"
        }
    ],
    "1891596": [
        {
            "ioc_value": "150.158.102.111:22",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-08-30 23:05:08",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "cobaltstrike",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1891595": [
        {
            "ioc_value": "150.158.102.111:8082",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-08-30 23:05:07",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "cobaltstrike",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1891594": [
        {
            "ioc_value": "150.158.102.111:85",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-08-30 23:05:06",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "cobaltstrike",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1891593": [
        {
            "ioc_value": "109.236.50.145:22",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-08-30 23:05:05",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "cobaltstrike",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1891592": [
        {
            "ioc_value": "h5xluule.barbashat.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-08-30 23:01:28",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,mac-0x68dc,macos",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1891591": [
        {
            "ioc_value": "http://urbandm.click:4812/documents",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.remus",
            "malware_alias": null,
            "malware_printable": "Remus",
            "first_seen_utc": "2026-08-30 22:44:22",
            "last_seen_utc": null,
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "remus",
            "anonymous": 0,
            "reporter": "Myrtus0x0"
        }
    ],
    "1891590": [
        {
            "ioc_value": "mumyqowi.workers.dev",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "php.shin_webshell",
            "malware_alias": null,
            "malware_printable": "php.shin_webshell",
            "first_seen_utc": "2026-08-30 22:34:05",
            "last_seen_utc": null,
            "confidence_level": 50,
            "is_compromised": true,
            "reference": null,
            "tags": "Cloudflare,GIF,PHP,webshell,WordPress,workers.dev,wp-admin",
            "anonymous": 0,
            "reporter": "xscon"
        }
    ],
    "1891589": [
        {
            "ioc_value": "lacygenetic.workers.dev",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "php.shin_webshell",
            "malware_alias": null,
            "malware_printable": "php.shin_webshell",
            "first_seen_utc": "2026-08-30 22:15:01",
            "last_seen_utc": null,
            "confidence_level": 50,
            "is_compromised": true,
            "reference": null,
            "tags": "Cloudflare,GIF,PHP,webshell,WordPress,workers.dev,wp-admin",
            "anonymous": 0,
            "reporter": "xscon"
        }
    ],
    "1891588": [
        {
            "ioc_value": "http://cdire.shop:9048/videos",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.remus",
            "malware_alias": null,
            "malware_printable": "Remus",
            "first_seen_utc": "2026-08-30 22:11:23",
            "last_seen_utc": null,
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "remus",
            "anonymous": 0,
            "reporter": "Myrtus0x0"
        }
    ],
    "1891587": [
        {
            "ioc_value": "uey2bqd5os.workers.dev",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "php.shin_webshell",
            "malware_alias": null,
            "malware_printable": "php.shin_webshell",
            "first_seen_utc": "2026-08-30 22:08:34",
            "last_seen_utc": null,
            "confidence_level": 50,
            "is_compromised": true,
            "reference": null,
            "tags": "Cloudflare,GIF,PHP,webshell,WordPress,workers.dev,wp-admin",
            "anonymous": 0,
            "reporter": "xscon"
        }
    ],
    "1891585": [
        {
            "ioc_value": "150.158.102.111:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-08-30 22:05:06",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "cobaltstrike",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1891586": [
        {
            "ioc_value": "150.158.102.111:8080",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-08-30 22:05:06",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "cobaltstrike",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1891584": [
        {
            "ioc_value": "150.158.102.111:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-08-30 22:05:05",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "cobaltstrike",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1891582": [
        {
            "ioc_value": "kahule.workers.dev",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "php.shin_webshell",
            "malware_alias": null,
            "malware_printable": "php.shin_webshell",
            "first_seen_utc": "2026-08-30 21:44:47",
            "last_seen_utc": null,
            "confidence_level": 50,
            "is_compromised": true,
            "reference": null,
            "tags": "Cloudflare,GIF,PHP,webshell,WordPress,workers.dev,wp-admin",
            "anonymous": 0,
            "reporter": "xscon"
        }
    ],
    "1891581": [
        {
            "ioc_value": "dyfaqymo.workers.dev",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "php.shin_webshell",
            "malware_alias": null,
            "malware_printable": "php.shin_webshell",
            "first_seen_utc": "2026-08-30 21:38:30",
            "last_seen_utc": null,
            "confidence_level": 50,
            "is_compromised": true,
            "reference": null,
            "tags": "Cloudflare,GIF,PHP,webshell,WordPress,workers.dev,wp-admin",
            "anonymous": 0,
            "reporter": "xscon"
        }
    ],
    "1891580": [
        {
            "ioc_value": "lerubizi.workers.dev",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "php.shin_webshell",
            "malware_alias": null,
            "malware_printable": "php.shin_webshell",
            "first_seen_utc": "2026-08-30 21:31:14",
            "last_seen_utc": null,
            "confidence_level": 50,
            "is_compromised": true,
            "reference": null,
            "tags": "Cloudflare,GIF,PHP,webshell,WordPress,workers.dev,wp-admin",
            "anonymous": 0,
            "reporter": "xscon"
        }
    ],
    "1891578": [
        {
            "ioc_value": "zqjoz45628.workers.dev",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "php.shin_webshell",
            "malware_alias": null,
            "malware_printable": "php.shin_webshell",
            "first_seen_utc": "2026-08-30 21:16:00",
            "last_seen_utc": null,
            "confidence_level": 50,
            "is_compromised": true,
            "reference": null,
            "tags": "Cloudflare,GIF,PHP,webshell,WordPress,workers.dev,wp-admin",
            "anonymous": 0,
            "reporter": "xscon"
        }
    ],
    "1891576": [
        {
            "ioc_value": "0qa0xgkt.retinaclr.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-08-30 21:14:02",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,mac-0x0f14,macos",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1891575": [
        {
            "ioc_value": "retinaclr.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-08-30 21:13:04",
            "last_seen_utc": "2026-08-30 21:14:11",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "30August2026,ClearFake,Commandline,MacOS",
            "anonymous": 0,
            "reporter": "Gi7w0rm"
        }
    ],
    "1891574": [
        {
            "ioc_value": "mail.ded7845.inmotionhosting.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-08-30 21:06:39",
            "last_seen_utc": "2026-08-30 21:06:39",
            "confidence_level": 90,
            "is_compromised": true,
            "reference": null,
            "tags": "ClickFix,compromised",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1891573": [
        {
            "ioc_value": "104.168.102.116:22",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-08-30 21:05:07",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "cobaltstrike",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1891572": [
        {
            "ioc_value": "104.168.102.116:8080",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-08-30 21:05:06",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "cobaltstrike",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1891570": [
        {
            "ioc_value": "104.168.102.116:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-08-30 21:05:05",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "cobaltstrike",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1891571": [
        {
            "ioc_value": "104.168.102.116:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-08-30 21:05:05",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "cobaltstrike",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1891569": [
        {
            "ioc_value": "xnjbjf7o.shop-aquapeace.us",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-08-30 21:01:08",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,mac-0x68dc,macos",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1891568": [
        {
            "ioc_value": "shop-aquapeace.us",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-08-30 21:00:08",
            "last_seen_utc": "2026-08-30 21:01:12",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake",
            "anonymous": 0,
            "reporter": "threatcat_ch"
        }
    ],
    "1891566": [
        {
            "ioc_value": "http://cdire.shop:9048/tokens",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.remus",
            "malware_alias": null,
            "malware_printable": "Remus",
            "first_seen_utc": "2026-08-30 20:56:03",
            "last_seen_utc": null,
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "remus",
            "anonymous": 0,
            "reporter": "Myrtus0x0"
        }
    ],
    "1891565": [
        {
            "ioc_value": "dypocemy.workers.dev",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "php.shin_webshell",
            "malware_alias": null,
            "malware_printable": "php.shin_webshell",
            "first_seen_utc": "2026-08-30 20:53:44",
            "last_seen_utc": null,
            "confidence_level": 50,
            "is_compromised": true,
            "reference": null,
            "tags": "Cloudflare,GIF,PHP,webshell,WordPress,workers.dev,wp-admin",
            "anonymous": 0,
            "reporter": "xscon"
        }
    ],
    "1891564": [
        {
            "ioc_value": "29l1b9y1.shop-aeroslim.us",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-08-30 20:40:43",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,mac-0x76c7,macos",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1891563": [
        {
            "ioc_value": "pu8gkxg57y.workers.dev",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "php.shin_webshell",
            "malware_alias": null,
            "malware_printable": "php.shin_webshell",
            "first_seen_utc": "2026-08-30 20:40:06",
            "last_seen_utc": null,
            "confidence_level": 50,
            "is_compromised": true,
            "reference": null,
            "tags": "Cloudflare,GIF,PHP,webshell,WordPress,workers.dev,wp-admin",
            "anonymous": 0,
            "reporter": "xscon"
        }
    ],
    "1891562": [
        {
            "ioc_value": "http://cdire.shop:9048/webhooks",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.remus",
            "malware_alias": null,
            "malware_printable": "Remus",
            "first_seen_utc": "2026-08-30 20:25:04",
            "last_seen_utc": null,
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "remus",
            "anonymous": 0,
            "reporter": "Myrtus0x0"
        }
    ],
    "1891561": [
        {
            "ioc_value": "p0iqkjuq.usen-glucotrust-bites.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-08-30 20:20:18",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,mac-0xdcf2,macos",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1891560": [
        {
            "ioc_value": "usen-glucotrust-bites.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-08-30 20:19:34",
            "last_seen_utc": "2026-08-31 01:29:33",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "30August2026,ClearFake,Commandline,MacOS",
            "anonymous": 0,
            "reporter": "Gi7w0rm"
        }
    ],
    "1891559": [
        {
            "ioc_value": "toqima.workers.dev",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "php.shin_webshell",
            "malware_alias": null,
            "malware_printable": "php.shin_webshell",
            "first_seen_utc": "2026-08-30 20:14:27",
            "last_seen_utc": null,
            "confidence_level": 50,
            "is_compromised": true,
            "reference": null,
            "tags": "Cloudflare,GIF,PHP,webshell,WordPress,workers.dev,wp-admin",
            "anonymous": 0,
            "reporter": "xscon"
        }
    ],
    "1891558": [
        {
            "ioc_value": "109.236.50.145:8443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-08-30 20:05:07",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "cobaltstrike",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1891556": [
        {
            "ioc_value": "109.236.50.145:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-08-30 20:05:06",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "cobaltstrike",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1891557": [
        {
            "ioc_value": "109.236.50.145:8080",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-08-30 20:05:06",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "cobaltstrike",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1891554": [
        {
            "ioc_value": "109.236.50.145:8888",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-08-30 20:05:05",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "cobaltstrike",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1891555": [
        {
            "ioc_value": "109.236.50.145:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-08-30 20:05:05",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "cobaltstrike",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1891553": [
        {
            "ioc_value": "http://cc893886.tw1.ru/L1nc0In.php",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.dcrat",
            "malware_alias": "DarkCrystal RAT",
            "malware_printable": "DCRat",
            "first_seen_utc": "2026-08-30 20:05:04",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "DCRat,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1891552": [
        {
            "ioc_value": "tv7dug0hg6.workers.dev",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "php.shin_webshell",
            "malware_alias": null,
            "malware_printable": "php.shin_webshell",
            "first_seen_utc": "2026-08-30 20:02:40",
            "last_seen_utc": null,
            "confidence_level": 50,
            "is_compromised": true,
            "reference": null,
            "tags": "Cloudflare,GIF,PHP,webshell,WordPress,workers.dev,wp-admin",
            "anonymous": 0,
            "reporter": "xscon"
        }
    ],
    "1891551": [
        {
            "ioc_value": "nzasn96104.workers.dev",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "php.shin_webshell",
            "malware_alias": null,
            "malware_printable": "php.shin_webshell",
            "first_seen_utc": "2026-08-30 19:57:53",
            "last_seen_utc": null,
            "confidence_level": 50,
            "is_compromised": true,
            "reference": null,
            "tags": "Cloudflare,GIF,PHP,webshell,WordPress,workers.dev,wp-admin",
            "anonymous": 0,
            "reporter": "xscon"
        }
    ],
    "1891550": [
        {
            "ioc_value": "kadazyci.workers.dev",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "php.shin_webshell",
            "malware_alias": null,
            "malware_printable": "php.shin_webshell",
            "first_seen_utc": "2026-08-30 19:56:05",
            "last_seen_utc": null,
            "confidence_level": 50,
            "is_compromised": true,
            "reference": null,
            "tags": "Cloudflare,GIF,PHP,webshell,WordPress,workers.dev,wp-admin",
            "anonymous": 0,
            "reporter": "xscon"
        }
    ],
    "1891549": [
        {
            "ioc_value": "bezamy.workers.dev",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "php.shin_webshell",
            "malware_alias": null,
            "malware_printable": "php.shin_webshell",
            "first_seen_utc": "2026-08-30 19:52:20",
            "last_seen_utc": null,
            "confidence_level": 50,
            "is_compromised": true,
            "reference": null,
            "tags": "Cloudflare,GIF,PHP,webshell,WordPress,workers.dev,wp-admin",
            "anonymous": 0,
            "reporter": "xscon"
        }
    ],
    "1891547": [
        {
            "ioc_value": "lbxpg68375.workers.dev",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "php.shin_webshell",
            "malware_alias": null,
            "malware_printable": "php.shin_webshell",
            "first_seen_utc": "2026-08-30 19:47:05",
            "last_seen_utc": null,
            "confidence_level": 50,
            "is_compromised": true,
            "reference": null,
            "tags": "Cloudflare,GIF,PHP,webshell,WordPress,workers.dev,wp-admin",
            "anonymous": 0,
            "reporter": "xscon"
        }
    ],
    "1891546": [
        {
            "ioc_value": "check1.judicica1n",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-08-30 19:46:45",
            "last_seen_utc": "2026-08-31 07:48:15",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1891545": [
        {
            "ioc_value": "94.228.166.168:56002",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-30 19:46:39",
            "last_seen_utc": "2026-08-31 07:48:08",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1891544": [
        {
            "ioc_value": "91.219.239.81:972",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-08-30 19:46:33",
            "last_seen_utc": "2026-08-31 07:47:58",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1891543": [
        {
            "ioc_value": "45.225.135.156:56003",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-30 19:45:59",
            "last_seen_utc": "2026-08-31 07:47:13",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1891541": [
        {
            "ioc_value": "217.60.195.109:56001",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-30 19:45:29",
            "last_seen_utc": "2026-08-31 07:46:33",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1891542": [
        {
            "ioc_value": "217.60.195.109:56002",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-30 19:45:29",
            "last_seen_utc": "2026-08-31 07:46:33",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1891539": [
        {
            "ioc_value": "195.177.94.188:56001",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-30 19:44:37",
            "last_seen_utc": "2026-08-31 07:45:24",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1891540": [
        {
            "ioc_value": "195.177.94.188:56002",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-30 19:44:37",
            "last_seen_utc": "2026-08-31 07:45:24",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1891538": [
        {
            "ioc_value": "194.59.30.96:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.hype_agent",
            "malware_alias": null,
            "malware_printable": "HypeAgent",
            "first_seen_utc": "2026-08-30 19:44:35",
            "last_seen_utc": "2026-08-31 07:45:19",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,HypeAgent",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1891537": [
        {
            "ioc_value": "185.112.59.115:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-30 19:44:14",
            "last_seen_utc": "2026-08-31 07:44:41",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1891536": [
        {
            "ioc_value": "172.86.122.177:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-30 19:44:04",
            "last_seen_utc": "2026-08-31 07:44:27",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1891535": [
        {
            "ioc_value": "162.243.160.70:8443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.havoc",
            "malware_alias": "Havokiz",
            "malware_printable": "Havoc",
            "first_seen_utc": "2026-08-30 19:43:52",
            "last_seen_utc": "2026-08-31 07:44:11",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Havoc",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1891534": [
        {
            "ioc_value": "160.119.69.30:5555",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-08-30 19:43:51",
            "last_seen_utc": "2026-08-31 07:44:10",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1891531": [
        {
            "ioc_value": "144.31.6.6:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-30 19:43:37",
            "last_seen_utc": "2026-08-31 07:43:50",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1891532": [
        {
            "ioc_value": "144.31.6.6:56001",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-30 19:43:37",
            "last_seen_utc": "2026-08-31 07:43:50",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1891533": [
        {
            "ioc_value": "144.31.6.6:56002",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-30 19:43:37",
            "last_seen_utc": "2026-08-31 07:43:50",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1891529": [
        {
            "ioc_value": "144.31.106.168:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.chaos",
            "malware_alias": "FakeRyuk,RyukJoke,Yashma",
            "malware_printable": "Chaos",
            "first_seen_utc": "2026-08-30 19:43:36",
            "last_seen_utc": "2026-08-31 07:43:49",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CHAOS,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1891530": [
        {
            "ioc_value": "144.31.106.168:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.chaos",
            "malware_alias": "FakeRyuk,RyukJoke,Yashma",
            "malware_printable": "Chaos",
            "first_seen_utc": "2026-08-30 19:43:36",
            "last_seen_utc": "2026-08-31 07:43:50",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CHAOS,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1891528": [
        {
            "ioc_value": "102.117.167.19:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-08-30 19:05:04",
            "last_seen_utc": "2026-08-31 07:43:05",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "mythic",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1891527": [
        {
            "ioc_value": "eelsq5rh.shop-aquaburn.us",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-08-30 19:02:30",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,mac-0x68dc,macos",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1891526": [
        {
            "ioc_value": "shop-aquaburn.us",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-08-30 18:59:54",
            "last_seen_utc": "2026-08-30 19:00:29",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake",
            "anonymous": 0,
            "reporter": "threatcat_ch"
        }
    ],
    "1891525": [
        {
            "ioc_value": "nelinura.workers.dev",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "php.shin_webshell",
            "malware_alias": null,
            "malware_printable": "php.shin_webshell",
            "first_seen_utc": "2026-08-30 18:55:41",
            "last_seen_utc": null,
            "confidence_level": 50,
            "is_compromised": true,
            "reference": null,
            "tags": "Cloudflare,GIF,PHP,webshell,WordPress,workers.dev,wp-admin",
            "anonymous": 0,
            "reporter": "xscon"
        }
    ],
    "1891523": [
        {
            "ioc_value": "zalyxi.workers.dev",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "php.shin_webshell",
            "malware_alias": null,
            "malware_printable": "php.shin_webshell",
            "first_seen_utc": "2026-08-30 18:52:58",
            "last_seen_utc": null,
            "confidence_level": 50,
            "is_compromised": true,
            "reference": null,
            "tags": "Cloudflare,GIF,PHP,webshell,WordPress,workers.dev,wp-admin",
            "anonymous": 0,
            "reporter": "xscon"
        }
    ],
    "1891522": [
        {
            "ioc_value": "dosydi.workers.dev",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "php.shin_webshell",
            "malware_alias": null,
            "malware_printable": "php.shin_webshell",
            "first_seen_utc": "2026-08-30 18:47:44",
            "last_seen_utc": null,
            "confidence_level": 50,
            "is_compromised": true,
            "reference": null,
            "tags": "Cloudflare,GIF,PHP,webshell,WordPress,workers.dev,wp-admin",
            "anonymous": 0,
            "reporter": "xscon"
        }
    ],
    "1891517": [
        {
            "ioc_value": "l9hmkvn2xm.workers.dev",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "php.shin_webshell",
            "malware_alias": null,
            "malware_printable": "php.shin_webshell",
            "first_seen_utc": "2026-08-30 18:31:27",
            "last_seen_utc": null,
            "confidence_level": 50,
            "is_compromised": true,
            "reference": null,
            "tags": "Cloudflare,GIF,PHP,webshell,WordPress,workers.dev,wp-admin",
            "anonymous": 0,
            "reporter": "xscon"
        }
    ],
    "1891516": [
        {
            "ioc_value": "vi28v3xsvo.workers.dev",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "php.shin_webshell",
            "malware_alias": null,
            "malware_printable": "php.shin_webshell",
            "first_seen_utc": "2026-08-30 18:14:00",
            "last_seen_utc": null,
            "confidence_level": 50,
            "is_compromised": true,
            "reference": null,
            "tags": "Cloudflare,GIF,PHP,webshell,WordPress,workers.dev,wp-admin",
            "anonymous": 0,
            "reporter": "xscon"
        }
    ],
    "1891515": [
        {
            "ioc_value": "cc.nhancute.site",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "elf.mirai",
            "malware_alias": "Katana",
            "malware_printable": "Mirai",
            "first_seen_utc": "2026-08-30 18:09:21",
            "last_seen_utc": "2026-08-30 18:09:21",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://bazaar.abuse.ch/sample/1bf4366ad6b382991c6b8c68b4863e9bafcc8e9533867b0e17b1d5825689c143/",
            "tags": "Mirai",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1891514": [
        {
            "ioc_value": "160.250.181.124:47925",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.mirai",
            "malware_alias": "Katana",
            "malware_printable": "Mirai",
            "first_seen_utc": "2026-08-30 18:09:20",
            "last_seen_utc": null,
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://bazaar.abuse.ch/sample/1bf4366ad6b382991c6b8c68b4863e9bafcc8e9533867b0e17b1d5825689c143/",
            "tags": "Mirai",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1891513": [
        {
            "ioc_value": "zoxycada.workers.dev",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "php.shin_webshell",
            "malware_alias": null,
            "malware_printable": "php.shin_webshell",
            "first_seen_utc": "2026-08-30 18:08:29",
            "last_seen_utc": null,
            "confidence_level": 50,
            "is_compromised": true,
            "reference": null,
            "tags": "Cloudflare,GIF,PHP,webshell,WordPress,workers.dev,wp-admin",
            "anonymous": 0,
            "reporter": "xscon"
        }
    ],
    "1891512": [
        {
            "ioc_value": "87.120.104.147:8080",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-08-30 18:00:42",
            "last_seen_utc": null,
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://bazaar.abuse.ch/sample/82bee273347b6e752d229b8fd3e5fed68cfc49f0f7145a8e457bf3ca0c91b5df/",
            "tags": null,
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1891439": [
        {
            "ioc_value": "http://36.255.33.242:53631/Mozi.a",
            "ioc_type": "url",
            "threat_type": "payload_delivery",
            "malware": "elf.mozi",
            "malware_alias": null,
            "malware_printable": "Mozi",
            "first_seen_utc": "2026-08-30 17:40:00",
            "last_seen_utc": null,
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://honeylabs.net/lookup/36.255.33.242",
            "tags": "elf,iot,Mozi",
            "anonymous": 0,
            "reporter": "HoneyLabs"
        }
    ],
    "1891440": [
        {
            "ioc_value": "http://103.148.128.156:45276/Mozi.m",
            "ioc_type": "url",
            "threat_type": "payload_delivery",
            "malware": "elf.mozi",
            "malware_alias": null,
            "malware_printable": "Mozi",
            "first_seen_utc": "2026-08-30 17:39:59",
            "last_seen_utc": null,
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://honeylabs.net/lookup/103.148.128.156",
            "tags": "elf,iot,Mozi",
            "anonymous": 0,
            "reporter": "HoneyLabs"
        }
    ],
    "1891441": [
        {
            "ioc_value": "http://103.237.157.163:56063/Mozi.m",
            "ioc_type": "url",
            "threat_type": "payload_delivery",
            "malware": "elf.mozi",
            "malware_alias": null,
            "malware_printable": "Mozi",
            "first_seen_utc": "2026-08-30 17:39:59",
            "last_seen_utc": null,
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://honeylabs.net/lookup/103.237.157.163",
            "tags": "elf,iot,Mozi",
            "anonymous": 0,
            "reporter": "HoneyLabs"
        }
    ],
    "1891442": [
        {
            "ioc_value": "http://153.117.32.82:36030/Mozi.m",
            "ioc_type": "url",
            "threat_type": "payload_delivery",
            "malware": "elf.mozi",
            "malware_alias": null,
            "malware_printable": "Mozi",
            "first_seen_utc": "2026-08-30 17:39:58",
            "last_seen_utc": null,
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://honeylabs.net/lookup/153.117.32.82",
            "tags": "elf,iot,Mozi",
            "anonymous": 0,
            "reporter": "HoneyLabs"
        }
    ],
    "1891443": [
        {
            "ioc_value": "http://124.29.214.104:35063/Mozi.m",
            "ioc_type": "url",
            "threat_type": "payload_delivery",
            "malware": "elf.mozi",
            "malware_alias": null,
            "malware_printable": "Mozi",
            "first_seen_utc": "2026-08-30 17:39:58",
            "last_seen_utc": null,
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://honeylabs.net/lookup/124.29.214.104",
            "tags": "elf,iot,Mozi",
            "anonymous": 0,
            "reporter": "HoneyLabs"
        }
    ],
    "1891444": [
        {
            "ioc_value": "http://139.135.40.153:53926/Mozi.m",
            "ioc_type": "url",
            "threat_type": "payload_delivery",
            "malware": "elf.mozi",
            "malware_alias": null,
            "malware_printable": "Mozi",
            "first_seen_utc": "2026-08-30 17:39:57",
            "last_seen_utc": null,
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://honeylabs.net/lookup/139.135.40.153",
            "tags": "elf,iot,Mozi",
            "anonymous": 0,
            "reporter": "HoneyLabs"
        }
    ],
    "1891461": [
        {
            "ioc_value": "167.99.128.245:8443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.aisuru",
            "malware_alias": null,
            "malware_printable": "Aisuru",
            "first_seen_utc": "2026-08-30 17:39:56",
            "last_seen_utc": "2026-08-31 08:00:53",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "Aisuru,c2",
            "anonymous": 0,
            "reporter": "Bitsight"
        }
    ],
    "1891473": [
        {
            "ioc_value": "45.142.30.152:3000",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-08-30 17:39:56",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://x.com/devmihaylov/status/2093987929282560285",
            "tags": "angel-panel,clipper,multiablo,stealer,telegram",
            "anonymous": 0,
            "reporter": "devmihaylov"
        }
    ],
    "1891475": [
        {
            "ioc_value": "159.89.24.55:9034",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.aisuru",
            "malware_alias": null,
            "malware_printable": "Aisuru",
            "first_seen_utc": "2026-08-30 17:39:55",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "Aisuru,c2",
            "anonymous": 0,
            "reporter": "Bitsight"
        }
    ],
    "1891491": [
        {
            "ioc_value": "https://zca.12naga.org",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-08-30 17:39:54",
            "last_seen_utc": "2026-08-31 08:13:34",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "b8546d0712608b893c6c87d32a5986c5,c2,loader,stealer,Vidar",
            "anonymous": 0,
            "reporter": "Bitsight"
        }
    ],
    "1891492": [
        {
            "ioc_value": "https://2.28.55.31",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-08-30 17:39:54",
            "last_seen_utc": "2026-08-31 08:14:52",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "4811e2fc839a15fdbf489521544e9eb9,c2,loader,stealer,Vidar",
            "anonymous": 0,
            "reporter": "Bitsight"
        }
    ],
    "1891511": [
        {
            "ioc_value": "qumilaga.workers.dev",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "php.shin_webshell",
            "malware_alias": null,
            "malware_printable": "php.shin_webshell",
            "first_seen_utc": "2026-08-30 17:35:56",
            "last_seen_utc": null,
            "confidence_level": 50,
            "is_compromised": true,
            "reference": null,
            "tags": "Cloudflare,GIF,PHP,webshell,WordPress,workers.dev,wp-admin",
            "anonymous": 0,
            "reporter": "xscon"
        }
    ],
    "1891510": [
        {
            "ioc_value": "jizegumy.workers.dev",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "php.shin_webshell",
            "malware_alias": null,
            "malware_printable": "php.shin_webshell",
            "first_seen_utc": "2026-08-30 17:24:22",
            "last_seen_utc": null,
            "confidence_level": 50,
            "is_compromised": true,
            "reference": null,
            "tags": "Cloudflare,GIF,PHP,webshell,WordPress,workers.dev,wp-admin",
            "anonymous": 0,
            "reporter": "xscon"
        }
    ],
    "1891509": [
        {
            "ioc_value": "nonikiri.workers.dev",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "php.shin_webshell",
            "malware_alias": null,
            "malware_printable": "php.shin_webshell",
            "first_seen_utc": "2026-08-30 17:20:06",
            "last_seen_utc": null,
            "confidence_level": 50,
            "is_compromised": true,
            "reference": null,
            "tags": "Cloudflare,GIF,PHP,webshell,WordPress,workers.dev,wp-admin",
            "anonymous": 0,
            "reporter": "xscon"
        }
    ],
    "1891508": [
        {
            "ioc_value": "gygaqila.workers.dev",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "php.shin_webshell",
            "malware_alias": null,
            "malware_printable": "php.shin_webshell",
            "first_seen_utc": "2026-08-30 17:17:44",
            "last_seen_utc": null,
            "confidence_level": 50,
            "is_compromised": true,
            "reference": null,
            "tags": "Cloudflare,GIF,PHP,webshell,WordPress,workers.dev,wp-admin",
            "anonymous": 0,
            "reporter": "xscon"
        }
    ],
    "1891507": [
        {
            "ioc_value": "zavemo.workers.dev",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "php.shin_webshell",
            "malware_alias": null,
            "malware_printable": "php.shin_webshell",
            "first_seen_utc": "2026-08-30 17:11:16",
            "last_seen_utc": null,
            "confidence_level": 50,
            "is_compromised": true,
            "reference": null,
            "tags": "Cloudflare,GIF,PHP,webshell,WordPress,workers.dev,wp-admin",
            "anonymous": 0,
            "reporter": "xscon"
        }
    ],
    "1891506": [
        {
            "ioc_value": "sahowi.workers.dev",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "php.shin_webshell",
            "malware_alias": null,
            "malware_printable": "php.shin_webshell",
            "first_seen_utc": "2026-08-30 17:09:19",
            "last_seen_utc": null,
            "confidence_level": 50,
            "is_compromised": true,
            "reference": null,
            "tags": "Cloudflare,GIF,PHP,webshell,WordPress,workers.dev,wp-admin",
            "anonymous": 0,
            "reporter": "xscon"
        }
    ],
    "1891505": [
        {
            "ioc_value": "http://cdire.shop:9048/posts",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.remus",
            "malware_alias": null,
            "malware_printable": "Remus",
            "first_seen_utc": "2026-08-30 17:07:43",
            "last_seen_utc": null,
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "remus",
            "anonymous": 0,
            "reporter": "Myrtus0x0"
        }
    ],
    "1891504": [
        {
            "ioc_value": "7109hvuj.retinaclier.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-08-30 17:03:53",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,mac-0x0f14,macos",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1891503": [
        {
            "ioc_value": "retinaclier.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-08-30 17:03:07",
            "last_seen_utc": "2026-08-30 17:03:14",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "30August2026,ClearFake,Commandline,MacOS",
            "anonymous": 0,
            "reporter": "Gi7w0rm"
        }
    ],
    "1891502": [
        {
            "ioc_value": "lf2qo513.shop-aquaburn.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-08-30 17:00:30",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,mac-0x68dc,macos",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1891501": [
        {
            "ioc_value": "shop-aquaburn.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-08-30 16:59:25",
            "last_seen_utc": "2026-08-30 17:00:23",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake",
            "anonymous": 0,
            "reporter": "threatcat_ch"
        }
    ],
    "1891500": [
        {
            "ioc_value": "shop-alphatonic.us",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-08-30 16:57:46",
            "last_seen_utc": "2026-08-30 16:58:52",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake",
            "anonymous": 0,
            "reporter": "threatcat_ch"
        }
    ],
    "1891499": [
        {
            "ioc_value": "glyco--free.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-08-30 16:54:56",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "30August2026,ClearFake,Commandline,DomainShadowing,Windows",
            "anonymous": 0,
            "reporter": "Gi7w0rm"
        }
    ],
    "1891498": [
        {
            "ioc_value": "ryduzoxe.workers.dev",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "php.shin_webshell",
            "malware_alias": null,
            "malware_printable": "php.shin_webshell",
            "first_seen_utc": "2026-08-30 16:49:40",
            "last_seen_utc": null,
            "confidence_level": 50,
            "is_compromised": true,
            "reference": null,
            "tags": "Cloudflare,GIF,PHP,webshell,WordPress,workers.dev,wp-admin",
            "anonymous": 0,
            "reporter": "xscon"
        }
    ],
    "1891496": [
        {
            "ioc_value": "http://cdire.shop:9048/subscriptions",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.remus",
            "malware_alias": null,
            "malware_printable": "Remus",
            "first_seen_utc": "2026-08-30 16:41:43",
            "last_seen_utc": null,
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "remus",
            "anonymous": 0,
            "reporter": "Myrtus0x0"
        }
    ],
    "1891497": [
        {
            "ioc_value": "http://cdire.shop:9048/messages",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.remus",
            "malware_alias": null,
            "malware_printable": "Remus",
            "first_seen_utc": "2026-08-30 16:41:43",
            "last_seen_utc": null,
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "remus",
            "anonymous": 0,
            "reporter": "Myrtus0x0"
        }
    ],
    "1891495": [
        {
            "ioc_value": "http://flreaow.click:6527/tasks",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.remus",
            "malware_alias": null,
            "malware_printable": "Remus",
            "first_seen_utc": "2026-08-30 16:41:42",
            "last_seen_utc": null,
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "remus",
            "anonymous": 0,
            "reporter": "Myrtus0x0"
        }
    ],
    "1891494": [
        {
            "ioc_value": "pucotihy.workers.dev",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "php.shin_webshell",
            "malware_alias": null,
            "malware_printable": "php.shin_webshell",
            "first_seen_utc": "2026-08-30 16:19:03",
            "last_seen_utc": null,
            "confidence_level": 50,
            "is_compromised": true,
            "reference": null,
            "tags": "Cloudflare,GIF,PHP,webshell,WordPress,workers.dev,wp-admin",
            "anonymous": 0,
            "reporter": "xscon"
        }
    ],
    "1891493": [
        {
            "ioc_value": "www.maxmetalpackage.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-08-30 16:06:23",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": true,
            "reference": null,
            "tags": "compromised,EtherHide",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1891490": [
        {
            "ioc_value": "http://zonxh.shop:7728/reports",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.remus",
            "malware_alias": null,
            "malware_printable": "Remus",
            "first_seen_utc": "2026-08-30 15:55:19",
            "last_seen_utc": null,
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://bazaar.abuse.ch/sample/44fbba738f24e417236317f4efd260be890bcc745d6d9919a91b7015f84c402f/",
            "tags": "remus",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1891489": [
        {
            "ioc_value": "http://kupzovo.shop:7567/reports",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.remus",
            "malware_alias": null,
            "malware_printable": "Remus",
            "first_seen_utc": "2026-08-30 15:55:16",
            "last_seen_utc": null,
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://bazaar.abuse.ch/sample/44fbba738f24e417236317f4efd260be890bcc745d6d9919a91b7015f84c402f/",
            "tags": "remus",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1891488": [
        {
            "ioc_value": "nolacu.workers.dev",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "php.shin_webshell",
            "malware_alias": null,
            "malware_printable": "php.shin_webshell",
            "first_seen_utc": "2026-08-30 15:51:00",
            "last_seen_utc": null,
            "confidence_level": 50,
            "is_compromised": true,
            "reference": null,
            "tags": "Cloudflare,GIF,PHP,webshell,WordPress,workers.dev,wp-admin",
            "anonymous": 0,
            "reporter": "xscon"
        }
    ],
    "1891487": [
        {
            "ioc_value": "7ytwphx3.purabst.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-08-30 15:35:23",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,mac-0x76c7,macos",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1891486": [
        {
            "ioc_value": "fppanzb0p4.workers.dev",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "php.shin_webshell",
            "malware_alias": null,
            "malware_printable": "php.shin_webshell",
            "first_seen_utc": "2026-08-30 15:34:49",
            "last_seen_utc": null,
            "confidence_level": 50,
            "is_compromised": true,
            "reference": null,
            "tags": "Cloudflare,GIF,PHP,webshell,WordPress,workers.dev,wp-admin",
            "anonymous": 0,
            "reporter": "xscon"
        }
    ],
    "1891485": [
        {
            "ioc_value": "purabst.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-08-30 15:33:32",
            "last_seen_utc": "2026-08-30 15:34:24",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake",
            "anonymous": 0,
            "reporter": "threatcat_ch"
        }
    ],
    "1891484": [
        {
            "ioc_value": "cxgsu17653.workers.dev",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "php.shin_webshell",
            "malware_alias": null,
            "malware_printable": "php.shin_webshell",
            "first_seen_utc": "2026-08-30 15:31:28",
            "last_seen_utc": null,
            "confidence_level": 50,
            "is_compromised": true,
            "reference": null,
            "tags": "Cloudflare,GIF,PHP,webshell,WordPress,workers.dev,wp-admin",
            "anonymous": 0,
            "reporter": "xscon"
        }
    ],
    "1891483": [
        {
            "ioc_value": "kuhekybi.workers.dev",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "php.shin_webshell",
            "malware_alias": null,
            "malware_printable": "php.shin_webshell",
            "first_seen_utc": "2026-08-30 15:30:16",
            "last_seen_utc": null,
            "confidence_level": 50,
            "is_compromised": true,
            "reference": null,
            "tags": "Cloudflare,GIF,PHP,webshell,WordPress,workers.dev,wp-admin",
            "anonymous": 0,
            "reporter": "xscon"
        }
    ],
    "1891482": [
        {
            "ioc_value": "ryqagywe.workers.dev",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "php.shin_webshell",
            "malware_alias": null,
            "malware_printable": "php.shin_webshell",
            "first_seen_utc": "2026-08-30 15:21:08",
            "last_seen_utc": null,
            "confidence_level": 50,
            "is_compromised": true,
            "reference": null,
            "tags": "Cloudflare,GIF,PHP,webshell,WordPress,workers.dev,wp-admin",
            "anonymous": 0,
            "reporter": "xscon"
        }
    ],
    "1891481": [
        {
            "ioc_value": "quzerydu.workers.dev",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "php.shin_webshell",
            "malware_alias": null,
            "malware_printable": "php.shin_webshell",
            "first_seen_utc": "2026-08-30 15:08:15",
            "last_seen_utc": null,
            "confidence_level": 50,
            "is_compromised": true,
            "reference": null,
            "tags": "Cloudflare,GIF,PHP,webshell,WordPress,workers.dev,wp-admin",
            "anonymous": 0,
            "reporter": "xscon"
        }
    ],
    "1891480": [
        {
            "ioc_value": "2uehzspm.prosta-fense.org",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-08-30 15:06:30",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,mac-0xdcf2,macos",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1891479": [
        {
            "ioc_value": "prosta-fense.org",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-08-30 15:02:03",
            "last_seen_utc": "2026-08-30 15:02:10",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "30August2026,ClearFake,Commandline,MacOS",
            "anonymous": 0,
            "reporter": "Gi7w0rm"
        }
    ],
    "1891478": [
        {
            "ioc_value": "zyo61rgc.shop-alphasurge.us",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-08-30 14:58:58",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,mac-0x68dc,macos",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1891477": [
        {
            "ioc_value": "shop-alphasurge.us",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-08-30 14:57:14",
            "last_seen_utc": "2026-08-30 14:58:00",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake",
            "anonymous": 0,
            "reporter": "threatcat_ch"
        }
    ],
    "1891476": [
        {
            "ioc_value": "mdd0cs6ycy.workers.dev",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "php.shin_webshell",
            "malware_alias": null,
            "malware_printable": "php.shin_webshell",
            "first_seen_utc": "2026-08-30 14:43:33",
            "last_seen_utc": null,
            "confidence_level": 50,
            "is_compromised": true,
            "reference": null,
            "tags": "Cloudflare,GIF,PHP,webshell,WordPress,workers.dev,wp-admin",
            "anonymous": 0,
            "reporter": "xscon"
        }
    ],
    "1891474": [
        {
            "ioc_value": "molylasu.workers.dev",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "php.shin_webshell",
            "malware_alias": null,
            "malware_printable": "php.shin_webshell",
            "first_seen_utc": "2026-08-30 14:21:55",
            "last_seen_utc": null,
            "confidence_level": 50,
            "is_compromised": true,
            "reference": null,
            "tags": "Cloudflare,GIF,PHP,webshell,WordPress,workers.dev,wp-admin",
            "anonymous": 0,
            "reporter": "xscon"
        }
    ],
    "1891472": [
        {
            "ioc_value": "yvjqs79906.workers.dev",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "php.shin_webshell",
            "malware_alias": null,
            "malware_printable": "php.shin_webshell",
            "first_seen_utc": "2026-08-30 14:07:37",
            "last_seen_utc": null,
            "confidence_level": 50,
            "is_compromised": true,
            "reference": null,
            "tags": "Cloudflare,GIF,PHP,webshell,WordPress,workers.dev,wp-admin",
            "anonymous": 0,
            "reporter": "xscon"
        }
    ],
    "1891470": [
        {
            "ioc_value": "160.250.128.197:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-08-30 14:05:08",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "supershell",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1891471": [
        {
            "ioc_value": "145.79.143.166:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.vshell",
            "malware_alias": null,
            "malware_printable": "VShell",
            "first_seen_utc": "2026-08-30 14:05:08",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "vshell",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1891469": [
        {
            "ioc_value": "106.53.172.234:30092",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.vshell",
            "malware_alias": null,
            "malware_printable": "VShell",
            "first_seen_utc": "2026-08-30 14:05:07",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "vshell",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1891468": [
        {
            "ioc_value": "121.127.253.146:4444",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-08-30 14:05:05",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "adaptix",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1891467": [
        {
            "ioc_value": "sitykyly.workers.dev",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "php.shin_webshell",
            "malware_alias": null,
            "malware_printable": "php.shin_webshell",
            "first_seen_utc": "2026-08-30 13:55:33",
            "last_seen_utc": null,
            "confidence_level": 50,
            "is_compromised": true,
            "reference": null,
            "tags": "Cloudflare,GIF,PHP,webshell,WordPress,workers.dev,wp-admin",
            "anonymous": 0,
            "reporter": "xscon"
        }
    ],
    "1891466": [
        {
            "ioc_value": "http://cdire.shop:9048/images",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.remus",
            "malware_alias": null,
            "malware_printable": "Remus",
            "first_seen_utc": "2026-08-30 13:50:23",
            "last_seen_utc": null,
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "remus",
            "anonymous": 0,
            "reporter": "Myrtus0x0"
        }
    ],
    "1891465": [
        {
            "ioc_value": "http://flreaow.click:6527/messages",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.remus",
            "malware_alias": null,
            "malware_printable": "Remus",
            "first_seen_utc": "2026-08-30 13:50:22",
            "last_seen_utc": null,
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "remus",
            "anonymous": 0,
            "reporter": "Myrtus0x0"
        }
    ],
    "1891464": [
        {
            "ioc_value": "gmla8hmqnc.workers.dev",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "php.shin_webshell",
            "malware_alias": null,
            "malware_printable": "php.shin_webshell",
            "first_seen_utc": "2026-08-30 13:47:35",
            "last_seen_utc": null,
            "confidence_level": 50,
            "is_compromised": true,
            "reference": null,
            "tags": "Cloudflare,GIF,PHP,webshell,WordPress,workers.dev,wp-admin",
            "anonymous": 0,
            "reporter": "xscon"
        }
    ],
    "1891463": [
        {
            "ioc_value": "lufytiqi.workers.dev",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "php.shin_webshell",
            "malware_alias": null,
            "malware_printable": "php.shin_webshell",
            "first_seen_utc": "2026-08-30 13:43:00",
            "last_seen_utc": null,
            "confidence_level": 50,
            "is_compromised": true,
            "reference": null,
            "tags": "Cloudflare,GIF,PHP,webshell,WordPress,workers.dev,wp-admin",
            "anonymous": 0,
            "reporter": "xscon"
        }
    ],
    "1891462": [
        {
            "ioc_value": "demuqyle.workers.dev",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "php.shin_webshell",
            "malware_alias": null,
            "malware_printable": "php.shin_webshell",
            "first_seen_utc": "2026-08-30 13:24:54",
            "last_seen_utc": null,
            "confidence_level": 50,
            "is_compromised": true,
            "reference": null,
            "tags": "Cloudflare,GIF,PHP,webshell,WordPress,workers.dev,wp-admin",
            "anonymous": 0,
            "reporter": "xscon"
        }
    ],
    "1891460": [
        {
            "ioc_value": "http://uiccvbk.click:8839/notifications",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.remus",
            "malware_alias": null,
            "malware_printable": "Remus",
            "first_seen_utc": "2026-08-30 13:10:21",
            "last_seen_utc": "2026-08-30 14:20:55",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://bazaar.abuse.ch/sample/7a1ecb216f5fb09d8290fb0a5136c118b82f5e264043f839f0259775b05c0c29/",
            "tags": "remus",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1891459": [
        {
            "ioc_value": "http://cdire.shop:9048/imports",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.remus",
            "malware_alias": null,
            "malware_printable": "Remus",
            "first_seen_utc": "2026-08-30 13:10:18",
            "last_seen_utc": "2026-08-30 14:20:55",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://bazaar.abuse.ch/sample/c06a85f0ad8b1fca254994fc3a0953f903aa28027f165d79214bbe3363332939/",
            "tags": "remus",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1891458": [
        {
            "ioc_value": "http://cdire.shop:9048/documents",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.remus",
            "malware_alias": null,
            "malware_printable": "Remus",
            "first_seen_utc": "2026-08-30 13:10:16",
            "last_seen_utc": "2026-08-30 14:20:55",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://bazaar.abuse.ch/sample/7a1ecb216f5fb09d8290fb0a5136c118b82f5e264043f839f0259775b05c0c29/",
            "tags": "remus",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1891456": [
        {
            "ioc_value": "121.127.253.146:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-08-30 13:05:07",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "adaptix",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1891457": [
        {
            "ioc_value": "121.127.253.146:8080",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-08-30 13:05:07",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "adaptix",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1891455": [
        {
            "ioc_value": "121.127.253.146:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-08-30 13:05:06",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "adaptix",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1891454": [
        {
            "ioc_value": "pdrlxmneon.workers.dev",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "php.shin_webshell",
            "malware_alias": null,
            "malware_printable": "php.shin_webshell",
            "first_seen_utc": "2026-08-30 13:04:20",
            "last_seen_utc": null,
            "confidence_level": 50,
            "is_compromised": true,
            "reference": null,
            "tags": "Cloudflare,GIF,PHP,webshell,WordPress,workers.dev,wp-admin",
            "anonymous": 0,
            "reporter": "xscon"
        }
    ],
    "1891453": [
        {
            "ioc_value": "eq7rkug7.shop-alphastreamplus.us",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-08-30 12:58:10",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,mac-0x68dc,macos",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1891452": [
        {
            "ioc_value": "glucotrust-bites.us.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-08-30 12:57:22",
            "last_seen_utc": "2026-08-30 16:56:18",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "30August2026,ClearFake,Commandline,DomainShadowing,Windows",
            "anonymous": 0,
            "reporter": "Gi7w0rm"
        }
    ],
    "1891451": [
        {
            "ioc_value": "shop-alphastreamplus.us",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-08-30 12:56:47",
            "last_seen_utc": "2026-08-30 12:57:40",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake",
            "anonymous": 0,
            "reporter": "threatcat_ch"
        }
    ],
    "1891450": [
        {
            "ioc_value": "https://raw.githubusercontent.com/Kath19634/ural3495/refs/heads/main/fds5412",
            "ioc_type": "url",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-08-30 12:55:21",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake",
            "anonymous": 0,
            "reporter": "threatcat_ch"
        }
    ],
    "1891449": [
        {
            "ioc_value": "84pa4isp.retinaclearofficials.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-08-30 12:55:09",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,mac-0x0f14,macos",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1891448": [
        {
            "ioc_value": "retinaclearofficials.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-08-30 12:52:06",
            "last_seen_utc": "2026-08-30 12:52:12",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "30August2026,ClearFake,Commandline,MacOS",
            "anonymous": 0,
            "reporter": "Gi7w0rm"
        }
    ],
    "1891446": [
        {
            "ioc_value": "lbsa.nova-dev.ch",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-08-30 12:41:12",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": true,
            "reference": null,
            "tags": "compromised,EtherHide",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1891447": [
        {
            "ioc_value": "woodfield.global",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-08-30 12:41:12",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": true,
            "reference": null,
            "tags": "compromised,EtherHide",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1891445": [
        {
            "ioc_value": "toruseli.workers.dev",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "php.shin_webshell",
            "malware_alias": null,
            "malware_printable": "php.shin_webshell",
            "first_seen_utc": "2026-08-30 12:35:38",
            "last_seen_utc": null,
            "confidence_level": 50,
            "is_compromised": true,
            "reference": null,
            "tags": "Cloudflare,GIF,PHP,webshell,WordPress,workers.dev,wp-admin",
            "anonymous": 0,
            "reporter": "xscon"
        }
    ],
    "1891438": [
        {
            "ioc_value": "ciqyzo.workers.dev",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "php.shin_webshell",
            "malware_alias": null,
            "malware_printable": "php.shin_webshell",
            "first_seen_utc": "2026-08-30 12:15:12",
            "last_seen_utc": null,
            "confidence_level": 50,
            "is_compromised": true,
            "reference": null,
            "tags": "Cloudflare,GIF,PHP,webshell,WordPress,workers.dev,wp-admin",
            "anonymous": 0,
            "reporter": "xscon"
        }
    ],
    "1891437": [
        {
            "ioc_value": "jficfycgrz.workers.dev",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "php.shin_webshell",
            "malware_alias": null,
            "malware_printable": "php.shin_webshell",
            "first_seen_utc": "2026-08-30 12:14:19",
            "last_seen_utc": null,
            "confidence_level": 50,
            "is_compromised": true,
            "reference": null,
            "tags": "Cloudflare,GIF,PHP,webshell,WordPress,workers.dev,wp-admin",
            "anonymous": 0,
            "reporter": "xscon"
        }
    ],
    "1891436": [
        {
            "ioc_value": "poqakybe.workers.dev",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "php.shin_webshell",
            "malware_alias": null,
            "malware_printable": "php.shin_webshell",
            "first_seen_utc": "2026-08-30 12:05:15",
            "last_seen_utc": null,
            "confidence_level": 50,
            "is_compromised": true,
            "reference": null,
            "tags": "Cloudflare,GIF,PHP,webshell,WordPress,workers.dev,wp-admin",
            "anonymous": 0,
            "reporter": "xscon"
        }
    ],
    "1891435": [
        {
            "ioc_value": "102.129.165.177:8080",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.vshell",
            "malware_alias": null,
            "malware_printable": "VShell",
            "first_seen_utc": "2026-08-30 12:05:06",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "vshell",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1891433": [
        {
            "ioc_value": "lywixeha.workers.dev",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "php.shin_webshell",
            "malware_alias": null,
            "malware_printable": "php.shin_webshell",
            "first_seen_utc": "2026-08-30 12:01:09",
            "last_seen_utc": null,
            "confidence_level": 50,
            "is_compromised": true,
            "reference": null,
            "tags": "Cloudflare,GIF,PHP,webshell,WordPress,workers.dev,wp-admin",
            "anonymous": 0,
            "reporter": "xscon"
        }
    ],
    "1891434": [
        {
            "ioc_value": "hendersonlawjax.net",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-08-30 12:01:09",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": true,
            "reference": null,
            "tags": "compromised,EtherHide",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1891430": [
        {
            "ioc_value": "46.101.179.59:9034",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.aisuru",
            "malware_alias": null,
            "malware_printable": "Aisuru",
            "first_seen_utc": "2026-08-30 11:55:39",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "Aisuru,c2",
            "anonymous": 0,
            "reporter": "Bitsight"
        }
    ],
    "1891432": [
        {
            "ioc_value": "wazabe.workers.dev",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "php.shin_webshell",
            "malware_alias": null,
            "malware_printable": "php.shin_webshell",
            "first_seen_utc": "2026-08-30 11:38:23",
            "last_seen_utc": null,
            "confidence_level": 50,
            "is_compromised": true,
            "reference": null,
            "tags": "Cloudflare,GIF,PHP,webshell,WordPress,workers.dev,wp-admin",
            "anonymous": 0,
            "reporter": "xscon"
        }
    ],
    "1891431": [
        {
            "ioc_value": "cuzurejo.workers.dev",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "php.shin_webshell",
            "malware_alias": null,
            "malware_printable": "php.shin_webshell",
            "first_seen_utc": "2026-08-30 11:31:00",
            "last_seen_utc": null,
            "confidence_level": 50,
            "is_compromised": true,
            "reference": null,
            "tags": "Cloudflare,GIF,PHP,webshell,WordPress,workers.dev,wp-admin",
            "anonymous": 0,
            "reporter": "xscon"
        }
    ],
    "1891429": [
        {
            "ioc_value": "4u4hidmw.shop-alphaboostpro.us",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-08-30 10:57:37",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,mac-0x68dc,macos",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1891428": [
        {
            "ioc_value": "shop-alphaboostpro.us",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-08-30 10:56:53",
            "last_seen_utc": "2026-08-31 06:41:03",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake",
            "anonymous": 0,
            "reporter": "threatcat_ch"
        }
    ],
    "1891427": [
        {
            "ioc_value": "199.85.8.183:2404",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-08-30 10:55:16",
            "last_seen_utc": "2026-08-31 07:13:21",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://bazaar.abuse.ch/sample/b0f2fe074f097302568a247237554fb52e8001997671a3aa88adfff25e620ac1/",
            "tags": "remcos",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1891426": [
        {
            "ioc_value": "hegitylo.workers.dev",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "php.shin_webshell",
            "malware_alias": null,
            "malware_printable": "php.shin_webshell",
            "first_seen_utc": "2026-08-30 10:54:18",
            "last_seen_utc": null,
            "confidence_level": 50,
            "is_compromised": true,
            "reference": null,
            "tags": "Cloudflare,GIF,PHP,webshell,WordPress,workers.dev,wp-admin",
            "anonymous": 0,
            "reporter": "xscon"
        }
    ],
    "1891425": [
        {
            "ioc_value": "3pynvhuk.ultralightlondon.uk",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-08-30 10:54:11",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,mac-0x0f14,macos",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1891424": [
        {
            "ioc_value": "ultralightlondon.uk",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-08-30 10:53:12",
            "last_seen_utc": "2026-08-30 10:53:19",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "30August2026,ClearFake,Commandline,MacOS",
            "anonymous": 0,
            "reporter": "Gi7w0rm"
        }
    ],
    "1891423": [
        {
            "ioc_value": "yzcza03457.workers.dev",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "php.shin_webshell",
            "malware_alias": null,
            "malware_printable": "php.shin_webshell",
            "first_seen_utc": "2026-08-30 10:50:26",
            "last_seen_utc": null,
            "confidence_level": 50,
            "is_compromised": true,
            "reference": null,
            "tags": "Cloudflare,GIF,PHP,webshell,WordPress,workers.dev,wp-admin",
            "anonymous": 0,
            "reporter": "xscon"
        }
    ],
    "1891422": [
        {
            "ioc_value": "36.255.97.175:8787",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.xworm",
            "malware_alias": null,
            "malware_printable": "XWorm",
            "first_seen_utc": "2026-08-30 10:50:18",
            "last_seen_utc": null,
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://bazaar.abuse.ch/sample/7404b53e27b9a0c6a53a6f01f57874b64acec513ebc90abc38f7f8096bc91cb0/",
            "tags": "xworm",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1891420": [
        {
            "ioc_value": "45.55.191.196:8080",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.aisuru",
            "malware_alias": null,
            "malware_printable": "Aisuru",
            "first_seen_utc": "2026-08-30 10:43:05",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "Aisuru,c2",
            "anonymous": 0,
            "reporter": "Bitsight"
        }
    ],
    "1891421": [
        {
            "ioc_value": "64.89.160.222:65481",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.bashlite",
            "malware_alias": "gayfgt,Gafgyt,qbot,torlus,lizkebab",
            "malware_printable": "Bashlite",
            "first_seen_utc": "2026-08-30 10:43:05",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "Gafgyt",
            "anonymous": 0,
            "reporter": "elfdigest"
        }
    ],
    "1891419": [
        {
            "ioc_value": "zqnro91792.workers.dev",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "php.shin_webshell",
            "malware_alias": null,
            "malware_printable": "php.shin_webshell",
            "first_seen_utc": "2026-08-30 10:34:53",
            "last_seen_utc": null,
            "confidence_level": 50,
            "is_compromised": true,
            "reference": null,
            "tags": "Cloudflare,GIF,PHP,webshell,WordPress,workers.dev,wp-admin",
            "anonymous": 0,
            "reporter": "xscon"
        }
    ],
    "1891418": [
        {
            "ioc_value": "1jtxup9c.pura--boost.us",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-08-30 10:34:51",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,mac-0x76c7,macos",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1891417": [
        {
            "ioc_value": "pura--boost.us",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-08-30 10:33:25",
            "last_seen_utc": "2026-08-30 10:33:45",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake",
            "anonymous": 0,
            "reporter": "threatcat_ch"
        }
    ],
    "1891416": [
        {
            "ioc_value": "gebasaje.workers.dev",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "php.shin_webshell",
            "malware_alias": null,
            "malware_printable": "php.shin_webshell",
            "first_seen_utc": "2026-08-30 10:30:52",
            "last_seen_utc": null,
            "confidence_level": 50,
            "is_compromised": true,
            "reference": null,
            "tags": "Cloudflare,GIF,PHP,webshell,WordPress,workers.dev,wp-admin",
            "anonymous": 0,
            "reporter": "xscon"
        }
    ],
    "1891415": [
        {
            "ioc_value": "xylucyzo.workers.dev",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "php.shin_webshell",
            "malware_alias": null,
            "malware_printable": "php.shin_webshell",
            "first_seen_utc": "2026-08-30 10:23:00",
            "last_seen_utc": null,
            "confidence_level": 50,
            "is_compromised": true,
            "reference": null,
            "tags": "Cloudflare,GIF,PHP,webshell,WordPress,workers.dev,wp-admin",
            "anonymous": 0,
            "reporter": "xscon"
        }
    ],
    "1891414": [
        {
            "ioc_value": "smtp.freshtlemanbarbershop.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-08-30 10:06:02",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": true,
            "reference": null,
            "tags": "ClickFix,compromised",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1891413": [
        {
            "ioc_value": "111.230.143.136:8080",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-08-30 10:05:06",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "viper",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1891412": [
        {
            "ioc_value": "111.230.143.136:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-08-30 10:05:05",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "viper",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1891411": [
        {
            "ioc_value": "curly7588.workers.dev",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "php.shin_webshell",
            "malware_alias": null,
            "malware_printable": "php.shin_webshell",
            "first_seen_utc": "2026-08-30 10:04:54",
            "last_seen_utc": null,
            "confidence_level": 50,
            "is_compromised": true,
            "reference": null,
            "tags": "Cloudflare,GIF,PHP,webshell,WordPress,workers.dev,wp-admin",
            "anonymous": 0,
            "reporter": "xscon"
        }
    ],
    "1891410": [
        {
            "ioc_value": "uehky4jw.prosta--fense.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-08-30 10:02:21",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,mac-0xdcf2,macos",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1891409": [
        {
            "ioc_value": "bufepy.workers.dev",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "php.shin_webshell",
            "malware_alias": null,
            "malware_printable": "php.shin_webshell",
            "first_seen_utc": "2026-08-30 09:47:47",
            "last_seen_utc": null,
            "confidence_level": 50,
            "is_compromised": true,
            "reference": null,
            "tags": "Cloudflare,GIF,PHP,webshell,WordPress,workers.dev,wp-admin",
            "anonymous": 0,
            "reporter": "xscon"
        }
    ],
    "1891408": [
        {
            "ioc_value": "80.190.77.86:2414",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-08-30 09:47:12",
            "last_seen_utc": "2026-08-31 07:47:44",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1891407": [
        {
            "ioc_value": "64.177.112.21:50",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-08-30 09:47:00",
            "last_seen_utc": "2026-08-31 07:47:34",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1891406": [
        {
            "ioc_value": "46.151.182.98:7080",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.hype_agent",
            "malware_alias": null,
            "malware_printable": "HypeAgent",
            "first_seen_utc": "2026-08-30 09:46:48",
            "last_seen_utc": "2026-08-31 07:47:21",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,HypeAgent",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1891405": [
        {
            "ioc_value": "45.156.87.215:1111",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-30 09:46:38",
            "last_seen_utc": "2026-08-31 07:47:10",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1891404": [
        {
            "ioc_value": "37.244.243.56:4433",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.danabot",
            "malware_alias": "DanaTools",
            "malware_printable": "DanaBot",
            "first_seen_utc": "2026-08-30 09:46:25",
            "last_seen_utc": "2026-08-31 07:46:54",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DanBot,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1891403": [
        {
            "ioc_value": "31.57.38.7:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-30 09:46:20",
            "last_seen_utc": "2026-08-31 07:46:48",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1891402": [
        {
            "ioc_value": "217.60.195.109:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-30 09:46:06",
            "last_seen_utc": "2026-08-31 07:46:33",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1891401": [
        {
            "ioc_value": "2.91.185.72:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.havoc",
            "malware_alias": "Havokiz",
            "malware_printable": "Havoc",
            "first_seen_utc": "2026-08-30 09:45:14",
            "last_seen_utc": "2026-08-31 07:45:37",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Havoc",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1891400": [
        {
            "ioc_value": "194.59.30.96:7080",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.hype_agent",
            "malware_alias": null,
            "malware_printable": "HypeAgent",
            "first_seen_utc": "2026-08-30 09:44:54",
            "last_seen_utc": "2026-08-31 07:45:19",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,HypeAgent",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1891399": [
        {
            "ioc_value": "172.174.128.128:8848",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.dcrat",
            "malware_alias": "DarkCrystal RAT",
            "malware_printable": "DCRat",
            "first_seen_utc": "2026-08-30 09:44:14",
            "last_seen_utc": "2026-08-31 07:44:21",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DCRat,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1891397": [
        {
            "ioc_value": "166.88.95.90:5000",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.sliver",
            "malware_alias": null,
            "malware_printable": "Sliver",
            "first_seen_utc": "2026-08-30 09:44:09",
            "last_seen_utc": "2026-08-31 07:44:15",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Sliver",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1891398": [
        {
            "ioc_value": "166.88.95.90:8080",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.sliver",
            "malware_alias": null,
            "malware_printable": "Sliver",
            "first_seen_utc": "2026-08-30 09:44:09",
            "last_seen_utc": "2026-08-31 07:44:15",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Sliver",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1891396": [
        {
            "ioc_value": "104.250.180.85:56013",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-30 09:43:17",
            "last_seen_utc": "2026-08-31 07:43:18",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1891395": [
        {
            "ioc_value": "piwola.workers.dev",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "php.shin_webshell",
            "malware_alias": null,
            "malware_printable": "php.shin_webshell",
            "first_seen_utc": "2026-08-30 09:24:40",
            "last_seen_utc": null,
            "confidence_level": 50,
            "is_compromised": true,
            "reference": null,
            "tags": "Cloudflare,GIF,PHP,webshell,WordPress,workers.dev,wp-admin",
            "anonymous": 0,
            "reporter": "xscon"
        }
    ],
    "1891394": [
        {
            "ioc_value": "distrosummit.xyz",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "unknown_loader",
            "malware_alias": null,
            "malware_printable": "Unknown Loader",
            "first_seen_utc": "2026-08-30 09:19:05",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "OffLoader",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1891393": [
        {
            "ioc_value": "xy08z5pm.shop-aizenpower.us",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-08-30 09:01:24",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,mac-0x68dc,macos",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1891392": [
        {
            "ioc_value": "48dodie.workers.dev",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "php.shin_webshell",
            "malware_alias": null,
            "malware_printable": "php.shin_webshell",
            "first_seen_utc": "2026-08-30 08:57:05",
            "last_seen_utc": null,
            "confidence_level": 50,
            "is_compromised": true,
            "reference": null,
            "tags": "Cloudflare,GIF,PHP,webshell,WordPress,workers.dev,wp-admin",
            "anonymous": 0,
            "reporter": "xscon"
        }
    ],
    "1891391": [
        {
            "ioc_value": "shop-aizenpower.us",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-08-30 08:55:52",
            "last_seen_utc": "2026-08-31 01:40:00",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake",
            "anonymous": 0,
            "reporter": "threatcat_ch"
        }
    ],
    "1891390": [
        {
            "ioc_value": "gfzatydyf8.workers.dev",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "php.shin_webshell",
            "malware_alias": null,
            "malware_printable": "php.shin_webshell",
            "first_seen_utc": "2026-08-30 08:54:43",
            "last_seen_utc": null,
            "confidence_level": 50,
            "is_compromised": true,
            "reference": null,
            "tags": "Cloudflare,GIF,PHP,webshell,WordPress,workers.dev,wp-admin",
            "anonymous": 0,
            "reporter": "xscon"
        }
    ],
    "1891389": [
        {
            "ioc_value": "bixaky.workers.dev",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "php.shin_webshell",
            "malware_alias": null,
            "malware_printable": "php.shin_webshell",
            "first_seen_utc": "2026-08-30 08:51:34",
            "last_seen_utc": null,
            "confidence_level": 50,
            "is_compromised": true,
            "reference": null,
            "tags": "Cloudflare,GIF,PHP,webshell,WordPress,workers.dev,wp-admin",
            "anonymous": 0,
            "reporter": "xscon"
        }
    ],
    "1891388": [
        {
            "ioc_value": "cjbwc69441.workers.dev",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "php.shin_webshell",
            "malware_alias": null,
            "malware_printable": "php.shin_webshell",
            "first_seen_utc": "2026-08-30 08:27:04",
            "last_seen_utc": null,
            "confidence_level": 50,
            "is_compromised": true,
            "reference": null,
            "tags": "Cloudflare,GIF,PHP,webshell,WordPress,workers.dev,wp-admin",
            "anonymous": 0,
            "reporter": "xscon"
        }
    ],
    "1891380": [
        {
            "ioc_value": "103.153.183.25:3231",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-08-30 08:16:51",
            "last_seen_utc": "2026-08-31 03:54:38",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "c2,Remcos,RemoteHost",
            "anonymous": 0,
            "reporter": "Bitsight"
        }
    ],
    "1891382": [
        {
            "ioc_value": "152.42.255.118:8080",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.aisuru",
            "malware_alias": null,
            "malware_printable": "Aisuru",
            "first_seen_utc": "2026-08-30 08:16:51",
            "last_seen_utc": "2026-08-30 23:20:33",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "Aisuru,c2",
            "anonymous": 0,
            "reporter": "Bitsight"
        }
    ],
    "1891387": [
        {
            "ioc_value": "qwxeh11866.workers.dev",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "php.shin_webshell",
            "malware_alias": null,
            "malware_printable": "php.shin_webshell",
            "first_seen_utc": "2026-08-30 08:08:06",
            "last_seen_utc": null,
            "confidence_level": 50,
            "is_compromised": true,
            "reference": null,
            "tags": "Cloudflare,GIF,PHP,webshell,WordPress,workers.dev,wp-admin",
            "anonymous": 0,
            "reporter": "xscon"
        }
    ],
    "1891386": [
        {
            "ioc_value": "111.230.143.136:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-08-30 08:05:10",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "viper",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1891384": [
        {
            "ioc_value": "38.55.200.183:8443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.vshell",
            "malware_alias": null,
            "malware_printable": "VShell",
            "first_seen_utc": "2026-08-30 08:05:09",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "vshell",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1891385": [
        {
            "ioc_value": "111.230.143.136:60000",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-08-30 08:05:09",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "viper",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1891383": [
        {
            "ioc_value": "172.245.91.44:22",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-08-30 08:05:07",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "cobaltstrike",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1891381": [
        {
            "ioc_value": "injured304.workers.dev",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "php.shin_webshell",
            "malware_alias": null,
            "malware_printable": "php.shin_webshell",
            "first_seen_utc": "2026-08-30 07:58:19",
            "last_seen_utc": null,
            "confidence_level": 50,
            "is_compromised": true,
            "reference": null,
            "tags": "Cloudflare,GIF,PHP,webshell,WordPress,workers.dev,wp-admin",
            "anonymous": 0,
            "reporter": "xscon"
        }
    ],
    "1891379": [
        {
            "ioc_value": "lyvoha.workers.dev",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "php.shin_webshell",
            "malware_alias": null,
            "malware_printable": "php.shin_webshell",
            "first_seen_utc": "2026-08-30 07:41:15",
            "last_seen_utc": null,
            "confidence_level": 50,
            "is_compromised": true,
            "reference": null,
            "tags": "Cloudflare,GIF,PHP,webshell,WordPress,workers.dev,wp-admin",
            "anonymous": 0,
            "reporter": "xscon"
        }
    ],
    "1891375": [
        {
            "ioc_value": "demahapa.workers.dev",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "php.shin_webshell",
            "malware_alias": null,
            "malware_printable": "php.shin_webshell",
            "first_seen_utc": "2026-08-30 07:31:55",
            "last_seen_utc": null,
            "confidence_level": 50,
            "is_compromised": true,
            "reference": null,
            "tags": "Cloudflare,GIF,PHP,webshell,WordPress,workers.dev,wp-admin",
            "anonymous": 0,
            "reporter": "xscon"
        }
    ],
    "1891374": [
        {
            "ioc_value": "gawipavy.workers.dev",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "php.shin_webshell",
            "malware_alias": null,
            "malware_printable": "php.shin_webshell",
            "first_seen_utc": "2026-08-30 07:21:26",
            "last_seen_utc": null,
            "confidence_level": 50,
            "is_compromised": true,
            "reference": null,
            "tags": "Cloudflare,GIF,PHP,webshell,WordPress,workers.dev,wp-admin",
            "anonymous": 0,
            "reporter": "xscon"
        }
    ],
    "1891373": [
        {
            "ioc_value": "5462elka.workers.dev",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "php.shin_webshell",
            "malware_alias": null,
            "malware_printable": "php.shin_webshell",
            "first_seen_utc": "2026-08-30 07:14:47",
            "last_seen_utc": null,
            "confidence_level": 50,
            "is_compromised": true,
            "reference": null,
            "tags": "Cloudflare,GIF,PHP,webshell,WordPress,workers.dev,wp-admin",
            "anonymous": 0,
            "reporter": "xscon"
        }
    ],
    "1891088": [
        {
            "ioc_value": "69.167.11.148:2404",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-08-30 07:09:46",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "c2,Remcos,Start-Asegurar",
            "anonymous": 0,
            "reporter": "Bitsight"
        }
    ],
    "1891091": [
        {
            "ioc_value": "190.123.46.208:80",
            "ioc_type": "ip:port",
            "threat_type": "payload_delivery",
            "malware": "elf.mirai",
            "malware_alias": "Katana",
            "malware_printable": "Mirai",
            "first_seen_utc": "2026-08-30 07:09:45",
            "last_seen_utc": null,
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://www.virustotal.com/gui/file/193ea99089cfef206c47bf4e8e335546bdadc3f146374f6ef7489ae8fce4208c",
            "tags": "cowrie,honeypot",
            "anonymous": 0,
            "reporter": "TawnyBalfour"
        }
    ],
    "1891106": [
        {
            "ioc_value": "shift-api-control.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "unknown_rat",
            "malware_alias": null,
            "malware_printable": "Unknown RAT",
            "first_seen_utc": "2026-08-30 07:09:45",
            "last_seen_utc": "2026-08-30 08:25:32",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://github.com/Justice-Hammer/threat-hunting-detections/blob/main/30-research/RES-0007%20-%20ComponentTask33%20MSI%20Loader%20with%20On-Chain%20C2%20Discovery.md",
            "tags": "ComponentTask33,EtherHiding,MSI-loader,NodeJS-RAT,on-chain-c2,Polygon",
            "anonymous": 0,
            "reporter": "Justice_Hammer"
        }
    ],
    "1891107": [
        {
            "ioc_value": "176.65.144.127:3847",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown_rat",
            "malware_alias": null,
            "malware_printable": "Unknown RAT",
            "first_seen_utc": "2026-08-30 07:09:44",
            "last_seen_utc": "2026-08-30 08:25:34",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://github.com/Justice-Hammer/threat-hunting-detections/blob/main/30-research/RES-0007%20-%20ComponentTask33%20MSI%20Loader%20with%20On-Chain%20C2%20Discovery.md",
            "tags": "ComponentTask33,EtherHiding,MSI-loader,NodeJS-RAT,on-chain-c2,Polygon",
            "anonymous": 0,
            "reporter": "Justice_Hammer"
        }
    ],
    "1891108": [
        {
            "ioc_value": "api-configuard.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "unknown_loader",
            "malware_alias": null,
            "malware_printable": "Unknown Loader",
            "first_seen_utc": "2026-08-30 07:09:44",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://github.com/Justice-Hammer/threat-hunting-detections/blob/main/30-research/RES-0007%20-%20ComponentTask33%20MSI%20Loader%20with%20On-Chain%20C2%20Discovery.md",
            "tags": "ComponentTask33,EtherHiding,MSI-loader,NodeJS-RAT,on-chain-c2,Polygon",
            "anonymous": 0,
            "reporter": "Justice_Hammer"
        }
    ],
    "1891127": [
        {
            "ioc_value": "45.74.7.158:4332",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-08-30 07:09:43",
            "last_seen_utc": "2026-08-30 19:15:00",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "c2,Remcos,tor25t",
            "anonymous": 0,
            "reporter": "Bitsight"
        }
    ],
    "1891109": [
        {
            "ioc_value": "82.25.63.146:80",
            "ioc_type": "ip:port",
            "threat_type": "payload_delivery",
            "malware": "unknown_loader",
            "malware_alias": null,
            "malware_printable": "Unknown Loader",
            "first_seen_utc": "2026-08-30 07:09:42",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://github.com/Justice-Hammer/threat-hunting-detections/blob/main/30-research/RES-0007%20-%20ComponentTask33%20MSI%20Loader%20with%20On-Chain%20C2%20Discovery.md",
            "tags": "ComponentTask33,EtherHiding,MSI-loader,NodeJS-RAT,on-chain-c2,Polygon",
            "anonymous": 0,
            "reporter": "Justice_Hammer"
        }
    ],
    "1891131": [
        {
            "ioc_value": "http://103.26.82.216:35366/Mozi.m",
            "ioc_type": "url",
            "threat_type": "payload_delivery",
            "malware": "elf.mozi",
            "malware_alias": null,
            "malware_printable": "Mozi",
            "first_seen_utc": "2026-08-30 07:09:41",
            "last_seen_utc": null,
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://honeylabs.net/lookup/103.26.82.216",
            "tags": "elf,iot,Mozi",
            "anonymous": 0,
            "reporter": "HoneyLabs"
        }
    ],
    "1891132": [
        {
            "ioc_value": "http://139.135.42.31:43969/Mozi.m",
            "ioc_type": "url",
            "threat_type": "payload_delivery",
            "malware": "elf.mozi",
            "malware_alias": null,
            "malware_printable": "Mozi",
            "first_seen_utc": "2026-08-30 07:09:41",
            "last_seen_utc": null,
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://honeylabs.net/lookup/139.135.42.31",
            "tags": "elf,iot,Mozi",
            "anonymous": 0,
            "reporter": "HoneyLabs"
        }
    ],
    "1891190": [
        {
            "ioc_value": "134.122.124.236:8001",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.aisuru",
            "malware_alias": null,
            "malware_printable": "Aisuru",
            "first_seen_utc": "2026-08-30 07:09:40",
            "last_seen_utc": "2026-08-31 08:01:18",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "Aisuru,c2",
            "anonymous": 0,
            "reporter": "Bitsight"
        }
    ],
    "1891191": [
        {
            "ioc_value": "45.55.191.196:8001",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.aisuru",
            "malware_alias": null,
            "malware_printable": "Aisuru",
            "first_seen_utc": "2026-08-30 07:09:39",
            "last_seen_utc": "2026-08-31 08:01:06",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "Aisuru,c2",
            "anonymous": 0,
            "reporter": "Bitsight"
        }
    ],
    "1891192": [
        {
            "ioc_value": "152.42.255.118:8001",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.aisuru",
            "malware_alias": null,
            "malware_printable": "Aisuru",
            "first_seen_utc": "2026-08-30 07:09:39",
            "last_seen_utc": "2026-08-31 08:01:44",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "Aisuru,c2",
            "anonymous": 0,
            "reporter": "Bitsight"
        }
    ],
    "1891193": [
        {
            "ioc_value": "167.99.128.245:8001",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.aisuru",
            "malware_alias": null,
            "malware_printable": "Aisuru",
            "first_seen_utc": "2026-08-30 07:09:38",
            "last_seen_utc": "2026-08-31 07:27:15",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "Aisuru,c2",
            "anonymous": 0,
            "reporter": "Bitsight"
        }
    ],
    "1891194": [
        {
            "ioc_value": "67.205.132.147:8001",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.aisuru",
            "malware_alias": null,
            "malware_printable": "Aisuru",
            "first_seen_utc": "2026-08-30 07:09:38",
            "last_seen_utc": "2026-08-31 08:00:30",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "Aisuru,c2",
            "anonymous": 0,
            "reporter": "Bitsight"
        }
    ],
    "1891197": [
        {
            "ioc_value": "174.138.30.59:8001",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.aisuru",
            "malware_alias": null,
            "malware_printable": "Aisuru",
            "first_seen_utc": "2026-08-30 07:09:37",
            "last_seen_utc": "2026-08-31 08:00:17",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "Aisuru,c2",
            "anonymous": 0,
            "reporter": "Bitsight"
        }
    ],
    "1891195": [
        {
            "ioc_value": "165.22.191.159:8001",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.aisuru",
            "malware_alias": null,
            "malware_printable": "Aisuru",
            "first_seen_utc": "2026-08-30 07:09:36",
            "last_seen_utc": "2026-08-31 08:01:31",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "Aisuru,c2",
            "anonymous": 0,
            "reporter": "Bitsight"
        }
    ],
    "1891196": [
        {
            "ioc_value": "104.248.27.128:8001",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.aisuru",
            "malware_alias": null,
            "malware_printable": "Aisuru",
            "first_seen_utc": "2026-08-30 07:09:35",
            "last_seen_utc": "2026-08-31 08:01:57",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "Aisuru,c2",
            "anonymous": 0,
            "reporter": "Bitsight"
        }
    ],
    "1891198": [
        {
            "ioc_value": "165.22.122.89:9034",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.aisuru",
            "malware_alias": null,
            "malware_printable": "Aisuru",
            "first_seen_utc": "2026-08-30 07:09:35",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "Aisuru,c2",
            "anonymous": 0,
            "reporter": "Bitsight"
        }
    ],
    "1891231": [
        {
            "ioc_value": "https://daskljtitaskastvv.pro/dsasfd555.js",
            "ioc_type": "url",
            "threat_type": "payload_delivery",
            "malware": "win.netsupportmanager_rat",
            "malware_alias": "NetSupport",
            "malware_printable": "NetSupportManager RAT",
            "first_seen_utc": "2026-08-30 07:09:34",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": "https://github.com/Justice-Hammer/threat-hunting-detections/blob/main/10-hunts/HUNT-0005%20-%20ClickFix%20WordPress%20Delivery%20Network%20Hunt.md",
            "tags": "clickfix,evalusion,fake-captcha,merry-florist,netsupport,unc2190,wordpress-injection",
            "anonymous": 0,
            "reporter": "Justice_Hammer"
        }
    ],
    "1891234": [
        {
            "ioc_value": "http://116.109.33.252:33235/Mozi.a",
            "ioc_type": "url",
            "threat_type": "payload_delivery",
            "malware": "elf.mozi",
            "malware_alias": null,
            "malware_printable": "Mozi",
            "first_seen_utc": "2026-08-30 07:09:33",
            "last_seen_utc": null,
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://honeylabs.net/lookup/116.109.33.252",
            "tags": "elf,iot,Mozi",
            "anonymous": 0,
            "reporter": "HoneyLabs"
        }
    ],
    "1891235": [
        {
            "ioc_value": "http://112.25.235.194:60134/Mozi.7",
            "ioc_type": "url",
            "threat_type": "payload_delivery",
            "malware": "elf.mozi",
            "malware_alias": null,
            "malware_printable": "Mozi",
            "first_seen_utc": "2026-08-30 07:09:32",
            "last_seen_utc": null,
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://honeylabs.net/lookup/112.25.235.194",
            "tags": "elf,iot,Mozi",
            "anonymous": 0,
            "reporter": "HoneyLabs"
        }
    ],
    "1891236": [
        {
            "ioc_value": "http://175.107.0.8:44034/Mozi.7",
            "ioc_type": "url",
            "threat_type": "payload_delivery",
            "malware": "elf.mozi",
            "malware_alias": null,
            "malware_printable": "Mozi",
            "first_seen_utc": "2026-08-30 07:09:31",
            "last_seen_utc": null,
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://honeylabs.net/lookup/175.107.0.8",
            "tags": "elf,iot,Mozi",
            "anonymous": 0,
            "reporter": "HoneyLabs"
        }
    ],
    "1891243": [
        {
            "ioc_value": "https://chi.12naga.org",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-08-30 07:09:31",
            "last_seen_utc": "2026-08-31 08:14:07",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "268d1539fef7aab0b99f0b10cc2693b0,c2,loader,stealer,Vidar",
            "anonymous": 0,
            "reporter": "Bitsight"
        }
    ],
    "1891242": [
        {
            "ioc_value": "https://ley.123ful.net",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-08-30 07:09:30",
            "last_seen_utc": "2026-08-31 08:15:18",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "9e42080fd45ba9f402718ea0d28bb085,c2,loader,stealer,Vidar",
            "anonymous": 0,
            "reporter": "Bitsight"
        }
    ],
    "1891245": [
        {
            "ioc_value": "185.195.65.180:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-08-30 07:09:30",
            "last_seen_utc": null,
            "confidence_level": 50,
            "is_compromised": false,
            "reference": null,
            "tags": "57169,c2,censys,cobalt strike",
            "anonymous": 0,
            "reporter": "sojubear"
        }
    ],
    "1891250": [
        {
            "ioc_value": "141.94.96.195:3333",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.xmrig",
            "malware_alias": null,
            "malware_printable": "XMRIG",
            "first_seen_utc": "2026-08-30 07:09:29",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": true,
            "reference": null,
            "tags": "cryptojacking,docker-api,monero,xmrig",
            "anonymous": 0,
            "reporter": "Stateoftheattack"
        }
    ],
    "1891253": [
        {
            "ioc_value": "165.22.191.159:8443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.aisuru",
            "malware_alias": null,
            "malware_printable": "Aisuru",
            "first_seen_utc": "2026-08-30 07:09:28",
            "last_seen_utc": "2026-08-30 17:37:57",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "Aisuru,c2",
            "anonymous": 0,
            "reporter": "Bitsight"
        }
    ],
    "1891294": [
        {
            "ioc_value": "104.248.247.126:9034",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.aisuru",
            "malware_alias": null,
            "malware_printable": "Aisuru",
            "first_seen_utc": "2026-08-30 07:09:28",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "Aisuru,c2",
            "anonymous": 0,
            "reporter": "Bitsight"
        }
    ],
    "1891306": [
        {
            "ioc_value": "174.138.30.59:8443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.aisuru",
            "malware_alias": null,
            "malware_printable": "Aisuru",
            "first_seen_utc": "2026-08-30 07:09:27",
            "last_seen_utc": "2026-08-31 00:25:49",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "Aisuru,c2",
            "anonymous": 0,
            "reporter": "Bitsight"
        }
    ],
    "1891311": [
        {
            "ioc_value": "167.99.194.254:9035",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.aisuru",
            "malware_alias": null,
            "malware_printable": "Aisuru",
            "first_seen_utc": "2026-08-30 07:09:26",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "Aisuru,c2",
            "anonymous": 0,
            "reporter": "Bitsight"
        }
    ],
    "1891312": [
        {
            "ioc_value": "104.248.27.128:8443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.aisuru",
            "malware_alias": null,
            "malware_printable": "Aisuru",
            "first_seen_utc": "2026-08-30 07:09:26",
            "last_seen_utc": "2026-08-31 03:10:21",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "Aisuru,c2",
            "anonymous": 0,
            "reporter": "Bitsight"
        }
    ],
    "1891313": [
        {
            "ioc_value": "67.205.132.147:8443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.aisuru",
            "malware_alias": null,
            "malware_printable": "Aisuru",
            "first_seen_utc": "2026-08-30 07:09:26",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "Aisuru,c2",
            "anonymous": 0,
            "reporter": "Bitsight"
        }
    ],
    "1891314": [
        {
            "ioc_value": "134.122.124.236:8443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.aisuru",
            "malware_alias": null,
            "malware_printable": "Aisuru",
            "first_seen_utc": "2026-08-30 07:09:25",
            "last_seen_utc": "2026-08-31 05:49:38",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "Aisuru,c2",
            "anonymous": 0,
            "reporter": "Bitsight"
        }
    ],
    "1891315": [
        {
            "ioc_value": "188.166.234.214:7528",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remus",
            "malware_alias": null,
            "malware_printable": "Remus",
            "first_seen_utc": "2026-08-30 07:09:25",
            "last_seen_utc": "2026-08-31 05:36:09",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "945c9f3c8cddcb7f33efce50a9a949ad,c2,remus",
            "anonymous": 0,
            "reporter": "Bitsight"
        }
    ],
    "1891321": [
        {
            "ioc_value": "167.99.128.245:34567",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.aisuru",
            "malware_alias": null,
            "malware_printable": "Aisuru",
            "first_seen_utc": "2026-08-30 07:09:24",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "Aisuru,c2",
            "anonymous": 0,
            "reporter": "Bitsight"
        }
    ],
    "1891331": [
        {
            "ioc_value": "log.afghankabobgrill.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-08-30 07:09:24",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": 0,
            "reporter": "penislandrocket"
        }
    ],
    "1891345": [
        {
            "ioc_value": "http://153.117.37.70:33874/Mozi.m",
            "ioc_type": "url",
            "threat_type": "payload_delivery",
            "malware": "elf.mozi",
            "malware_alias": null,
            "malware_printable": "Mozi",
            "first_seen_utc": "2026-08-30 07:09:24",
            "last_seen_utc": null,
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://honeylabs.net/lookup/153.117.37.70",
            "tags": "elf,iot,Mozi",
            "anonymous": 0,
            "reporter": "HoneyLabs"
        }
    ],
    "1891364": [
        {
            "ioc_value": "152.42.255.118:8443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.aisuru",
            "malware_alias": null,
            "malware_printable": "Aisuru",
            "first_seen_utc": "2026-08-30 07:09:21",
            "last_seen_utc": "2026-08-31 06:22:46",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "Aisuru,c2",
            "anonymous": 0,
            "reporter": "Bitsight"
        }
    ],
    "1891365": [
        {
            "ioc_value": "159.65.50.202:8080",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.aisuru",
            "malware_alias": null,
            "malware_printable": "Aisuru",
            "first_seen_utc": "2026-08-30 07:09:21",
            "last_seen_utc": "2026-08-30 08:31:50",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "Aisuru,c2",
            "anonymous": 0,
            "reporter": "Bitsight"
        }
    ],
    "1891372": [
        {
            "ioc_value": "47.113.179.196:8085",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.vshell",
            "malware_alias": null,
            "malware_printable": "VShell",
            "first_seen_utc": "2026-08-30 07:05:06",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "vshell",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1891370": [
        {
            "ioc_value": "123.254.106.168:8084",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.vshell",
            "malware_alias": null,
            "malware_printable": "VShell",
            "first_seen_utc": "2026-08-30 07:05:05",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "vshell",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1891371": [
        {
            "ioc_value": "118.99.55.153:8083",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.vshell",
            "malware_alias": null,
            "malware_printable": "VShell",
            "first_seen_utc": "2026-08-30 07:05:05",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "vshell",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1891369": [
        {
            "ioc_value": "significant615.workers.dev",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "php.shin_webshell",
            "malware_alias": null,
            "malware_printable": "php.shin_webshell",
            "first_seen_utc": "2026-08-30 07:03:17",
            "last_seen_utc": null,
            "confidence_level": 50,
            "is_compromised": true,
            "reference": null,
            "tags": "Cloudflare,GIF,PHP,webshell,WordPress,workers.dev,wp-admin",
            "anonymous": 0,
            "reporter": "xscon"
        }
    ],
    "1891368": [
        {
            "ioc_value": "quy30mlr.shop-aeroslim.us",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-08-30 06:59:14",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,mac-0x68dc,macos",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1891367": [
        {
            "ioc_value": "levulibo.workers.dev",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "php.shin_webshell",
            "malware_alias": null,
            "malware_printable": "php.shin_webshell",
            "first_seen_utc": "2026-08-30 06:57:14",
            "last_seen_utc": null,
            "confidence_level": 50,
            "is_compromised": true,
            "reference": null,
            "tags": "Cloudflare,GIF,PHP,webshell,WordPress,workers.dev,wp-admin",
            "anonymous": 0,
            "reporter": "xscon"
        }
    ],
    "1891366": [
        {
            "ioc_value": "shop-aeroslim.us",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-08-30 06:55:19",
            "last_seen_utc": "2026-08-30 20:39:23",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake",
            "anonymous": 0,
            "reporter": "threatcat_ch"
        }
    ],
    "1891363": [
        {
            "ioc_value": "s0bhultx.thirtyonehat.net",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-08-30 06:43:00",
            "last_seen_utc": "2026-08-30 06:43:17",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,mac-0x0f14,macos",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1891362": [
        {
            "ioc_value": "jyxali.workers.dev",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "php.shin_webshell",
            "malware_alias": null,
            "malware_printable": "php.shin_webshell",
            "first_seen_utc": "2026-08-30 06:41:42",
            "last_seen_utc": null,
            "confidence_level": 50,
            "is_compromised": true,
            "reference": null,
            "tags": "Cloudflare,GIF,PHP,webshell,WordPress,workers.dev,wp-admin",
            "anonymous": 0,
            "reporter": "xscon"
        }
    ],
    "1891360": [
        {
            "ioc_value": "http://flreaow.click:6527/customers",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.remus",
            "malware_alias": null,
            "malware_printable": "Remus",
            "first_seen_utc": "2026-08-30 06:40:55",
            "last_seen_utc": null,
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "remus",
            "anonymous": 0,
            "reporter": "Myrtus0x0"
        }
    ],
    "1891361": [
        {
            "ioc_value": "http://shhsift.click:7647/products",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.remus",
            "malware_alias": null,
            "malware_printable": "Remus",
            "first_seen_utc": "2026-08-30 06:40:55",
            "last_seen_utc": null,
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "remus",
            "anonymous": 0,
            "reporter": "Myrtus0x0"
        }
    ],
    "1891359": [
        {
            "ioc_value": "boyenspray.arrow-it.dev",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-08-30 06:40:50",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": true,
            "reference": null,
            "tags": "compromised,EtherHide",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1891356": [
        {
            "ioc_value": "1c250ac3db43c8379591c0a1e8e428b972c1adda38eec2fb46376fb905e0a5e1",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "win.nanocore",
            "malware_alias": "Nancrat,NanoCore",
            "malware_printable": "Nanocore RAT",
            "first_seen_utc": "2026-08-30 06:34:01",
            "last_seen_utc": null,
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1891357": [
        {
            "ioc_value": "a7306d1131fc113334101d30db8b5b0fa376665b",
            "ioc_type": "sha1_hash",
            "threat_type": "payload",
            "malware": "win.nanocore",
            "malware_alias": "Nancrat,NanoCore",
            "malware_printable": "Nanocore RAT",
            "first_seen_utc": "2026-08-30 06:34:01",
            "last_seen_utc": null,
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1891358": [
        {
            "ioc_value": "df436f62af38b7a5bcd8a3368a9f110a",
            "ioc_type": "md5_hash",
            "threat_type": "payload",
            "malware": "win.nanocore",
            "malware_alias": "Nancrat,NanoCore",
            "malware_printable": "Nanocore RAT",
            "first_seen_utc": "2026-08-30 06:34:01",
            "last_seen_utc": null,
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1891354": [
        {
            "ioc_value": "6daf41bd96b45d41c4a6c149efda326e5baf663e",
            "ioc_type": "sha1_hash",
            "threat_type": "payload",
            "malware": "win.quasar_rat",
            "malware_alias": "CinaRAT,QuasarRAT,Yggdrasil",
            "malware_printable": "Quasar RAT",
            "first_seen_utc": "2026-08-30 06:34:00",
            "last_seen_utc": null,
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1891355": [
        {
            "ioc_value": "f6db29a1c53467f9d613666064785e98",
            "ioc_type": "md5_hash",
            "threat_type": "payload",
            "malware": "win.quasar_rat",
            "malware_alias": "CinaRAT,QuasarRAT,Yggdrasil",
            "malware_printable": "Quasar RAT",
            "first_seen_utc": "2026-08-30 06:34:00",
            "last_seen_utc": null,
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1891351": [
        {
            "ioc_value": "5d1307ffad96536894481fead93401448cc6adac",
            "ioc_type": "sha1_hash",
            "threat_type": "payload",
            "malware": "win.coinminer",
            "malware_alias": null,
            "malware_printable": "Coinminer",
            "first_seen_utc": "2026-08-30 06:33:59",
            "last_seen_utc": null,
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1891352": [
        {
            "ioc_value": "99ad52820bd7ae090c578610e367fcdb",
            "ioc_type": "md5_hash",
            "threat_type": "payload",
            "malware": "win.coinminer",
            "malware_alias": null,
            "malware_printable": "Coinminer",
            "first_seen_utc": "2026-08-30 06:33:59",
            "last_seen_utc": null,
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1891353": [
        {
            "ioc_value": "95dc20449c307be8bad1541a3fbf53ee6c9a107f9add5811f744ee33e344b63d",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "win.quasar_rat",
            "malware_alias": "CinaRAT,QuasarRAT,Yggdrasil",
            "malware_printable": "Quasar RAT",
            "first_seen_utc": "2026-08-30 06:33:59",
            "last_seen_utc": null,
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1891348": [
        {
            "ioc_value": "d313053982390ae6a4707aeba20451cfc13fc88e",
            "ioc_type": "sha1_hash",
            "threat_type": "payload",
            "malware": "win.wannacryptor",
            "malware_alias": "Wana Decrypt0r,WannaCry,WannaCrypt,Wcry",
            "malware_printable": "WannaCryptor",
            "first_seen_utc": "2026-08-30 06:33:58",
            "last_seen_utc": null,
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1891349": [
        {
            "ioc_value": "70f6dff404b94d943db1514648700cfa",
            "ioc_type": "md5_hash",
            "threat_type": "payload",
            "malware": "win.wannacryptor",
            "malware_alias": "Wana Decrypt0r,WannaCry,WannaCrypt,Wcry",
            "malware_printable": "WannaCryptor",
            "first_seen_utc": "2026-08-30 06:33:58",
            "last_seen_utc": null,
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1891350": [
        {
            "ioc_value": "916cf18c98363cf3419b4d51e9635dd1c610adb3b6d6264aac3f52a02b77541a",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "win.coinminer",
            "malware_alias": null,
            "malware_printable": "Coinminer",
            "first_seen_utc": "2026-08-30 06:33:58",
            "last_seen_utc": null,
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1891347": [
        {
            "ioc_value": "507bbce068c50bc2e2c3907debe65c3bf974ac1c2ace16d15c952bd3a72c15f2",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "win.wannacryptor",
            "malware_alias": "Wana Decrypt0r,WannaCry,WannaCrypt,Wcry",
            "malware_printable": "WannaCryptor",
            "first_seen_utc": "2026-08-30 06:33:57",
            "last_seen_utc": null,
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1891346": [
        {
            "ioc_value": "xutegaje.workers.dev",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "php.shin_webshell",
            "malware_alias": null,
            "malware_printable": "php.shin_webshell",
            "first_seen_utc": "2026-08-30 06:23:24",
            "last_seen_utc": null,
            "confidence_level": 50,
            "is_compromised": true,
            "reference": null,
            "tags": "Cloudflare,GIF,PHP,webshell,WordPress,workers.dev,wp-admin",
            "anonymous": 0,
            "reporter": "xscon"
        }
    ],
    "1891344": [
        {
            "ioc_value": "boqoca.workers.dev",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "php.shin_webshell",
            "malware_alias": null,
            "malware_printable": "php.shin_webshell",
            "first_seen_utc": "2026-08-30 06:10:22",
            "last_seen_utc": null,
            "confidence_level": 50,
            "is_compromised": true,
            "reference": null,
            "tags": "Cloudflare,GIF,PHP,webshell,WordPress,workers.dev,wp-admin",
            "anonymous": 0,
            "reporter": "xscon"
        }
    ],
    "1891342": [
        {
            "ioc_value": "172.245.91.44:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-08-30 06:05:07",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "cobaltstrike",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1891343": [
        {
            "ioc_value": "172.245.91.44:8080",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-08-30 06:05:07",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "cobaltstrike",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1891341": [
        {
            "ioc_value": "172.245.91.44:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-08-30 06:05:06",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "cobaltstrike",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1891340": [
        {
            "ioc_value": "188.212.158.203:8808",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-08-30 06:05:05",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "asyncrat",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1891339": [
        {
            "ioc_value": "xuqyzy.workers.dev",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "php.shin_webshell",
            "malware_alias": null,
            "malware_printable": "php.shin_webshell",
            "first_seen_utc": "2026-08-30 05:52:43",
            "last_seen_utc": null,
            "confidence_level": 50,
            "is_compromised": true,
            "reference": null,
            "tags": "Cloudflare,GIF,PHP,webshell,WordPress,workers.dev,wp-admin",
            "anonymous": 0,
            "reporter": "xscon"
        }
    ],
    "1891338": [
        {
            "ioc_value": "ztsuw61048.workers.dev",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "php.shin_webshell",
            "malware_alias": null,
            "malware_printable": "php.shin_webshell",
            "first_seen_utc": "2026-08-30 05:47:57",
            "last_seen_utc": null,
            "confidence_level": 50,
            "is_compromised": true,
            "reference": null,
            "tags": "Cloudflare,GIF,PHP,webshell,WordPress,workers.dev,wp-admin",
            "anonymous": 0,
            "reporter": "xscon"
        }
    ],
    "1891337": [
        {
            "ioc_value": "ln20gg35dp.workers.dev",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "php.shin_webshell",
            "malware_alias": null,
            "malware_printable": "php.shin_webshell",
            "first_seen_utc": "2026-08-30 05:44:56",
            "last_seen_utc": null,
            "confidence_level": 50,
            "is_compromised": true,
            "reference": null,
            "tags": "Cloudflare,GIF,PHP,webshell,WordPress,workers.dev,wp-admin",
            "anonymous": 0,
            "reporter": "xscon"
        }
    ],
    "1891336": [
        {
            "ioc_value": "pamole.workers.dev",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "php.shin_webshell",
            "malware_alias": null,
            "malware_printable": "php.shin_webshell",
            "first_seen_utc": "2026-08-30 05:37:03",
            "last_seen_utc": null,
            "confidence_level": 50,
            "is_compromised": true,
            "reference": null,
            "tags": "Cloudflare,GIF,PHP,webshell,WordPress,workers.dev,wp-admin",
            "anonymous": 0,
            "reporter": "xscon"
        }
    ],
    "1891335": [
        {
            "ioc_value": "76fz7fl1.thegvgalleryco.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-08-30 05:35:31",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,mac-0x76c7,macos",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1891334": [
        {
            "ioc_value": "log.afghankabobgrill.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-08-30 05:35:04",
            "last_seen_utc": "2026-08-30 08:18:04",
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,ErrTraffic,EtherHiding",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1891333": [
        {
            "ioc_value": "thegvgalleryco.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-08-30 05:32:35",
            "last_seen_utc": "2026-08-30 05:33:08",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake",
            "anonymous": 0,
            "reporter": "threatcat_ch"
        }
    ],
    "1891332": [
        {
            "ioc_value": "niwosatu.workers.dev",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "php.shin_webshell",
            "malware_alias": null,
            "malware_printable": "php.shin_webshell",
            "first_seen_utc": "2026-08-30 05:27:42",
            "last_seen_utc": null,
            "confidence_level": 50,
            "is_compromised": true,
            "reference": null,
            "tags": "Cloudflare,GIF,PHP,webshell,WordPress,workers.dev,wp-admin",
            "anonymous": 0,
            "reporter": "xscon"
        }
    ],
    "1891330": [
        {
            "ioc_value": "waducako.workers.dev",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "php.shin_webshell",
            "malware_alias": null,
            "malware_printable": "php.shin_webshell",
            "first_seen_utc": "2026-08-30 05:09:49",
            "last_seen_utc": null,
            "confidence_level": 50,
            "is_compromised": true,
            "reference": null,
            "tags": "Cloudflare,GIF,PHP,webshell,WordPress,workers.dev,wp-admin",
            "anonymous": 0,
            "reporter": "xscon"
        }
    ],
    "1891329": [
        {
            "ioc_value": "89.126.249.219:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-08-30 05:05:05",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "mythic",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1891328": [
        {
            "ioc_value": "raspberryhillsshop.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-08-30 05:01:49",
            "last_seen_utc": "2026-08-30 05:01:56",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "30August2026,ClearFake,Commandline,MacOS",
            "anonymous": 0,
            "reporter": "Gi7w0rm"
        }
    ],
    "1891327": [
        {
            "ioc_value": "jbyn0h7d.shop-abundancegoddess.us",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-08-30 04:56:19",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,mac-0x68dc,macos",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1891326": [
        {
            "ioc_value": "shop-abundancegoddess.us",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-08-30 04:55:21",
            "last_seen_utc": "2026-08-30 04:55:27",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "30August2026,ClearFake,Commandline,MacOS",
            "anonymous": 0,
            "reporter": "Gi7w0rm"
        }
    ],
    "1891325": [
        {
            "ioc_value": "migelabu.workers.dev",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "php.shin_webshell",
            "malware_alias": null,
            "malware_printable": "php.shin_webshell",
            "first_seen_utc": "2026-08-30 04:55:16",
            "last_seen_utc": null,
            "confidence_level": 50,
            "is_compromised": true,
            "reference": null,
            "tags": "Cloudflare,GIF,PHP,webshell,WordPress,workers.dev,wp-admin",
            "anonymous": 0,
            "reporter": "xscon"
        }
    ],
    "1891324": [
        {
            "ioc_value": "cudww89511.workers.dev",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "php.shin_webshell",
            "malware_alias": null,
            "malware_printable": "php.shin_webshell",
            "first_seen_utc": "2026-08-30 04:47:13",
            "last_seen_utc": null,
            "confidence_level": 50,
            "is_compromised": true,
            "reference": null,
            "tags": "Cloudflare,GIF,PHP,webshell,WordPress,workers.dev,wp-admin",
            "anonymous": 0,
            "reporter": "xscon"
        }
    ],
    "1891323": [
        {
            "ioc_value": "vtfpy96040.workers.dev",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "php.shin_webshell",
            "malware_alias": null,
            "malware_printable": "php.shin_webshell",
            "first_seen_utc": "2026-08-30 04:42:29",
            "last_seen_utc": null,
            "confidence_level": 50,
            "is_compromised": true,
            "reference": null,
            "tags": "Cloudflare,GIF,PHP,webshell,WordPress,workers.dev,wp-admin",
            "anonymous": 0,
            "reporter": "xscon"
        }
    ],
    "1891322": [
        {
            "ioc_value": "biqyhiny.workers.dev",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "php.shin_webshell",
            "malware_alias": null,
            "malware_printable": "php.shin_webshell",
            "first_seen_utc": "2026-08-30 04:40:35",
            "last_seen_utc": null,
            "confidence_level": 50,
            "is_compromised": true,
            "reference": null,
            "tags": "Cloudflare,GIF,PHP,webshell,WordPress,workers.dev,wp-admin",
            "anonymous": 0,
            "reporter": "xscon"
        }
    ],
    "1891320": [
        {
            "ioc_value": "yellingevey.workers.dev",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "php.shin_webshell",
            "malware_alias": null,
            "malware_printable": "php.shin_webshell",
            "first_seen_utc": "2026-08-30 04:29:35",
            "last_seen_utc": null,
            "confidence_level": 50,
            "is_compromised": true,
            "reference": null,
            "tags": "Cloudflare,GIF,PHP,webshell,WordPress,workers.dev,wp-admin",
            "anonymous": 0,
            "reporter": "xscon"
        }
    ],
    "1891319": [
        {
            "ioc_value": "134.122.185.201:6685",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.valley_rat",
            "malware_alias": "Winos",
            "malware_printable": "ValleyRAT",
            "first_seen_utc": "2026-08-30 04:25:13",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "RAT,ValleyRAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1891318": [
        {
            "ioc_value": "134.122.185.201:6698",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.valley_rat",
            "malware_alias": "Winos",
            "malware_printable": "ValleyRAT",
            "first_seen_utc": "2026-08-30 04:25:09",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "RAT,ValleyRAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1891317": [
        {
            "ioc_value": "byrehu.workers.dev",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "php.shin_webshell",
            "malware_alias": null,
            "malware_printable": "php.shin_webshell",
            "first_seen_utc": "2026-08-30 04:14:30",
            "last_seen_utc": null,
            "confidence_level": 50,
            "is_compromised": true,
            "reference": null,
            "tags": "Cloudflare,GIF,PHP,webshell,WordPress,workers.dev,wp-admin",
            "anonymous": 0,
            "reporter": "xscon"
        }
    ],
    "1891316": [
        {
            "ioc_value": "mo6zthwbal.workers.dev",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "php.shin_webshell",
            "malware_alias": null,
            "malware_printable": "php.shin_webshell",
            "first_seen_utc": "2026-08-30 04:13:50",
            "last_seen_utc": null,
            "confidence_level": 50,
            "is_compromised": true,
            "reference": null,
            "tags": "Cloudflare,GIF,PHP,webshell,WordPress,workers.dev,wp-admin",
            "anonymous": 0,
            "reporter": "xscon"
        }
    ],
    "1891310": [
        {
            "ioc_value": "kexelado.workers.dev",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "php.shin_webshell",
            "malware_alias": null,
            "malware_printable": "php.shin_webshell",
            "first_seen_utc": "2026-08-30 03:56:11",
            "last_seen_utc": null,
            "confidence_level": 50,
            "is_compromised": true,
            "reference": null,
            "tags": "Cloudflare,GIF,PHP,webshell,WordPress,workers.dev,wp-admin",
            "anonymous": 0,
            "reporter": "xscon"
        }
    ],
    "1891309": [
        {
            "ioc_value": "y63nxzlm5a.workers.dev",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "php.shin_webshell",
            "malware_alias": null,
            "malware_printable": "php.shin_webshell",
            "first_seen_utc": "2026-08-30 03:40:59",
            "last_seen_utc": null,
            "confidence_level": 50,
            "is_compromised": true,
            "reference": null,
            "tags": "Cloudflare,GIF,PHP,webshell,WordPress,workers.dev,wp-admin",
            "anonymous": 0,
            "reporter": "xscon"
        }
    ],
    "1891308": [
        {
            "ioc_value": "http://cdire.shop:9048/files",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.remus",
            "malware_alias": null,
            "malware_printable": "Remus",
            "first_seen_utc": "2026-08-30 03:38:53",
            "last_seen_utc": null,
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "remus",
            "anonymous": 0,
            "reporter": "Myrtus0x0"
        }
    ],
    "1891307": [
        {
            "ioc_value": "http://flreaow.click:6527/images",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.remus",
            "malware_alias": null,
            "malware_printable": "Remus",
            "first_seen_utc": "2026-08-30 03:38:52",
            "last_seen_utc": null,
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "remus",
            "anonymous": 0,
            "reporter": "Myrtus0x0"
        }
    ],
    "1891305": [
        {
            "ioc_value": "ksqbbc27ir.workers.dev",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "php.shin_webshell",
            "malware_alias": null,
            "malware_printable": "php.shin_webshell",
            "first_seen_utc": "2026-08-30 03:19:59",
            "last_seen_utc": null,
            "confidence_level": 50,
            "is_compromised": true,
            "reference": null,
            "tags": "Cloudflare,GIF,PHP,webshell,WordPress,workers.dev,wp-admin",
            "anonymous": 0,
            "reporter": "xscon"
        }
    ],
    "1891304": [
        {
            "ioc_value": "http://mountat.click:7528/tokens",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.remus",
            "malware_alias": null,
            "malware_printable": "Remus",
            "first_seen_utc": "2026-08-30 03:11:43",
            "last_seen_utc": null,
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "remus",
            "anonymous": 0,
            "reporter": "Myrtus0x0"
        }
    ],
    "1891303": [
        {
            "ioc_value": "rqytbre182.workers.dev",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "php.shin_webshell",
            "malware_alias": null,
            "malware_printable": "php.shin_webshell",
            "first_seen_utc": "2026-08-30 03:07:24",
            "last_seen_utc": null,
            "confidence_level": 50,
            "is_compromised": true,
            "reference": null,
            "tags": "Cloudflare,GIF,PHP,webshell,WordPress,workers.dev,wp-admin",
            "anonymous": 0,
            "reporter": "xscon"
        }
    ],
    "1891302": [
        {
            "ioc_value": "wenoty.workers.dev",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "php.shin_webshell",
            "malware_alias": null,
            "malware_printable": "php.shin_webshell",
            "first_seen_utc": "2026-08-30 03:03:08",
            "last_seen_utc": null,
            "confidence_level": 50,
            "is_compromised": true,
            "reference": null,
            "tags": "Cloudflare,GIF,PHP,webshell,WordPress,workers.dev,wp-admin",
            "anonymous": 0,
            "reporter": "xscon"
        }
    ],
    "1891301": [
        {
            "ioc_value": "gertrudachocolate.workers.dev",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "php.shin_webshell",
            "malware_alias": null,
            "malware_printable": "php.shin_webshell",
            "first_seen_utc": "2026-08-30 02:51:32",
            "last_seen_utc": null,
            "confidence_level": 50,
            "is_compromised": true,
            "reference": null,
            "tags": "Cloudflare,GIF,PHP,webshell,WordPress,workers.dev,wp-admin",
            "anonymous": 0,
            "reporter": "xscon"
        }
    ],
    "1891300": [
        {
            "ioc_value": "rm9jpaae.themertraa.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-08-30 02:37:30",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,mac-0x0f14,macos",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1891299": [
        {
            "ioc_value": "himenuzi.workers.dev",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "php.shin_webshell",
            "malware_alias": null,
            "malware_printable": "php.shin_webshell",
            "first_seen_utc": "2026-08-30 02:32:19",
            "last_seen_utc": null,
            "confidence_level": 50,
            "is_compromised": true,
            "reference": null,
            "tags": "Cloudflare,GIF,PHP,webshell,WordPress,workers.dev,wp-admin",
            "anonymous": 0,
            "reporter": "xscon"
        }
    ],
    "1891298": [
        {
            "ioc_value": "themertraa.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-08-30 02:32:09",
            "last_seen_utc": "2026-08-30 02:32:15",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "30August2026,ClearFake,Commandline,MacOS",
            "anonymous": 0,
            "reporter": "Gi7w0rm"
        }
    ],
    "1891297": [
        {
            "ioc_value": "bubaqupu.workers.dev",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "php.shin_webshell",
            "malware_alias": null,
            "malware_printable": "php.shin_webshell",
            "first_seen_utc": "2026-08-30 02:18:32",
            "last_seen_utc": null,
            "confidence_level": 50,
            "is_compromised": true,
            "reference": null,
            "tags": "Cloudflare,GIF,PHP,webshell,WordPress,workers.dev,wp-admin",
            "anonymous": 0,
            "reporter": "xscon"
        }
    ],
    "1891296": [
        {
            "ioc_value": "mqa24zcwc6.workers.dev",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "php.shin_webshell",
            "malware_alias": null,
            "malware_printable": "php.shin_webshell",
            "first_seen_utc": "2026-08-30 02:07:21",
            "last_seen_utc": null,
            "confidence_level": 50,
            "is_compromised": true,
            "reference": null,
            "tags": "Cloudflare,GIF,PHP,webshell,WordPress,workers.dev,wp-admin",
            "anonymous": 0,
            "reporter": "xscon"
        }
    ],
    "1891295": [
        {
            "ioc_value": "43.136.76.42:8081",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.vshell",
            "malware_alias": null,
            "malware_printable": "VShell",
            "first_seen_utc": "2026-08-30 02:05:05",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "vshell",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1891293": [
        {
            "ioc_value": "shec1y17p3.workers.dev",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "php.shin_webshell",
            "malware_alias": null,
            "malware_printable": "php.shin_webshell",
            "first_seen_utc": "2026-08-30 01:48:17",
            "last_seen_utc": null,
            "confidence_level": 50,
            "is_compromised": true,
            "reference": null,
            "tags": "Cloudflare,GIF,PHP,webshell,WordPress,workers.dev,wp-admin",
            "anonymous": 0,
            "reporter": "xscon"
        }
    ],
    "1891292": [
        {
            "ioc_value": "vcabw71270.workers.dev",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "php.shin_webshell",
            "malware_alias": null,
            "malware_printable": "php.shin_webshell",
            "first_seen_utc": "2026-08-30 01:41:23",
            "last_seen_utc": null,
            "confidence_level": 50,
            "is_compromised": true,
            "reference": null,
            "tags": "Cloudflare,GIF,PHP,webshell,WordPress,workers.dev,wp-admin",
            "anonymous": 0,
            "reporter": "xscon"
        }
    ],
    "1891291": [
        {
            "ioc_value": "mbond38982.workers.dev",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "php.shin_webshell",
            "malware_alias": null,
            "malware_printable": "php.shin_webshell",
            "first_seen_utc": "2026-08-30 01:39:33",
            "last_seen_utc": null,
            "confidence_level": 50,
            "is_compromised": true,
            "reference": null,
            "tags": "Cloudflare,GIF,PHP,webshell,WordPress,workers.dev,wp-admin",
            "anonymous": 0,
            "reporter": "xscon"
        }
    ],
    "1891288": [
        {
            "ioc_value": "a1bde6f032dc7452a8e447e9750a3b14a1e5c7e3803420e8919831fe67b338b7",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-08-30 01:34:48",
            "last_seen_utc": null,
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1891289": [
        {
            "ioc_value": "3dd25cbfe76db155615283f905992030468f3da9",
            "ioc_type": "sha1_hash",
            "threat_type": "payload",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-08-30 01:34:48",
            "last_seen_utc": null,
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1891290": [
        {
            "ioc_value": "fb472c15a793251aeeb03b38bd4a678f",
            "ioc_type": "md5_hash",
            "threat_type": "payload",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-08-30 01:34:48",
            "last_seen_utc": null,
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1891287": [
        {
            "ioc_value": "8bbbf6e8040d137c142bbf1775be770c",
            "ioc_type": "md5_hash",
            "threat_type": "payload",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-08-30 01:34:45",
            "last_seen_utc": "2026-08-30 06:34:32",
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1891285": [
        {
            "ioc_value": "db4a45d88c943be3f60bf216bb6ac8a2d3b70dfa13e9669e402f11e2aaea1b74",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-08-30 01:34:44",
            "last_seen_utc": "2026-08-30 06:34:31",
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1891286": [
        {
            "ioc_value": "0d5f36f78a1cbf922f9e33c348c5693e93e24c06",
            "ioc_type": "sha1_hash",
            "threat_type": "payload",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-08-30 01:34:44",
            "last_seen_utc": "2026-08-30 06:34:32",
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1891282": [
        {
            "ioc_value": "30550319146db843b5987e3bd4f3befcd5dd77ec3f24862db2d0703f5998667c",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "win.valley_rat",
            "malware_alias": "Winos",
            "malware_printable": "ValleyRAT",
            "first_seen_utc": "2026-08-30 01:34:28",
            "last_seen_utc": "2026-08-30 06:34:13",
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1891283": [
        {
            "ioc_value": "eb5e1454e3edc95f364b74c3db91c12c21ad0902",
            "ioc_type": "sha1_hash",
            "threat_type": "payload",
            "malware": "win.valley_rat",
            "malware_alias": "Winos",
            "malware_printable": "ValleyRAT",
            "first_seen_utc": "2026-08-30 01:34:28",
            "last_seen_utc": "2026-08-30 06:34:14",
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1891284": [
        {
            "ioc_value": "d9c681a726183af26a21128279ef0ced",
            "ioc_type": "md5_hash",
            "threat_type": "payload",
            "malware": "win.valley_rat",
            "malware_alias": "Winos",
            "malware_printable": "ValleyRAT",
            "first_seen_utc": "2026-08-30 01:34:28",
            "last_seen_utc": "2026-08-30 06:34:14",
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1891278": [
        {
            "ioc_value": "d6016c0b8acc0c4d73d27019ed290ba5",
            "ioc_type": "md5_hash",
            "threat_type": "payload",
            "malware": "win.valley_rat",
            "malware_alias": "Winos",
            "malware_printable": "ValleyRAT",
            "first_seen_utc": "2026-08-30 01:34:27",
            "last_seen_utc": "2026-08-30 06:34:12",
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1891279": [
        {
            "ioc_value": "1a71cf44e6bf88acc3009341875a6ac584f70f1d8f02517ad08090b6d9c94f84",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "win.valley_rat",
            "malware_alias": "Winos",
            "malware_printable": "ValleyRAT",
            "first_seen_utc": "2026-08-30 01:34:27",
            "last_seen_utc": "2026-08-30 06:34:13",
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1891280": [
        {
            "ioc_value": "b6294d17310ca94f96e129d0ad8901252c8556a7",
            "ioc_type": "sha1_hash",
            "threat_type": "payload",
            "malware": "win.valley_rat",
            "malware_alias": "Winos",
            "malware_printable": "ValleyRAT",
            "first_seen_utc": "2026-08-30 01:34:27",
            "last_seen_utc": "2026-08-30 06:34:13",
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1891281": [
        {
            "ioc_value": "28318ef8d982d051f7ea8987ea303075",
            "ioc_type": "md5_hash",
            "threat_type": "payload",
            "malware": "win.valley_rat",
            "malware_alias": "Winos",
            "malware_printable": "ValleyRAT",
            "first_seen_utc": "2026-08-30 01:34:27",
            "last_seen_utc": "2026-08-30 06:34:13",
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1891276": [
        {
            "ioc_value": "c4476378ccde96e2bcbb413e42d7df500c56b577b3a8a58c5318df96201e0b02",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "win.valley_rat",
            "malware_alias": "Winos",
            "malware_printable": "ValleyRAT",
            "first_seen_utc": "2026-08-30 01:34:26",
            "last_seen_utc": "2026-08-30 06:34:12",
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1891277": [
        {
            "ioc_value": "c639de6cf192fd1f6a1edf72537d92e744bc764b",
            "ioc_type": "sha1_hash",
            "threat_type": "payload",
            "malware": "win.valley_rat",
            "malware_alias": "Winos",
            "malware_printable": "ValleyRAT",
            "first_seen_utc": "2026-08-30 01:34:26",
            "last_seen_utc": "2026-08-30 06:34:12",
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1891273": [
        {
            "ioc_value": "9c927df9fdd83af1b57810daa6cc7712a238d31a860bb8d33c6dacb03f53584d",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "win.stealc",
            "malware_alias": null,
            "malware_printable": "Stealc",
            "first_seen_utc": "2026-08-30 01:34:25",
            "last_seen_utc": "2026-08-30 06:34:10",
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1891274": [
        {
            "ioc_value": "ca3229c74dd6ac34f0f7e2469229865d58dfc89d",
            "ioc_type": "sha1_hash",
            "threat_type": "payload",
            "malware": "win.stealc",
            "malware_alias": null,
            "malware_printable": "Stealc",
            "first_seen_utc": "2026-08-30 01:34:25",
            "last_seen_utc": "2026-08-30 06:34:10",
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1891275": [
        {
            "ioc_value": "7e03150e97b7d8e181ae4092c55b3b27",
            "ioc_type": "md5_hash",
            "threat_type": "payload",
            "malware": "win.stealc",
            "malware_alias": null,
            "malware_printable": "Stealc",
            "first_seen_utc": "2026-08-30 01:34:25",
            "last_seen_utc": "2026-08-30 06:34:11",
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1891270": [
        {
            "ioc_value": "0f1af10b96c08c9aeecf28c2fa238542e667d218df65ce51701aaaeb7dcc75b1",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-08-30 01:34:22",
            "last_seen_utc": "2026-08-30 06:34:06",
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1891271": [
        {
            "ioc_value": "94c1d86395777db22933c0d97cac2b535d543c87",
            "ioc_type": "sha1_hash",
            "threat_type": "payload",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-08-30 01:34:22",
            "last_seen_utc": "2026-08-30 06:34:07",
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1891272": [
        {
            "ioc_value": "0b130d9fec6bb8f9b80b13e110d4e0b0",
            "ioc_type": "md5_hash",
            "threat_type": "payload",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-08-30 01:34:22",
            "last_seen_utc": "2026-08-30 06:34:08",
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1891266": [
        {
            "ioc_value": "e7905f19dc5cebd37e3f9e2f65368b04",
            "ioc_type": "md5_hash",
            "threat_type": "payload",
            "malware": "win.wannacryptor",
            "malware_alias": "Wana Decrypt0r,WannaCry,WannaCrypt,Wcry",
            "malware_printable": "WannaCryptor",
            "first_seen_utc": "2026-08-30 01:34:21",
            "last_seen_utc": "2026-08-30 06:34:05",
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1891267": [
        {
            "ioc_value": "b434022c41d8380221ddd621eaae69b0f0eb2503ac53069ef7f932f45cdf81d7",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "win.coinminer",
            "malware_alias": null,
            "malware_printable": "Coinminer",
            "first_seen_utc": "2026-08-30 01:34:21",
            "last_seen_utc": "2026-08-30 06:34:06",
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1891268": [
        {
            "ioc_value": "8cced0e041a11e7d0d85c3c9b7595e70004b7414",
            "ioc_type": "sha1_hash",
            "threat_type": "payload",
            "malware": "win.coinminer",
            "malware_alias": null,
            "malware_printable": "Coinminer",
            "first_seen_utc": "2026-08-30 01:34:21",
            "last_seen_utc": "2026-08-30 06:34:06",
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1891269": [
        {
            "ioc_value": "c3fb146a44516f025122c71348c36b0e",
            "ioc_type": "md5_hash",
            "threat_type": "payload",
            "malware": "win.coinminer",
            "malware_alias": null,
            "malware_printable": "Coinminer",
            "first_seen_utc": "2026-08-30 01:34:21",
            "last_seen_utc": "2026-08-30 06:34:06",
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1891262": [
        {
            "ioc_value": "1b8bee90a24f2303b3e30d5cbd0d0bb2f7dba242",
            "ioc_type": "sha1_hash",
            "threat_type": "payload",
            "malware": "py.venus_stealer",
            "malware_alias": null,
            "malware_printable": "Venus Stealer",
            "first_seen_utc": "2026-08-30 01:34:20",
            "last_seen_utc": "2026-08-30 06:34:04",
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1891263": [
        {
            "ioc_value": "c5c38ba91507353b7b68c0086fe53274",
            "ioc_type": "md5_hash",
            "threat_type": "payload",
            "malware": "py.venus_stealer",
            "malware_alias": null,
            "malware_printable": "Venus Stealer",
            "first_seen_utc": "2026-08-30 01:34:20",
            "last_seen_utc": "2026-08-30 06:34:05",
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1891264": [
        {
            "ioc_value": "0960a25a046f08f30489bce5f7cc6e83af9b21989f8e937c57722cafe00b2dca",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "win.wannacryptor",
            "malware_alias": "Wana Decrypt0r,WannaCry,WannaCrypt,Wcry",
            "malware_printable": "WannaCryptor",
            "first_seen_utc": "2026-08-30 01:34:20",
            "last_seen_utc": "2026-08-30 06:34:05",
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1891265": [
        {
            "ioc_value": "12da85ebf11415b0837c4930af8ae1f46194e8cb",
            "ioc_type": "sha1_hash",
            "threat_type": "payload",
            "malware": "win.wannacryptor",
            "malware_alias": "Wana Decrypt0r,WannaCry,WannaCrypt,Wcry",
            "malware_printable": "WannaCryptor",
            "first_seen_utc": "2026-08-30 01:34:20",
            "last_seen_utc": "2026-08-30 06:34:05",
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1891258": [
        {
            "ioc_value": "117dc9528d518447ab50ba8114b5a47fd06a7c251ade9e90162df66fcb7fd279",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-08-30 01:34:19",
            "last_seen_utc": "2026-08-30 06:34:03",
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1891259": [
        {
            "ioc_value": "b38e013a2139f76614c42147befaa2d357ab56ec",
            "ioc_type": "sha1_hash",
            "threat_type": "payload",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-08-30 01:34:19",
            "last_seen_utc": "2026-08-30 06:34:03",
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1891260": [
        {
            "ioc_value": "7399b202c9c2fe7479680505e1f55e89",
            "ioc_type": "md5_hash",
            "threat_type": "payload",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-08-30 01:34:19",
            "last_seen_utc": "2026-08-30 06:34:04",
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1891261": [
        {
            "ioc_value": "0970ea5b4f55b1cfee90c06e00ed48dbc861f5eac590b144d4a911b62942abbc",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "py.venus_stealer",
            "malware_alias": null,
            "malware_printable": "Venus Stealer",
            "first_seen_utc": "2026-08-30 01:34:19",
            "last_seen_utc": "2026-08-30 06:34:04",
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1891255": [
        {
            "ioc_value": "11ae2d71c9ccae0fa60dc80eedf85ebf784267c28ca42e9c14fffa06515e097a",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "win.coinminer",
            "malware_alias": null,
            "malware_printable": "Coinminer",
            "first_seen_utc": "2026-08-30 01:34:18",
            "last_seen_utc": "2026-08-30 06:34:02",
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1891256": [
        {
            "ioc_value": "0e6e9304c236469d4e8a62ac9bcbfca6ca7a1114",
            "ioc_type": "sha1_hash",
            "threat_type": "payload",
            "malware": "win.coinminer",
            "malware_alias": null,
            "malware_printable": "Coinminer",
            "first_seen_utc": "2026-08-30 01:34:18",
            "last_seen_utc": "2026-08-30 06:34:03",
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1891257": [
        {
            "ioc_value": "7d7fd1e5a3ef87809b2e82e000f835c7",
            "ioc_type": "md5_hash",
            "threat_type": "payload",
            "malware": "win.coinminer",
            "malware_alias": null,
            "malware_printable": "Coinminer",
            "first_seen_utc": "2026-08-30 01:34:18",
            "last_seen_utc": "2026-08-30 06:34:03",
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1891254": [
        {
            "ioc_value": "gwshh85519.workers.dev",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "php.shin_webshell",
            "malware_alias": null,
            "malware_printable": "php.shin_webshell",
            "first_seen_utc": "2026-08-30 01:32:31",
            "last_seen_utc": null,
            "confidence_level": 50,
            "is_compromised": true,
            "reference": null,
            "tags": "Cloudflare,GIF,PHP,webshell,WordPress,workers.dev,wp-admin",
            "anonymous": 0,
            "reporter": "xscon"
        }
    ],
    "1891251": [
        {
            "ioc_value": "http://shhsift.click:7647/customers",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.remus",
            "malware_alias": null,
            "malware_printable": "Remus",
            "first_seen_utc": "2026-08-30 01:25:55",
            "last_seen_utc": null,
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "remus",
            "anonymous": 0,
            "reporter": "Myrtus0x0"
        }
    ],
    "1891252": [
        {
            "ioc_value": "http://cdire.shop:9048/contacts",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.remus",
            "malware_alias": null,
            "malware_printable": "Remus",
            "first_seen_utc": "2026-08-30 01:25:55",
            "last_seen_utc": null,
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "remus",
            "anonymous": 0,
            "reporter": "Myrtus0x0"
        }
    ],
    "1891248": [
        {
            "ioc_value": "dutylama.workers.dev",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "php.shin_webshell",
            "malware_alias": null,
            "malware_printable": "php.shin_webshell",
            "first_seen_utc": "2026-08-30 01:19:31",
            "last_seen_utc": null,
            "confidence_level": 50,
            "is_compromised": true,
            "reference": null,
            "tags": "Cloudflare,GIF,PHP,webshell,WordPress,workers.dev,wp-admin",
            "anonymous": 0,
            "reporter": "xscon"
        }
    ],
    "1891246": [
        {
            "ioc_value": "161.35.173.98:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-08-30 01:05:06",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "cobaltstrike",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1891247": [
        {
            "ioc_value": "161.35.173.98:8080",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-08-30 01:05:06",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "cobaltstrike",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1891244": [
        {
            "ioc_value": "n9tgy4rfiy.workers.dev",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "php.shin_webshell",
            "malware_alias": null,
            "malware_printable": "php.shin_webshell",
            "first_seen_utc": "2026-08-30 01:00:23",
            "last_seen_utc": null,
            "confidence_level": 50,
            "is_compromised": true,
            "reference": null,
            "tags": "Cloudflare,GIF,PHP,webshell,WordPress,workers.dev,wp-admin",
            "anonymous": 0,
            "reporter": "xscon"
        }
    ],
    "1891241": [
        {
            "ioc_value": "skybap.shop",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-08-30 00:47:21",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": true,
            "reference": null,
            "tags": "compromised,EtherHide",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1891240": [
        {
            "ioc_value": "cw5afior.satoshinakamotoco.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-08-30 00:36:27",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,mac-0x76c7,macos",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1891239": [
        {
            "ioc_value": "ot1ewu6jyq.workers.dev",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "php.shin_webshell",
            "malware_alias": null,
            "malware_printable": "php.shin_webshell",
            "first_seen_utc": "2026-08-30 00:36:12",
            "last_seen_utc": null,
            "confidence_level": 50,
            "is_compromised": true,
            "reference": null,
            "tags": "Cloudflare,GIF,PHP,webshell,WordPress,workers.dev,wp-admin",
            "anonymous": 0,
            "reporter": "xscon"
        }
    ],
    "1891238": [
        {
            "ioc_value": "satoshinakamotoco.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-08-30 00:32:18",
            "last_seen_utc": "2026-08-30 00:32:39",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "30August2026,ClearFake,Commandline,MacOS",
            "anonymous": 0,
            "reporter": "Gi7w0rm"
        }
    ],
    "1891237": [
        {
            "ioc_value": "kusuhuti.workers.dev",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "php.shin_webshell",
            "malware_alias": null,
            "malware_printable": "php.shin_webshell",
            "first_seen_utc": "2026-08-30 00:26:56",
            "last_seen_utc": null,
            "confidence_level": 50,
            "is_compromised": true,
            "reference": null,
            "tags": "Cloudflare,GIF,PHP,webshell,WordPress,workers.dev,wp-admin",
            "anonymous": 0,
            "reporter": "xscon"
        }
    ],
    "1891233": [
        {
            "ioc_value": "suhyjypy.workers.dev",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "php.shin_webshell",
            "malware_alias": null,
            "malware_printable": "php.shin_webshell",
            "first_seen_utc": "2026-08-30 00:08:25",
            "last_seen_utc": null,
            "confidence_level": 50,
            "is_compromised": true,
            "reference": null,
            "tags": "Cloudflare,GIF,PHP,webshell,WordPress,workers.dev,wp-admin",
            "anonymous": 0,
            "reporter": "xscon"
        }
    ],
    "1891232": [
        {
            "ioc_value": "tbs46zz6.nurve-alive.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-08-30 00:07:39",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,mac-0x68dc,macos",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1891230": [
        {
            "ioc_value": "http://flreaow.click:6527/imports",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.remus",
            "malware_alias": null,
            "malware_printable": "Remus",
            "first_seen_utc": "2026-08-30 00:05:53",
            "last_seen_utc": null,
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "remus",
            "anonymous": 0,
            "reporter": "Myrtus0x0"
        }
    ],
    "1891229": [
        {
            "ioc_value": "silver6749.workers.dev",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "php.shin_webshell",
            "malware_alias": null,
            "malware_printable": "php.shin_webshell",
            "first_seen_utc": "2026-08-30 00:04:32",
            "last_seen_utc": null,
            "confidence_level": 50,
            "is_compromised": true,
            "reference": null,
            "tags": "Cloudflare,GIF,PHP,webshell,WordPress,workers.dev,wp-admin",
            "anonymous": 0,
            "reporter": "xscon"
        }
    ],
    "1891228": [
        {
            "ioc_value": "nurve-alive.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-08-30 00:04:27",
            "last_seen_utc": "2026-08-30 00:05:08",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake",
            "anonymous": 0,
            "reporter": "threatcat_ch"
        }
    ],
    "1891227": [
        {
            "ioc_value": "nklav1nt.raspberryhillsco.net",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-08-30 00:03:16",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,mac-0xdcf2,macos",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1891226": [
        {
            "ioc_value": "powulapi.workers.dev",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "php.shin_webshell",
            "malware_alias": null,
            "malware_printable": "php.shin_webshell",
            "first_seen_utc": "2026-08-30 00:01:41",
            "last_seen_utc": null,
            "confidence_level": 50,
            "is_compromised": true,
            "reference": null,
            "tags": "Cloudflare,GIF,PHP,webshell,WordPress,workers.dev,wp-admin",
            "anonymous": 0,
            "reporter": "xscon"
        }
    ],
    "1891225": [
        {
            "ioc_value": "raspberryhillsco.net",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-08-30 00:01:10",
            "last_seen_utc": "2026-08-30 00:01:17",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "30August2026,ClearFake,Commandline,MacOS",
            "anonymous": 0,
            "reporter": "Gi7w0rm"
        }
    ],
    "1891224": [
        {
            "ioc_value": "v9gh4nz9ty.workers.dev",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "php.shin_webshell",
            "malware_alias": null,
            "malware_printable": "php.shin_webshell",
            "first_seen_utc": "2026-08-30 00:01:09",
            "last_seen_utc": null,
            "confidence_level": 50,
            "is_compromised": true,
            "reference": null,
            "tags": "Cloudflare,GIF,PHP,webshell,WordPress,workers.dev,wp-admin",
            "anonymous": 0,
            "reporter": "xscon"
        }
    ],
    "1891223": [
        {
            "ioc_value": "sizype.workers.dev",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "php.shin_webshell",
            "malware_alias": null,
            "malware_printable": "php.shin_webshell",
            "first_seen_utc": "2026-08-30 00:00:15",
            "last_seen_utc": null,
            "confidence_level": 50,
            "is_compromised": true,
            "reference": null,
            "tags": "Cloudflare,GIF,PHP,webshell,WordPress,workers.dev,wp-admin",
            "anonymous": 0,
            "reporter": "xscon"
        }
    ],
    "1891222": [
        {
            "ioc_value": "47.86.9.253:10982",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-08-29 23:47:01",
            "last_seen_utc": "2026-08-31 07:48:53",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1891221": [
        {
            "ioc_value": "161.35.173.98:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-08-29 23:46:50",
            "last_seen_utc": "2026-08-31 07:48:38",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1891220": [
        {
            "ioc_value": "154.94.237.203:8086",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-08-29 23:46:49",
            "last_seen_utc": "2026-08-31 07:48:37",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1891219": [
        {
            "ioc_value": "161-35-173-98.sslip.io",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-08-29 23:46:33",
            "last_seen_utc": "2026-08-31 07:48:13",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1891218": [
        {
            "ioc_value": "round60.workers.dev",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "php.shin_webshell",
            "malware_alias": null,
            "malware_printable": "php.shin_webshell",
            "first_seen_utc": "2026-08-29 23:42:14",
            "last_seen_utc": null,
            "confidence_level": 50,
            "is_compromised": true,
            "reference": null,
            "tags": "Cloudflare,GIF,PHP,webshell,WordPress,workers.dev,wp-admin",
            "anonymous": 0,
            "reporter": "xscon"
        }
    ],
    "1891217": [
        {
            "ioc_value": "http://xightne.click:7242/tokens",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.remus",
            "malware_alias": null,
            "malware_printable": "Remus",
            "first_seen_utc": "2026-08-29 23:39:22",
            "last_seen_utc": null,
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "remus",
            "anonymous": 0,
            "reporter": "Myrtus0x0"
        }
    ],
    "1891216": [
        {
            "ioc_value": "http://fezm.website:9048/webhooks",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.remus",
            "malware_alias": null,
            "malware_printable": "Remus",
            "first_seen_utc": "2026-08-29 23:33:53",
            "last_seen_utc": null,
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "remus",
            "anonymous": 0,
            "reporter": "Myrtus0x0"
        }
    ],
    "1891215": [
        {
            "ioc_value": "ailenerobust.workers.dev",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "php.shin_webshell",
            "malware_alias": null,
            "malware_printable": "php.shin_webshell",
            "first_seen_utc": "2026-08-29 23:27:11",
            "last_seen_utc": null,
            "confidence_level": 50,
            "is_compromised": true,
            "reference": null,
            "tags": "Cloudflare,GIF,PHP,webshell,WordPress,workers.dev,wp-admin",
            "anonymous": 0,
            "reporter": "xscon"
        }
    ],
    "1891214": [
        {
            "ioc_value": "baami.development.tee.education",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-08-29 23:17:15",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": true,
            "reference": null,
            "tags": "compromised,EtherHide",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1891213": [
        {
            "ioc_value": "mkvmd28439.workers.dev",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "php.shin_webshell",
            "malware_alias": null,
            "malware_printable": "php.shin_webshell",
            "first_seen_utc": "2026-08-29 23:15:53",
            "last_seen_utc": null,
            "confidence_level": 50,
            "is_compromised": true,
            "reference": null,
            "tags": "Cloudflare,GIF,PHP,webshell,WordPress,workers.dev,wp-admin",
            "anonymous": 0,
            "reporter": "xscon"
        }
    ],
    "1891212": [
        {
            "ioc_value": "hyvugu.workers.dev",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "php.shin_webshell",
            "malware_alias": null,
            "malware_printable": "php.shin_webshell",
            "first_seen_utc": "2026-08-29 22:59:00",
            "last_seen_utc": null,
            "confidence_level": 50,
            "is_compromised": true,
            "reference": null,
            "tags": "Cloudflare,GIF,PHP,webshell,WordPress,workers.dev,wp-admin",
            "anonymous": 0,
            "reporter": "xscon"
        }
    ],
    "1891211": [
        {
            "ioc_value": "kedide.workers.dev",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "php.shin_webshell",
            "malware_alias": null,
            "malware_printable": "php.shin_webshell",
            "first_seen_utc": "2026-08-29 22:41:10",
            "last_seen_utc": null,
            "confidence_level": 50,
            "is_compromised": true,
            "reference": null,
            "tags": "Cloudflare,GIF,PHP,webshell,WordPress,workers.dev,wp-admin",
            "anonymous": 0,
            "reporter": "xscon"
        }
    ],
    "1891210": [
        {
            "ioc_value": "qpfql84049.workers.dev",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "php.shin_webshell",
            "malware_alias": null,
            "malware_printable": "php.shin_webshell",
            "first_seen_utc": "2026-08-29 22:33:49",
            "last_seen_utc": null,
            "confidence_level": 50,
            "is_compromised": true,
            "reference": null,
            "tags": "Cloudflare,GIF,PHP,webshell,WordPress,workers.dev,wp-admin",
            "anonymous": 0,
            "reporter": "xscon"
        }
    ],
    "1891209": [
        {
            "ioc_value": "arohr77201.workers.dev",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "php.shin_webshell",
            "malware_alias": null,
            "malware_printable": "php.shin_webshell",
            "first_seen_utc": "2026-08-29 22:28:30",
            "last_seen_utc": null,
            "confidence_level": 50,
            "is_compromised": true,
            "reference": null,
            "tags": "Cloudflare,GIF,PHP,webshell,WordPress,workers.dev,wp-admin",
            "anonymous": 0,
            "reporter": "xscon"
        }
    ],
    "1891208": [
        {
            "ioc_value": "mwr6ykxb.thegvgalleryy.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-08-29 22:25:13",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,mac-0x0f14,macos",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1891207": [
        {
            "ioc_value": "miwyti.workers.dev",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "php.shin_webshell",
            "malware_alias": null,
            "malware_printable": "php.shin_webshell",
            "first_seen_utc": "2026-08-29 22:23:45",
            "last_seen_utc": null,
            "confidence_level": 50,
            "is_compromised": true,
            "reference": null,
            "tags": "Cloudflare,GIF,PHP,webshell,WordPress,workers.dev,wp-admin",
            "anonymous": 0,
            "reporter": "xscon"
        }
    ],
    "1891206": [
        {
            "ioc_value": "thegvgalleryy.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-08-29 22:22:12",
            "last_seen_utc": "2026-08-29 22:22:17",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "29August2026,ClearFake,Commandline,MacOS",
            "anonymous": 0,
            "reporter": "Gi7w0rm"
        }
    ],
    "1891205": [
        {
            "ioc_value": "gyjuha.workers.dev",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "php.shin_webshell",
            "malware_alias": null,
            "malware_printable": "php.shin_webshell",
            "first_seen_utc": "2026-08-29 22:20:18",
            "last_seen_utc": null,
            "confidence_level": 50,
            "is_compromised": true,
            "reference": null,
            "tags": "Cloudflare,GIF,PHP,webshell,WordPress,workers.dev,wp-admin",
            "anonymous": 0,
            "reporter": "xscon"
        }
    ],
    "1891204": [
        {
            "ioc_value": "o98orlmh.nurosarp.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-08-29 22:08:30",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,mac-0x68dc,macos",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1891203": [
        {
            "ioc_value": "nurosarp.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-08-29 22:03:56",
            "last_seen_utc": "2026-08-29 22:04:15",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake",
            "anonymous": 0,
            "reporter": "threatcat_ch"
        }
    ],
    "1891201": [
        {
            "ioc_value": "tappancsrendelo.hu",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-08-29 22:02:11",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": true,
            "reference": null,
            "tags": "compromised,EtherHide",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1891202": [
        {
            "ioc_value": "rossinsuranceplans.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-08-29 22:02:11",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": true,
            "reference": null,
            "tags": "compromised,EtherHide",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1891200": [
        {
            "ioc_value": "ymc04wy61g.workers.dev",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "php.shin_webshell",
            "malware_alias": null,
            "malware_printable": "php.shin_webshell",
            "first_seen_utc": "2026-08-29 21:59:48",
            "last_seen_utc": null,
            "confidence_level": 50,
            "is_compromised": true,
            "reference": null,
            "tags": "Cloudflare,GIF,PHP,webshell,WordPress,workers.dev,wp-admin",
            "anonymous": 0,
            "reporter": "xscon"
        }
    ],
    "1891199": [
        {
            "ioc_value": "kekyhu.workers.dev",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "php.shin_webshell",
            "malware_alias": null,
            "malware_printable": "php.shin_webshell",
            "first_seen_utc": "2026-08-29 21:58:05",
            "last_seen_utc": null,
            "confidence_level": 50,
            "is_compromised": true,
            "reference": null,
            "tags": "Cloudflare,GIF,PHP,webshell,WordPress,workers.dev,wp-admin",
            "anonymous": 0,
            "reporter": "xscon"
        }
    ],
    "1891189": [
        {
            "ioc_value": "nugiwy.workers.dev",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "php.shin_webshell",
            "malware_alias": null,
            "malware_printable": "php.shin_webshell",
            "first_seen_utc": "2026-08-29 21:32:21",
            "last_seen_utc": null,
            "confidence_level": 50,
            "is_compromised": true,
            "reference": null,
            "tags": "Cloudflare,GIF,PHP,webshell,WordPress,workers.dev,wp-admin",
            "anonymous": 0,
            "reporter": "xscon"
        }
    ],
    "1891188": [
        {
            "ioc_value": "pm4y2dogij.workers.dev",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "php.shin_webshell",
            "malware_alias": null,
            "malware_printable": "php.shin_webshell",
            "first_seen_utc": "2026-08-29 21:20:51",
            "last_seen_utc": null,
            "confidence_level": 50,
            "is_compromised": true,
            "reference": null,
            "tags": "Cloudflare,GIF,PHP,webshell,WordPress,workers.dev,wp-admin",
            "anonymous": 0,
            "reporter": "xscon"
        }
    ],
    "1891187": [
        {
            "ioc_value": "semuxo.workers.dev",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "php.shin_webshell",
            "malware_alias": null,
            "malware_printable": "php.shin_webshell",
            "first_seen_utc": "2026-08-29 21:15:41",
            "last_seen_utc": null,
            "confidence_level": 50,
            "is_compromised": true,
            "reference": null,
            "tags": "Cloudflare,GIF,PHP,webshell,WordPress,workers.dev,wp-admin",
            "anonymous": 0,
            "reporter": "xscon"
        }
    ],
    "1891186": [
        {
            "ioc_value": "gwtrading.ae",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-08-29 21:02:07",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": true,
            "reference": null,
            "tags": "compromised,EtherHide",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1891185": [
        {
            "ioc_value": "qobemyjo.workers.dev",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "php.shin_webshell",
            "malware_alias": null,
            "malware_printable": "php.shin_webshell",
            "first_seen_utc": "2026-08-29 20:56:14",
            "last_seen_utc": null,
            "confidence_level": 50,
            "is_compromised": true,
            "reference": null,
            "tags": "Cloudflare,GIF,PHP,webshell,WordPress,workers.dev,wp-admin",
            "anonymous": 0,
            "reporter": "xscon"
        }
    ],
    "1891184": [
        {
            "ioc_value": "sjkdf91029.workers.dev",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "php.shin_webshell",
            "malware_alias": null,
            "malware_printable": "php.shin_webshell",
            "first_seen_utc": "2026-08-29 20:56:05",
            "last_seen_utc": null,
            "confidence_level": 50,
            "is_compromised": true,
            "reference": null,
            "tags": "Cloudflare,GIF,PHP,webshell,WordPress,workers.dev,wp-admin",
            "anonymous": 0,
            "reporter": "xscon"
        }
    ],
    "1891183": [
        {
            "ioc_value": "hbiar54800.workers.dev",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "php.shin_webshell",
            "malware_alias": null,
            "malware_printable": "php.shin_webshell",
            "first_seen_utc": "2026-08-29 20:51:18",
            "last_seen_utc": null,
            "confidence_level": 50,
            "is_compromised": true,
            "reference": null,
            "tags": "Cloudflare,GIF,PHP,webshell,WordPress,workers.dev,wp-admin",
            "anonymous": 0,
            "reporter": "xscon"
        }
    ],
    "1891182": [
        {
            "ioc_value": "98candide.workers.dev",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "php.shin_webshell",
            "malware_alias": null,
            "malware_printable": "php.shin_webshell",
            "first_seen_utc": "2026-08-29 20:48:20",
            "last_seen_utc": null,
            "confidence_level": 50,
            "is_compromised": true,
            "reference": null,
            "tags": "Cloudflare,GIF,PHP,webshell,WordPress,workers.dev,wp-admin",
            "anonymous": 0,
            "reporter": "xscon"
        }
    ],
    "1891181": [
        {
            "ioc_value": "0u2eowjgwm.workers.dev",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "php.shin_webshell",
            "malware_alias": null,
            "malware_printable": "php.shin_webshell",
            "first_seen_utc": "2026-08-29 20:37:56",
            "last_seen_utc": null,
            "confidence_level": 50,
            "is_compromised": true,
            "reference": null,
            "tags": "Cloudflare,GIF,PHP,webshell,WordPress,workers.dev,wp-admin",
            "anonymous": 0,
            "reporter": "xscon"
        }
    ],
    "1891180": [
        {
            "ioc_value": "ryzabymy.workers.dev",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "php.shin_webshell",
            "malware_alias": null,
            "malware_printable": "php.shin_webshell",
            "first_seen_utc": "2026-08-29 20:25:55",
            "last_seen_utc": null,
            "confidence_level": 50,
            "is_compromised": true,
            "reference": null,
            "tags": "Cloudflare,GIF,PHP,webshell,WordPress,workers.dev,wp-admin",
            "anonymous": 0,
            "reporter": "xscon"
        }
    ],
    "1891179": [
        {
            "ioc_value": "pt0h0z5vzo.workers.dev",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "php.shin_webshell",
            "malware_alias": null,
            "malware_printable": "php.shin_webshell",
            "first_seen_utc": "2026-08-29 20:16:32",
            "last_seen_utc": null,
            "confidence_level": 50,
            "is_compromised": true,
            "reference": null,
            "tags": "Cloudflare,GIF,PHP,webshell,WordPress,workers.dev,wp-admin",
            "anonymous": 0,
            "reporter": "xscon"
        }
    ],
    "1891178": [
        {
            "ioc_value": "http://spareon.click:8811/folders",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.remus",
            "malware_alias": null,
            "malware_printable": "Remus",
            "first_seen_utc": "2026-08-29 20:05:27",
            "last_seen_utc": "2026-08-29 20:34:21",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://bazaar.abuse.ch/sample/0970ea5b4f55b1cfee90c06e00ed48dbc861f5eac590b144d4a911b62942abbc/",
            "tags": "remus",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1891177": [
        {
            "ioc_value": "gs870sms.nuerovera.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-08-29 20:04:39",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,mac-0x68dc,macos",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1891176": [
        {
            "ioc_value": "nuerovera.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-08-29 20:03:54",
            "last_seen_utc": "2026-08-29 20:04:12",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake",
            "anonymous": 0,
            "reporter": "threatcat_ch"
        }
    ],
    "1891175": [
        {
            "ioc_value": "jrzan65776.workers.dev",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "php.shin_webshell",
            "malware_alias": null,
            "malware_printable": "php.shin_webshell",
            "first_seen_utc": "2026-08-29 19:55:42",
            "last_seen_utc": null,
            "confidence_level": 50,
            "is_compromised": true,
            "reference": null,
            "tags": "Cloudflare,GIF,PHP,webshell,WordPress,workers.dev,wp-admin",
            "anonymous": 0,
            "reporter": "xscon"
        }
    ],
    "1891174": [
        {
            "ioc_value": "94.228.166.168:56003",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-29 19:47:14",
            "last_seen_utc": "2026-08-31 07:48:08",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1891173": [
        {
            "ioc_value": "54.199.206.9:21672",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-08-29 19:46:41",
            "last_seen_utc": "2026-08-31 07:47:29",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1891172": [
        {
            "ioc_value": "52.196.79.161:21672",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-08-29 19:46:40",
            "last_seen_utc": "2026-08-31 07:47:28",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1891171": [
        {
            "ioc_value": "46.246.93.245:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-08-29 19:46:36",
            "last_seen_utc": "2026-08-31 07:47:23",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1891170": [
        {
            "ioc_value": "45.192.169.254:8848",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.dcrat",
            "malware_alias": "DarkCrystal RAT",
            "malware_printable": "DCRat",
            "first_seen_utc": "2026-08-29 19:46:25",
            "last_seen_utc": "2026-08-31 07:47:11",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DCRat,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1891168": [
        {
            "ioc_value": "38.60.252.124:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.dcrat",
            "malware_alias": "DarkCrystal RAT",
            "malware_printable": "DCRat",
            "first_seen_utc": "2026-08-29 19:46:17",
            "last_seen_utc": "2026-08-31 07:46:59",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DCRat,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1891169": [
        {
            "ioc_value": "38.60.252.124:8848",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.dcrat",
            "malware_alias": "DarkCrystal RAT",
            "malware_printable": "DCRat",
            "first_seen_utc": "2026-08-29 19:46:17",
            "last_seen_utc": "2026-08-31 07:46:59",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DCRat,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1891167": [
        {
            "ioc_value": "38.180.250.214:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "js.tsundere",
            "malware_alias": "DinDoor",
            "malware_printable": "Tsundere",
            "first_seen_utc": "2026-08-29 19:46:14",
            "last_seen_utc": "2026-08-31 07:46:57",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DinDoor,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1891165": [
        {
            "ioc_value": "31.76.100.3:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.chaos",
            "malware_alias": "FakeRyuk,RyukJoke,Yashma",
            "malware_printable": "Chaos",
            "first_seen_utc": "2026-08-29 19:46:07",
            "last_seen_utc": "2026-08-31 07:46:49",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CHAOS,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1891166": [
        {
            "ioc_value": "31.76.100.3:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.chaos",
            "malware_alias": "FakeRyuk,RyukJoke,Yashma",
            "malware_printable": "Chaos",
            "first_seen_utc": "2026-08-29 19:46:07",
            "last_seen_utc": "2026-08-31 07:46:49",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CHAOS,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1891164": [
        {
            "ioc_value": "3.113.147.16:21672",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-08-29 19:46:03",
            "last_seen_utc": "2026-08-31 07:46:44",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1891163": [
        {
            "ioc_value": "196.251.121.124:56002",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-29 19:44:52",
            "last_seen_utc": "2026-08-31 07:45:29",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1891162": [
        {
            "ioc_value": "195.20.115.80:52203",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-29 19:44:51",
            "last_seen_utc": "2026-08-31 07:45:27",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1891160": [
        {
            "ioc_value": "194.9.6.35:56002",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-29 19:44:48",
            "last_seen_utc": "2026-08-31 07:45:22",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1891161": [
        {
            "ioc_value": "194.9.6.35:56003",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-29 19:44:48",
            "last_seen_utc": "2026-08-31 07:45:22",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1891159": [
        {
            "ioc_value": "168.222.97.92:56003",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-29 19:44:04",
            "last_seen_utc": "2026-08-31 07:44:17",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1891158": [
        {
            "ioc_value": "132.226.72.227:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-08-29 19:43:33",
            "last_seen_utc": "2026-08-31 07:43:42",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1891157": [
        {
            "ioc_value": "128.90.171.209:7777",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-08-29 19:43:30",
            "last_seen_utc": "2026-08-31 07:43:38",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1891156": [
        {
            "ioc_value": "128.90.105.118:8624",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.dcrat",
            "malware_alias": "DarkCrystal RAT",
            "malware_printable": "DCRat",
            "first_seen_utc": "2026-08-29 19:43:29",
            "last_seen_utc": "2026-08-31 07:43:37",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DCRat,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1891155": [
        {
            "ioc_value": "104.250.180.85:55010",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-29 19:43:15",
            "last_seen_utc": "2026-08-31 07:43:18",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1891154": [
        {
            "ioc_value": "103.98.18.238:8660",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.dcrat",
            "malware_alias": "DarkCrystal RAT",
            "malware_printable": "DCRat",
            "first_seen_utc": "2026-08-29 19:43:10",
            "last_seen_utc": "2026-08-31 07:43:12",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DCRat,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1891153": [
        {
            "ioc_value": "1.69.201.249:9003",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-08-29 19:43:02",
            "last_seen_utc": "2026-08-31 07:43:02",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1891152": [
        {
            "ioc_value": "wizawytu.workers.dev",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "php.shin_webshell",
            "malware_alias": null,
            "malware_printable": "php.shin_webshell",
            "first_seen_utc": "2026-08-29 19:40:54",
            "last_seen_utc": null,
            "confidence_level": 50,
            "is_compromised": true,
            "reference": null,
            "tags": "Cloudflare,GIF,PHP,webshell,WordPress,workers.dev,wp-admin",
            "anonymous": 0,
            "reporter": "xscon"
        }
    ],
    "1891151": [
        {
            "ioc_value": "icindh6d.saintvanityllc.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-08-29 19:34:43",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,mac-0x76c7,macos",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1891150": [
        {
            "ioc_value": "saintvanityllc.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-08-29 19:31:33",
            "last_seen_utc": "2026-08-29 19:31:59",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake",
            "anonymous": 0,
            "reporter": "threatcat_ch"
        }
    ],
    "1891149": [
        {
            "ioc_value": "laxmisynthetics.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-08-29 19:22:02",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": true,
            "reference": null,
            "tags": "compromised,EtherHide",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1891148": [
        {
            "ioc_value": "dteug87599.workers.dev",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "php.shin_webshell",
            "malware_alias": null,
            "malware_printable": "php.shin_webshell",
            "first_seen_utc": "2026-08-29 19:22:00",
            "last_seen_utc": null,
            "confidence_level": 50,
            "is_compromised": true,
            "reference": null,
            "tags": "Cloudflare,GIF,PHP,webshell,WordPress,workers.dev,wp-admin",
            "anonymous": 0,
            "reporter": "xscon"
        }
    ],
    "1891147": [
        {
            "ioc_value": "nrgtg63932.workers.dev",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "php.shin_webshell",
            "malware_alias": null,
            "malware_printable": "php.shin_webshell",
            "first_seen_utc": "2026-08-29 19:20:40",
            "last_seen_utc": null,
            "confidence_level": 50,
            "is_compromised": true,
            "reference": null,
            "tags": "Cloudflare,GIF,PHP,webshell,WordPress,workers.dev,wp-admin",
            "anonymous": 0,
            "reporter": "xscon"
        }
    ],
    "1891146": [
        {
            "ioc_value": "biqyxihu.workers.dev",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "php.shin_webshell",
            "malware_alias": null,
            "malware_printable": "php.shin_webshell",
            "first_seen_utc": "2026-08-29 19:18:16",
            "last_seen_utc": null,
            "confidence_level": 50,
            "is_compromised": true,
            "reference": null,
            "tags": "Cloudflare,GIF,PHP,webshell,WordPress,workers.dev,wp-admin",
            "anonymous": 0,
            "reporter": "xscon"
        }
    ],
    "1891145": [
        {
            "ioc_value": "lyzazusu.workers.dev",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "php.shin_webshell",
            "malware_alias": null,
            "malware_printable": "php.shin_webshell",
            "first_seen_utc": "2026-08-29 19:14:50",
            "last_seen_utc": null,
            "confidence_level": 50,
            "is_compromised": true,
            "reference": null,
            "tags": "Cloudflare,GIF,PHP,webshell,WordPress,workers.dev,wp-admin",
            "anonymous": 0,
            "reporter": "xscon"
        }
    ],
    "1891144": [
        {
            "ioc_value": "38lhdq9v9t.workers.dev",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "php.shin_webshell",
            "malware_alias": null,
            "malware_printable": "php.shin_webshell",
            "first_seen_utc": "2026-08-29 19:05:18",
            "last_seen_utc": null,
            "confidence_level": 50,
            "is_compromised": true,
            "reference": null,
            "tags": "Cloudflare,GIF,PHP,webshell,WordPress,workers.dev,wp-admin",
            "anonymous": 0,
            "reporter": "xscon"
        }
    ],
    "1891143": [
        {
            "ioc_value": "159.198.75.180:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-08-29 19:05:06",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "mythic",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1891142": [
        {
            "ioc_value": "43.163.88.35:445",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-08-29 19:05:05",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "cobaltstrike",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1891141": [
        {
            "ioc_value": "https://clickzona.net/embed/",
            "ioc_type": "url",
            "threat_type": "payload_delivery",
            "malware": "js.iclickfix",
            "malware_alias": null,
            "malware_printable": "IClickFix",
            "first_seen_utc": "2026-08-29 19:02:46",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClickFix",
            "anonymous": 0,
            "reporter": "threatcat_ch"
        }
    ],
    "1891140": [
        {
            "ioc_value": "3agcohuj.peaceinwarr.net",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-08-29 19:02:41",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,mac-0xdcf2,macos",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1891139": [
        {
            "ioc_value": "portfolio-r211.alexandreguillet.fr",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-08-29 19:02:00",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": true,
            "reference": null,
            "tags": "compromised,EtherHide",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1891138": [
        {
            "ioc_value": "peaceinwarr.net",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-08-29 19:00:46",
            "last_seen_utc": "2026-08-29 19:00:52",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "29August2026,ClearFake,Commandline,MacOS",
            "anonymous": 0,
            "reporter": "Gi7w0rm"
        }
    ],
    "1891136": [
        {
            "ioc_value": "www.demenagements-delage-perigueux.fr",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-08-29 18:51:59",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": true,
            "reference": null,
            "tags": "compromised,EtherHide",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1891137": [
        {
            "ioc_value": "www.kmag.it",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-08-29 18:51:59",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": true,
            "reference": null,
            "tags": "compromised,EtherHide",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1891135": [
        {
            "ioc_value": "hwxyl07635.workers.dev",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "php.shin_webshell",
            "malware_alias": null,
            "malware_printable": "php.shin_webshell",
            "first_seen_utc": "2026-08-29 18:45:38",
            "last_seen_utc": null,
            "confidence_level": 50,
            "is_compromised": true,
            "reference": null,
            "tags": "Cloudflare,GIF,PHP,webshell,WordPress,workers.dev,wp-admin",
            "anonymous": 0,
            "reporter": "xscon"
        }
    ],
    "1891134": [
        {
            "ioc_value": "seo.mogacode.ma",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-08-29 18:41:57",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": true,
            "reference": null,
            "tags": "compromised,EtherHide",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1891133": [
        {
            "ioc_value": "vaxabaja.workers.dev",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "php.shin_webshell",
            "malware_alias": null,
            "malware_printable": "php.shin_webshell",
            "first_seen_utc": "2026-08-29 18:38:05",
            "last_seen_utc": null,
            "confidence_level": 50,
            "is_compromised": true,
            "reference": null,
            "tags": "Cloudflare,GIF,PHP,webshell,WordPress,workers.dev,wp-admin",
            "anonymous": 0,
            "reporter": "xscon"
        }
    ],
    "1891130": [
        {
            "ioc_value": "7q9i0yalnt.workers.dev",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "php.shin_webshell",
            "malware_alias": null,
            "malware_printable": "php.shin_webshell",
            "first_seen_utc": "2026-08-29 18:15:56",
            "last_seen_utc": null,
            "confidence_level": 50,
            "is_compromised": true,
            "reference": null,
            "tags": "Cloudflare,GIF,PHP,webshell,WordPress,workers.dev,wp-admin",
            "anonymous": 0,
            "reporter": "xscon"
        }
    ],
    "1891129": [
        {
            "ioc_value": "jjqnwf6c.mertraa.org.uk",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-08-29 18:15:04",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,mac-0x0f14,macos",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1891128": [
        {
            "ioc_value": "mertraa.org.uk",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-08-29 18:11:42",
            "last_seen_utc": "2026-08-29 18:11:49",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "29August2026,ClearFake,Commandline,MacOS",
            "anonymous": 0,
            "reporter": "Gi7w0rm"
        }
    ],
    "1891126": [
        {
            "ioc_value": "flhq6iyb.neurowave.us",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-08-29 18:07:23",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,mac-0x68dc,macos",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1891125": [
        {
            "ioc_value": "holuri.workers.dev",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "php.shin_webshell",
            "malware_alias": null,
            "malware_printable": "php.shin_webshell",
            "first_seen_utc": "2026-08-29 17:58:23",
            "last_seen_utc": null,
            "confidence_level": 50,
            "is_compromised": true,
            "reference": null,
            "tags": "Cloudflare,GIF,PHP,webshell,WordPress,workers.dev,wp-admin",
            "anonymous": 0,
            "reporter": "xscon"
        }
    ],
    "1891124": [
        {
            "ioc_value": "https://raw.githubusercontent.com/Christa6547/unopened/refs/heads/main/matchbox",
            "ioc_type": "url",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-08-29 17:56:47",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake",
            "anonymous": 0,
            "reporter": "threatcat_ch"
        }
    ],
    "1891123": [
        {
            "ioc_value": "sdxzz21626.workers.dev",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "php.shin_webshell",
            "malware_alias": null,
            "malware_printable": "php.shin_webshell",
            "first_seen_utc": "2026-08-29 17:44:26",
            "last_seen_utc": null,
            "confidence_level": 50,
            "is_compromised": true,
            "reference": null,
            "tags": "Cloudflare,GIF,PHP,webshell,WordPress,workers.dev,wp-admin",
            "anonymous": 0,
            "reporter": "xscon"
        }
    ],
    "1891122": [
        {
            "ioc_value": "c82yhw7bs7.workers.dev",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "php.shin_webshell",
            "malware_alias": null,
            "malware_printable": "php.shin_webshell",
            "first_seen_utc": "2026-08-29 17:43:06",
            "last_seen_utc": null,
            "confidence_level": 50,
            "is_compromised": true,
            "reference": null,
            "tags": "Cloudflare,GIF,PHP,webshell,WordPress,workers.dev,wp-admin",
            "anonymous": 0,
            "reporter": "xscon"
        }
    ],
    "1891119": [
        {
            "ioc_value": "https://bestcloudservicesupport.com",
            "ioc_type": "url",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-08-29 17:39:47",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1891120": [
        {
            "ioc_value": "https://bestguardservicesupport.com",
            "ioc_type": "url",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-08-29 17:39:47",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1891121": [
        {
            "ioc_value": "https://bigdealjournal.com",
            "ioc_type": "url",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-08-29 17:39:47",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1891116": [
        {
            "ioc_value": "bestcloudservicesupport.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-08-29 17:39:46",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1891117": [
        {
            "ioc_value": "bestguardservicesupport.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-08-29 17:39:46",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1891118": [
        {
            "ioc_value": "bigdealjournal.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-08-29 17:39:46",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1891115": [
        {
            "ioc_value": "qs0sd7xjfm.workers.dev",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "php.shin_webshell",
            "malware_alias": null,
            "malware_printable": "php.shin_webshell",
            "first_seen_utc": "2026-08-29 17:35:48",
            "last_seen_utc": null,
            "confidence_level": 50,
            "is_compromised": true,
            "reference": null,
            "tags": "Cloudflare,GIF,PHP,webshell,WordPress,workers.dev,wp-admin",
            "anonymous": 0,
            "reporter": "xscon"
        }
    ],
    "1891114": [
        {
            "ioc_value": "nomalipo.workers.dev",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "php.shin_webshell",
            "malware_alias": null,
            "malware_printable": "php.shin_webshell",
            "first_seen_utc": "2026-08-29 17:35:01",
            "last_seen_utc": null,
            "confidence_level": 50,
            "is_compromised": true,
            "reference": null,
            "tags": "Cloudflare,GIF,PHP,webshell,WordPress,workers.dev,wp-admin",
            "anonymous": 0,
            "reporter": "xscon"
        }
    ],
    "1891113": [
        {
            "ioc_value": "zfpij29832.workers.dev",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "php.shin_webshell",
            "malware_alias": null,
            "malware_printable": "php.shin_webshell",
            "first_seen_utc": "2026-08-29 17:18:26",
            "last_seen_utc": null,
            "confidence_level": 50,
            "is_compromised": true,
            "reference": null,
            "tags": "Cloudflare,GIF,PHP,webshell,WordPress,workers.dev,wp-admin",
            "anonymous": 0,
            "reporter": "xscon"
        }
    ],
    "1891112": [
        {
            "ioc_value": "osd9uavwa9.workers.dev",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "php.shin_webshell",
            "malware_alias": null,
            "malware_printable": "php.shin_webshell",
            "first_seen_utc": "2026-08-29 17:10:01",
            "last_seen_utc": null,
            "confidence_level": 50,
            "is_compromised": true,
            "reference": null,
            "tags": "Cloudflare,GIF,PHP,webshell,WordPress,workers.dev,wp-admin",
            "anonymous": 0,
            "reporter": "xscon"
        }
    ],
    "1891111": [
        {
            "ioc_value": "http://shhsift.click:7647/orders",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.remus",
            "malware_alias": null,
            "malware_printable": "Remus",
            "first_seen_utc": "2026-08-29 17:05:15",
            "last_seen_utc": "2026-08-29 18:14:23",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://bazaar.abuse.ch/sample/11142fc49721aed0381514a9fb813cbe1143e05c2a3f5e1180995eda4cc4d005/",
            "tags": "remus",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1891110": [
        {
            "ioc_value": "http://piarl.site:9048/imports",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.remus",
            "malware_alias": null,
            "malware_printable": "Remus",
            "first_seen_utc": "2026-08-29 17:05:12",
            "last_seen_utc": "2026-08-29 18:14:23",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://bazaar.abuse.ch/sample/11142fc49721aed0381514a9fb813cbe1143e05c2a3f5e1180995eda4cc4d005/",
            "tags": "remus",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1891105": [
        {
            "ioc_value": "bmrpo37305.workers.dev",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "php.shin_webshell",
            "malware_alias": null,
            "malware_printable": "php.shin_webshell",
            "first_seen_utc": "2026-08-29 16:49:44",
            "last_seen_utc": null,
            "confidence_level": 50,
            "is_compromised": true,
            "reference": null,
            "tags": "Cloudflare,GIF,PHP,webshell,WordPress,workers.dev,wp-admin",
            "anonymous": 0,
            "reporter": "xscon"
        }
    ],
    "1891104": [
        {
            "ioc_value": "puemr96226.workers.dev",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "php.shin_webshell",
            "malware_alias": null,
            "malware_printable": "php.shin_webshell",
            "first_seen_utc": "2026-08-29 16:43:22",
            "last_seen_utc": null,
            "confidence_level": 50,
            "is_compromised": true,
            "reference": null,
            "tags": "Cloudflare,GIF,PHP,webshell,WordPress,workers.dev,wp-admin",
            "anonymous": 0,
            "reporter": "xscon"
        }
    ],
    "1891103": [
        {
            "ioc_value": "forecast-chaos.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "unknown_loader",
            "malware_alias": null,
            "malware_printable": "Unknown Loader",
            "first_seen_utc": "2026-08-29 16:34:27",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "c2,gate,la02",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1891102": [
        {
            "ioc_value": "lesemi.workers.dev",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "php.shin_webshell",
            "malware_alias": null,
            "malware_printable": "php.shin_webshell",
            "first_seen_utc": "2026-08-29 16:18:19",
            "last_seen_utc": null,
            "confidence_level": 50,
            "is_compromised": true,
            "reference": null,
            "tags": "Cloudflare,GIF,PHP,webshell,WordPress,workers.dev,wp-admin",
            "anonymous": 0,
            "reporter": "xscon"
        }
    ],
    "1891101": [
        {
            "ioc_value": "ambitious56.workers.dev",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "php.shin_webshell",
            "malware_alias": null,
            "malware_printable": "php.shin_webshell",
            "first_seen_utc": "2026-08-29 16:08:57",
            "last_seen_utc": null,
            "confidence_level": 50,
            "is_compromised": true,
            "reference": null,
            "tags": "Cloudflare,GIF,PHP,webshell,WordPress,workers.dev,wp-admin",
            "anonymous": 0,
            "reporter": "xscon"
        }
    ],
    "1891100": [
        {
            "ioc_value": "45.192.105.141:60001",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-08-29 16:05:06",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "viper",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1891099": [
        {
            "ioc_value": "43.163.88.35:139",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-08-29 16:05:05",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "cobaltstrike",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1891098": [
        {
            "ioc_value": "wlwdk84865.workers.dev",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "php.shin_webshell",
            "malware_alias": null,
            "malware_printable": "php.shin_webshell",
            "first_seen_utc": "2026-08-29 16:04:07",
            "last_seen_utc": null,
            "confidence_level": 50,
            "is_compromised": true,
            "reference": null,
            "tags": "Cloudflare,GIF,PHP,webshell,WordPress,workers.dev,wp-admin",
            "anonymous": 0,
            "reporter": "xscon"
        }
    ],
    "1891097": [
        {
            "ioc_value": "kdjik001.neuro-wave.us",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-08-29 16:03:47",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,mac-0x68dc,macos",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1891096": [
        {
            "ioc_value": "neuro-wave.us",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-08-29 16:02:29",
            "last_seen_utc": "2026-08-29 16:03:21",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake",
            "anonymous": 0,
            "reporter": "threatcat_ch"
        }
    ],
    "1891095": [
        {
            "ioc_value": "qefepaky.workers.dev",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "php.shin_webshell",
            "malware_alias": null,
            "malware_printable": "php.shin_webshell",
            "first_seen_utc": "2026-08-29 16:02:10",
            "last_seen_utc": null,
            "confidence_level": 50,
            "is_compromised": true,
            "reference": null,
            "tags": "Cloudflare,GIF,PHP,webshell,WordPress,workers.dev,wp-admin",
            "anonymous": 0,
            "reporter": "xscon"
        }
    ],
    "1891094": [
        {
            "ioc_value": "invisibleharrie.workers.dev",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "php.shin_webshell",
            "malware_alias": null,
            "malware_printable": "php.shin_webshell",
            "first_seen_utc": "2026-08-29 16:01:13",
            "last_seen_utc": null,
            "confidence_level": 50,
            "is_compromised": true,
            "reference": null,
            "tags": "Cloudflare,GIF,PHP,webshell,WordPress,workers.dev,wp-admin",
            "anonymous": 0,
            "reporter": "xscon"
        }
    ],
    "1891093": [
        {
            "ioc_value": "sound-obstacle.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "unknown_loader",
            "malware_alias": null,
            "malware_printable": "Unknown Loader",
            "first_seen_utc": "2026-08-29 16:00:21",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "c2,gate,la02",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1891092": [
        {
            "ioc_value": "meta.study-run.xyz",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.revstealer",
            "malware_alias": null,
            "malware_printable": "RevStealer",
            "first_seen_utc": "2026-08-29 15:58:12",
            "last_seen_utc": null,
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "revstealer",
            "anonymous": 0,
            "reporter": "Myrtus0x0"
        }
    ],
    "1891090": [
        {
            "ioc_value": "kylatyni.workers.dev",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "php.shin_webshell",
            "malware_alias": null,
            "malware_printable": "php.shin_webshell",
            "first_seen_utc": "2026-08-29 15:35:34",
            "last_seen_utc": null,
            "confidence_level": 50,
            "is_compromised": true,
            "reference": null,
            "tags": "Cloudflare,GIF,PHP,webshell,WordPress,workers.dev,wp-admin",
            "anonymous": 0,
            "reporter": "xscon"
        }
    ],
    "1891089": [
        {
            "ioc_value": "maritsaaqua.workers.dev",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "php.shin_webshell",
            "malware_alias": null,
            "malware_printable": "php.shin_webshell",
            "first_seen_utc": "2026-08-29 15:15:58",
            "last_seen_utc": null,
            "confidence_level": 50,
            "is_compromised": true,
            "reference": null,
            "tags": "Cloudflare,GIF,PHP,webshell,WordPress,workers.dev,wp-admin",
            "anonymous": 0,
            "reporter": "xscon"
        }
    ],
    "1891085": [
        {
            "ioc_value": "45.140.213.2:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.havoc",
            "malware_alias": "Havokiz",
            "malware_printable": "Havoc",
            "first_seen_utc": "2026-08-29 15:05:05",
            "last_seen_utc": "2026-08-31 07:47:08",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "havoc",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1891086": [
        {
            "ioc_value": "45.140.213.2:8080",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.havoc",
            "malware_alias": "Havokiz",
            "malware_printable": "Havoc",
            "first_seen_utc": "2026-08-29 15:05:05",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "havoc",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1891087": [
        {
            "ioc_value": "102.117.162.133:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-08-29 15:05:05",
            "last_seen_utc": "2026-08-31 07:43:04",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "mythic",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1891084": [
        {
            "ioc_value": "0p1a6v5vih.workers.dev",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "php.shin_webshell",
            "malware_alias": null,
            "malware_printable": "php.shin_webshell",
            "first_seen_utc": "2026-08-29 14:59:04",
            "last_seen_utc": null,
            "confidence_level": 50,
            "is_compromised": true,
            "reference": null,
            "tags": "Cloudflare,GIF,PHP,webshell,WordPress,workers.dev,wp-admin",
            "anonymous": 0,
            "reporter": "xscon"
        }
    ],
    "1891083": [
        {
            "ioc_value": "https://raw.githubusercontent.com/Kath19634/landowner/refs/heads/main/target",
            "ioc_type": "url",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-08-29 14:53:13",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake",
            "anonymous": 0,
            "reporter": "threatcat_ch"
        }
    ],
    "1891082": [
        {
            "ioc_value": "gluccotrust--bites.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-08-29 14:51:53",
            "last_seen_utc": "2026-08-30 12:54:43",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "29August2026,ClearFake,Commandline,DomainShadowing,Windows",
            "anonymous": 0,
            "reporter": "Gi7w0rm"
        }
    ],
    "1891081": [
        {
            "ioc_value": "rexilafu.workers.dev",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "php.shin_webshell",
            "malware_alias": null,
            "malware_printable": "php.shin_webshell",
            "first_seen_utc": "2026-08-29 14:44:15",
            "last_seen_utc": null,
            "confidence_level": 50,
            "is_compromised": true,
            "reference": null,
            "tags": "Cloudflare,GIF,PHP,webshell,WordPress,workers.dev,wp-admin",
            "anonymous": 0,
            "reporter": "xscon"
        }
    ],
    "1891080": [
        {
            "ioc_value": "volokyli.workers.dev",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "php.shin_webshell",
            "malware_alias": null,
            "malware_printable": "php.shin_webshell",
            "first_seen_utc": "2026-08-29 14:34:39",
            "last_seen_utc": null,
            "confidence_level": 50,
            "is_compromised": true,
            "reference": null,
            "tags": "Cloudflare,GIF,PHP,webshell,WordPress,workers.dev,wp-admin",
            "anonymous": 0,
            "reporter": "xscon"
        }
    ],
    "1891079": [
        {
            "ioc_value": "nhq4h9ts.mertre.net",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-08-29 14:32:15",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,mac-0x76c7,macos",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1891078": [
        {
            "ioc_value": "mertre.net",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-08-29 14:31:11",
            "last_seen_utc": "2026-08-29 14:32:18",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "29August2026,ClearFake,Commandline,MacOS",
            "anonymous": 0,
            "reporter": "Gi7w0rm"
        }
    ],
    "1891077": [
        {
            "ioc_value": "levakike.workers.dev",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "php.shin_webshell",
            "malware_alias": null,
            "malware_printable": "php.shin_webshell",
            "first_seen_utc": "2026-08-29 14:30:08",
            "last_seen_utc": null,
            "confidence_level": 50,
            "is_compromised": true,
            "reference": null,
            "tags": "Cloudflare,GIF,PHP,webshell,WordPress,workers.dev,wp-admin",
            "anonymous": 0,
            "reporter": "xscon"
        }
    ],
    "1891076": [
        {
            "ioc_value": "tocawyso.workers.dev",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "php.shin_webshell",
            "malware_alias": null,
            "malware_printable": "php.shin_webshell",
            "first_seen_utc": "2026-08-29 14:29:32",
            "last_seen_utc": null,
            "confidence_level": 50,
            "is_compromised": true,
            "reference": null,
            "tags": "Cloudflare,GIF,PHP,webshell,WordPress,workers.dev,wp-admin",
            "anonymous": 0,
            "reporter": "xscon"
        }
    ],
    "1891075": [
        {
            "ioc_value": "bacujura.workers.dev",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "php.shin_webshell",
            "malware_alias": null,
            "malware_printable": "php.shin_webshell",
            "first_seen_utc": "2026-08-29 14:22:43",
            "last_seen_utc": null,
            "confidence_level": 50,
            "is_compromised": true,
            "reference": null,
            "tags": "Cloudflare,GIF,PHP,webshell,WordPress,workers.dev,wp-admin",
            "anonymous": 0,
            "reporter": "xscon"
        }
    ],
    "1891074": [
        {
            "ioc_value": "lolykeco.workers.dev",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "php.shin_webshell",
            "malware_alias": null,
            "malware_printable": "php.shin_webshell",
            "first_seen_utc": "2026-08-29 14:17:43",
            "last_seen_utc": null,
            "confidence_level": 50,
            "is_compromised": true,
            "reference": null,
            "tags": "Cloudflare,GIF,PHP,webshell,WordPress,workers.dev,wp-admin",
            "anonymous": 0,
            "reporter": "xscon"
        }
    ],
    "1891021": [
        {
            "ioc_value": "https://playmounthdom.top/",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.stealc",
            "malware_alias": null,
            "malware_printable": "Stealc",
            "first_seen_utc": "2026-08-29 14:08:52",
            "last_seen_utc": "2026-08-31 07:06:55",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "c2,loader,printer,StealC,stealer",
            "anonymous": 0,
            "reporter": "Bitsight"
        }
    ],
    "1891034": [
        {
            "ioc_value": "https://46.225.92.123",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-08-29 14:08:51",
            "last_seen_utc": "2026-08-31 08:15:11",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "052d95aa0b0505a149188acc00af5b78,c2,loader,stealer,Vidar",
            "anonymous": 0,
            "reporter": "Bitsight"
        }
    ],
    "1891043": [
        {
            "ioc_value": "http://203.101.186.166:41052/Mozi.m",
            "ioc_type": "url",
            "threat_type": "payload_delivery",
            "malware": "elf.mozi",
            "malware_alias": null,
            "malware_printable": "Mozi",
            "first_seen_utc": "2026-08-29 14:08:51",
            "last_seen_utc": null,
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://honeylabs.net/lookup/203.101.186.166",
            "tags": "elf,iot,Mozi",
            "anonymous": 0,
            "reporter": "HoneyLabs"
        }
    ],
    "1891073": [
        {
            "ioc_value": "qmoz0g9m.werighteus.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-08-29 14:05:30",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,mac-0x68dc,macos",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1891072": [
        {
            "ioc_value": "45.140.213.2:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.havoc",
            "malware_alias": "Havokiz",
            "malware_printable": "Havoc",
            "first_seen_utc": "2026-08-29 14:05:07",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "havoc",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1891070": [
        {
            "ioc_value": "43.163.88.35:8443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-08-29 14:05:06",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "cobaltstrike",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1891071": [
        {
            "ioc_value": "45.140.213.2:22",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.havoc",
            "malware_alias": "Havokiz",
            "malware_printable": "Havoc",
            "first_seen_utc": "2026-08-29 14:05:06",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "havoc",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1891069": [
        {
            "ioc_value": "43.163.88.35:22",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-08-29 14:05:05",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "cobaltstrike",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1891068": [
        {
            "ioc_value": "mkfbo763.jadedlondon.uk",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-08-29 14:04:48",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,mac-0x0f14,macos",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1891067": [
        {
            "ioc_value": "werighteus.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-08-29 14:01:51",
            "last_seen_utc": "2026-08-29 14:02:31",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake",
            "anonymous": 0,
            "reporter": "threatcat_ch"
        }
    ],
    "1891066": [
        {
            "ioc_value": "xp0re0bg.oucloud.com.mx",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-08-29 14:01:29",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,mac-0xdcf2,macos",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1891065": [
        {
            "ioc_value": "jadedlondon.uk",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-08-29 14:01:02",
            "last_seen_utc": "2026-08-29 14:01:09",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "29August2026,ClearFake,Commandline,MacOS",
            "anonymous": 0,
            "reporter": "Gi7w0rm"
        }
    ],
    "1891064": [
        {
            "ioc_value": "oucloud.com.mx",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-08-29 13:59:37",
            "last_seen_utc": "2026-08-29 13:59:44",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "29August2026,ClearFake,Commandline,MacOS",
            "anonymous": 0,
            "reporter": "Gi7w0rm"
        }
    ],
    "1891063": [
        {
            "ioc_value": "20kari.workers.dev",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "php.shin_webshell",
            "malware_alias": null,
            "malware_printable": "php.shin_webshell",
            "first_seen_utc": "2026-08-29 13:52:49",
            "last_seen_utc": null,
            "confidence_level": 50,
            "is_compromised": true,
            "reference": null,
            "tags": "Cloudflare,GIF,PHP,webshell,WordPress,workers.dev,wp-admin",
            "anonymous": 0,
            "reporter": "xscon"
        }
    ],
    "1891062": [
        {
            "ioc_value": "7ti.li",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-08-29 13:14:03",
            "last_seen_utc": "2026-08-30 15:41:11",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "29August2026,ClearFake,Commandline,DomainShadowing,Windows",
            "anonymous": 0,
            "reporter": "Gi7w0rm"
        }
    ],
    "1891061": [
        {
            "ioc_value": "www.hobbyegge.ch",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-08-29 13:11:40",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": true,
            "reference": null,
            "tags": "compromised,EtherHide",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1891059": [
        {
            "ioc_value": "43.163.88.35:8080",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-08-29 13:05:06",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "cobaltstrike",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1891060": [
        {
            "ioc_value": "43.163.88.35:137",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-08-29 13:05:06",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "cobaltstrike",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1891058": [
        {
            "ioc_value": "43.163.88.35:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-08-29 13:05:05",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "cobaltstrike",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1891057": [
        {
            "ioc_value": "dewocyki.workers.dev",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "php.shin_webshell",
            "malware_alias": null,
            "malware_printable": "php.shin_webshell",
            "first_seen_utc": "2026-08-29 13:04:46",
            "last_seen_utc": null,
            "confidence_level": 50,
            "is_compromised": true,
            "reference": null,
            "tags": "Cloudflare,GIF,PHP,webshell,WordPress,workers.dev,wp-admin",
            "anonymous": 0,
            "reporter": "xscon"
        }
    ],
    "1891056": [
        {
            "ioc_value": "caroleparodi.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-08-29 13:01:39",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": true,
            "reference": null,
            "tags": "compromised,EtherHide",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1891055": [
        {
            "ioc_value": "linywahe.workers.dev",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "php.shin_webshell",
            "malware_alias": null,
            "malware_printable": "php.shin_webshell",
            "first_seen_utc": "2026-08-29 12:58:54",
            "last_seen_utc": null,
            "confidence_level": 50,
            "is_compromised": true,
            "reference": null,
            "tags": "Cloudflare,GIF,PHP,webshell,WordPress,workers.dev,wp-admin",
            "anonymous": 0,
            "reporter": "xscon"
        }
    ],
    "1891054": [
        {
            "ioc_value": "luckywheels.world",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-08-29 12:52:02",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1891053": [
        {
            "ioc_value": "lulugyqi.workers.dev",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "php.shin_webshell",
            "malware_alias": null,
            "malware_printable": "php.shin_webshell",
            "first_seen_utc": "2026-08-29 12:49:49",
            "last_seen_utc": null,
            "confidence_level": 50,
            "is_compromised": true,
            "reference": null,
            "tags": "Cloudflare,GIF,PHP,webshell,WordPress,workers.dev,wp-admin",
            "anonymous": 0,
            "reporter": "xscon"
        }
    ],
    "1891052": [
        {
            "ioc_value": "bbxi4lykw4.workers.dev",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "php.shin_webshell",
            "malware_alias": null,
            "malware_printable": "php.shin_webshell",
            "first_seen_utc": "2026-08-29 12:43:18",
            "last_seen_utc": null,
            "confidence_level": 50,
            "is_compromised": true,
            "reference": null,
            "tags": "Cloudflare,GIF,PHP,webshell,WordPress,workers.dev,wp-admin",
            "anonymous": 0,
            "reporter": "xscon"
        }
    ],
    "1891051": [
        {
            "ioc_value": "c75aknnyxf.workers.dev",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "php.shin_webshell",
            "malware_alias": null,
            "malware_printable": "php.shin_webshell",
            "first_seen_utc": "2026-08-29 12:39:46",
            "last_seen_utc": null,
            "confidence_level": 50,
            "is_compromised": true,
            "reference": null,
            "tags": "Cloudflare,GIF,PHP,webshell,WordPress,workers.dev,wp-admin",
            "anonymous": 0,
            "reporter": "xscon"
        }
    ],
    "1891049": [
        {
            "ioc_value": "https://fish-planet.online",
            "ioc_type": "url",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-08-29 12:39:38",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,ErrTraffic,EtherHiding",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1891050": [
        {
            "ioc_value": "https://online-park.online",
            "ioc_type": "url",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-08-29 12:39:38",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,ErrTraffic,EtherHiding",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1891047": [
        {
            "ioc_value": "fish-planet.online",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-08-29 12:39:37",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,ErrTraffic,EtherHiding",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1891048": [
        {
            "ioc_value": "online-park.online",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-08-29 12:39:37",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,ErrTraffic,EtherHiding",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1891046": [
        {
            "ioc_value": "legexuca.workers.dev",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "php.shin_webshell",
            "malware_alias": null,
            "malware_printable": "php.shin_webshell",
            "first_seen_utc": "2026-08-29 12:27:47",
            "last_seen_utc": null,
            "confidence_level": 50,
            "is_compromised": true,
            "reference": null,
            "tags": "Cloudflare,GIF,PHP,webshell,WordPress,workers.dev,wp-admin",
            "anonymous": 0,
            "reporter": "xscon"
        }
    ],
    "1891044": [
        {
            "ioc_value": "http://flreaow.click:6527/comments",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.remus",
            "malware_alias": null,
            "malware_printable": "Remus",
            "first_seen_utc": "2026-08-29 12:25:55",
            "last_seen_utc": null,
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "remus",
            "anonymous": 0,
            "reporter": "Myrtus0x0"
        }
    ],
    "1891045": [
        {
            "ioc_value": "http://piarl.site:9048/documents",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.remus",
            "malware_alias": null,
            "malware_printable": "Remus",
            "first_seen_utc": "2026-08-29 12:25:55",
            "last_seen_utc": null,
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "remus",
            "anonymous": 0,
            "reporter": "Myrtus0x0"
        }
    ],
    "1891042": [
        {
            "ioc_value": "4151amalia.workers.dev",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "php.shin_webshell",
            "malware_alias": null,
            "malware_printable": "php.shin_webshell",
            "first_seen_utc": "2026-08-29 12:18:03",
            "last_seen_utc": null,
            "confidence_level": 50,
            "is_compromised": true,
            "reference": null,
            "tags": "Cloudflare,GIF,PHP,webshell,WordPress,workers.dev,wp-admin",
            "anonymous": 0,
            "reporter": "xscon"
        }
    ],
    "1891041": [
        {
            "ioc_value": "tin.tokyo77hit.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.iclickfix",
            "malware_alias": null,
            "malware_printable": "IClickFix",
            "first_seen_utc": "2026-08-29 12:13:20",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClickFix",
            "anonymous": 0,
            "reporter": "threatcat_ch"
        }
    ],
    "1891040": [
        {
            "ioc_value": "fmui74n9.bottegadesiresstore.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-08-29 12:05:34",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,mac-0x68dc,macos",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1891038": [
        {
            "ioc_value": "151.245.230.21:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-08-29 12:05:06",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "cobaltstrike",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1891039": [
        {
            "ioc_value": "151.245.230.21:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-08-29 12:05:06",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "cobaltstrike",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1891037": [
        {
            "ioc_value": "45.192.105.141:60000",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-08-29 12:05:05",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "viper",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1891036": [
        {
            "ioc_value": "grace352.workers.dev",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "php.shin_webshell",
            "malware_alias": null,
            "malware_printable": "php.shin_webshell",
            "first_seen_utc": "2026-08-29 12:03:46",
            "last_seen_utc": null,
            "confidence_level": 50,
            "is_compromised": true,
            "reference": null,
            "tags": "Cloudflare,GIF,PHP,webshell,WordPress,workers.dev,wp-admin",
            "anonymous": 0,
            "reporter": "xscon"
        }
    ],
    "1891035": [
        {
            "ioc_value": "bottegadesiresstore.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-08-29 12:01:17",
            "last_seen_utc": "2026-08-29 12:01:56",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake",
            "anonymous": 0,
            "reporter": "threatcat_ch"
        }
    ],
    "1891033": [
        {
            "ioc_value": "162.251.92.64:448",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-08-29 11:48:21",
            "last_seen_utc": "2026-08-31 07:48:38",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1891032": [
        {
            "ioc_value": "calmriverflowing.top",
            "ioc_type": "domain",
            "threat_type": "cc_skimming",
            "malware": "js.magecart",
            "malware_alias": null,
            "malware_printable": "magecart",
            "first_seen_utc": "2026-08-29 11:39:32",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "Magecart",
            "anonymous": 0,
            "reporter": "threatcat_ch"
        }
    ],
    "1891031": [
        {
            "ioc_value": "uylwd48175.workers.dev",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "php.shin_webshell",
            "malware_alias": null,
            "malware_printable": "php.shin_webshell",
            "first_seen_utc": "2026-08-29 11:39:04",
            "last_seen_utc": null,
            "confidence_level": 50,
            "is_compromised": true,
            "reference": null,
            "tags": "Cloudflare,GIF,PHP,webshell,WordPress,workers.dev,wp-admin",
            "anonymous": 0,
            "reporter": "xscon"
        }
    ],
    "1891030": [
        {
            "ioc_value": "pfaz89ummq.workers.dev",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "php.shin_webshell",
            "malware_alias": null,
            "malware_printable": "php.shin_webshell",
            "first_seen_utc": "2026-08-29 11:33:48",
            "last_seen_utc": null,
            "confidence_level": 50,
            "is_compromised": true,
            "reference": null,
            "tags": "Cloudflare,GIF,PHP,webshell,WordPress,workers.dev,wp-admin",
            "anonymous": 0,
            "reporter": "xscon"
        }
    ],
    "1891029": [
        {
            "ioc_value": "piomilokao.icu",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.iclickfix",
            "malware_alias": null,
            "malware_printable": "IClickFix",
            "first_seen_utc": "2026-08-29 11:32:50",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClickFix",
            "anonymous": 0,
            "reporter": "threatcat_ch"
        }
    ],
    "1891028": [
        {
            "ioc_value": "vailora231.life",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.iclickfix",
            "malware_alias": null,
            "malware_printable": "IClickFix",
            "first_seen_utc": "2026-08-29 11:32:47",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClickFix",
            "anonymous": 0,
            "reporter": "threatcat_ch"
        }
    ],
    "1891027": [
        {
            "ioc_value": "s95r07sbgv.workers.dev",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "php.shin_webshell",
            "malware_alias": null,
            "malware_printable": "php.shin_webshell",
            "first_seen_utc": "2026-08-29 11:12:59",
            "last_seen_utc": null,
            "confidence_level": 50,
            "is_compromised": true,
            "reference": null,
            "tags": "Cloudflare,GIF,PHP,webshell,WordPress,workers.dev,wp-admin",
            "anonymous": 0,
            "reporter": "xscon"
        }
    ],
    "1891026": [
        {
            "ioc_value": "4013kimmy.workers.dev",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "php.shin_webshell",
            "malware_alias": null,
            "malware_printable": "php.shin_webshell",
            "first_seen_utc": "2026-08-29 11:12:54",
            "last_seen_utc": null,
            "confidence_level": 50,
            "is_compromised": true,
            "reference": null,
            "tags": "Cloudflare,GIF,PHP,webshell,WordPress,workers.dev,wp-admin",
            "anonymous": 0,
            "reporter": "xscon"
        }
    ],
    "1891025": [
        {
            "ioc_value": "lubotoko.workers.dev",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "php.shin_webshell",
            "malware_alias": null,
            "malware_printable": "php.shin_webshell",
            "first_seen_utc": "2026-08-29 11:10:26",
            "last_seen_utc": null,
            "confidence_level": 50,
            "is_compromised": true,
            "reference": null,
            "tags": "Cloudflare,GIF,PHP,webshell,WordPress,workers.dev,wp-admin",
            "anonymous": 0,
            "reporter": "xscon"
        }
    ],
    "1891024": [
        {
            "ioc_value": "151.245.230.21:3389",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-08-29 11:05:06",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "cobaltstrike",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1891023": [
        {
            "ioc_value": "151.245.230.21:8080",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-08-29 11:05:05",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "cobaltstrike",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1891022": [
        {
            "ioc_value": "hemipaxo.workers.dev",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "php.shin_webshell",
            "malware_alias": null,
            "malware_printable": "php.shin_webshell",
            "first_seen_utc": "2026-08-29 11:05:00",
            "last_seen_utc": null,
            "confidence_level": 50,
            "is_compromised": true,
            "reference": null,
            "tags": "Cloudflare,GIF,PHP,webshell,WordPress,workers.dev,wp-admin",
            "anonymous": 0,
            "reporter": "xscon"
        }
    ],
    "1891020": [
        {
            "ioc_value": "doxise.workers.dev",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "php.shin_webshell",
            "malware_alias": null,
            "malware_printable": "php.shin_webshell",
            "first_seen_utc": "2026-08-29 10:44:36",
            "last_seen_utc": null,
            "confidence_level": 50,
            "is_compromised": true,
            "reference": null,
            "tags": "Cloudflare,GIF,PHP,webshell,WordPress,workers.dev,wp-admin",
            "anonymous": 0,
            "reporter": "xscon"
        }
    ],
    "1891019": [
        {
            "ioc_value": "muwlx00405.workers.dev",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "php.shin_webshell",
            "malware_alias": null,
            "malware_printable": "php.shin_webshell",
            "first_seen_utc": "2026-08-29 10:37:32",
            "last_seen_utc": null,
            "confidence_level": 50,
            "is_compromised": true,
            "reference": null,
            "tags": "Cloudflare,GIF,PHP,webshell,WordPress,workers.dev,wp-admin",
            "anonymous": 0,
            "reporter": "xscon"
        }
    ],
    "1891018": [
        {
            "ioc_value": "www.breezdanubemaritimecity.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-08-29 10:31:29",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": true,
            "reference": null,
            "tags": "compromised,EtherHide",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1891017": [
        {
            "ioc_value": "nynashanti.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-08-29 10:21:27",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": true,
            "reference": null,
            "tags": "compromised,EtherHide",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1891016": [
        {
            "ioc_value": "953sensible.workers.dev",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "php.shin_webshell",
            "malware_alias": null,
            "malware_printable": "php.shin_webshell",
            "first_seen_utc": "2026-08-29 10:20:54",
            "last_seen_utc": null,
            "confidence_level": 50,
            "is_compromised": true,
            "reference": null,
            "tags": "Cloudflare,GIF,PHP,webshell,WordPress,workers.dev,wp-admin",
            "anonymous": 0,
            "reporter": "xscon"
        }
    ],
    "1891015": [
        {
            "ioc_value": "tuqewyla.workers.dev",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "php.shin_webshell",
            "malware_alias": null,
            "malware_printable": "php.shin_webshell",
            "first_seen_utc": "2026-08-29 10:07:27",
            "last_seen_utc": null,
            "confidence_level": 50,
            "is_compromised": true,
            "reference": null,
            "tags": "Cloudflare,GIF,PHP,webshell,WordPress,workers.dev,wp-admin",
            "anonymous": 0,
            "reporter": "xscon"
        }
    ],
    "1891014": [
        {
            "ioc_value": "151.245.230.21:22",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-08-29 10:05:06",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "cobaltstrike",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1891013": [
        {
            "ioc_value": "8.135.18.143:8085",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.vshell",
            "malware_alias": null,
            "malware_printable": "VShell",
            "first_seen_utc": "2026-08-29 10:05:05",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "vshell",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1891012": [
        {
            "ioc_value": "165.154.226.87:8084",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.vshell",
            "malware_alias": null,
            "malware_printable": "VShell",
            "first_seen_utc": "2026-08-29 10:05:04",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "vshell",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1891011": [
        {
            "ioc_value": "nexo3n5e.born-x-raised.us",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-08-29 10:03:59",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,mac-0x68dc,macos",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1891010": [
        {
            "ioc_value": "born-x-raised.us",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-08-29 10:00:48",
            "last_seen_utc": "2026-08-29 10:01:44",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake",
            "anonymous": 0,
            "reporter": "threatcat_ch"
        }
    ],
    "1891009": [
        {
            "ioc_value": "cmbhbf32su.workers.dev",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "php.shin_webshell",
            "malware_alias": null,
            "malware_printable": "php.shin_webshell",
            "first_seen_utc": "2026-08-29 09:53:40",
            "last_seen_utc": null,
            "confidence_level": 50,
            "is_compromised": true,
            "reference": null,
            "tags": "Cloudflare,GIF,PHP,webshell,WordPress,workers.dev,wp-admin",
            "anonymous": 0,
            "reporter": "xscon"
        }
    ],
    "1891008": [
        {
            "ioc_value": "rqz74grh.home-power-shield.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-08-29 09:52:41",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,mac-0x0f14,macos",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1891006": [
        {
            "ioc_value": "http://flreaow.click:6527/articles",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.remus",
            "malware_alias": null,
            "malware_printable": "Remus",
            "first_seen_utc": "2026-08-29 09:51:55",
            "last_seen_utc": null,
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "remus",
            "anonymous": 0,
            "reporter": "Myrtus0x0"
        }
    ],
    "1891007": [
        {
            "ioc_value": "http://piarl.site:9048/collections",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.remus",
            "malware_alias": null,
            "malware_printable": "Remus",
            "first_seen_utc": "2026-08-29 09:51:55",
            "last_seen_utc": null,
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "remus",
            "anonymous": 0,
            "reporter": "Myrtus0x0"
        }
    ],
    "1891005": [
        {
            "ioc_value": "94.250.167.221:4433",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.danabot",
            "malware_alias": "DanaTools",
            "malware_printable": "DanaBot",
            "first_seen_utc": "2026-08-29 09:47:13",
            "last_seen_utc": "2026-08-31 07:48:08",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DanBot,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1891004": [
        {
            "ioc_value": "94.184.37.68:8080",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.chaos",
            "malware_alias": "FakeRyuk,RyukJoke,Yashma",
            "malware_printable": "Chaos",
            "first_seen_utc": "2026-08-29 09:47:12",
            "last_seen_utc": "2026-08-31 07:48:07",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CHAOS,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1891003": [
        {
            "ioc_value": "80.190.77.86:10700",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-08-29 09:46:52",
            "last_seen_utc": "2026-08-31 07:47:43",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1891002": [
        {
            "ioc_value": "46.109.235.15:7707",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-08-29 09:46:31",
            "last_seen_utc": "2026-08-31 07:47:20",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1891001": [
        {
            "ioc_value": "45.61.177.135:3333",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.evilginx",
            "malware_alias": null,
            "malware_printable": "Evilginx",
            "first_seen_utc": "2026-08-29 09:46:28",
            "last_seen_utc": "2026-08-31 07:47:16",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Evilginx,EvilGoPhish",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1890999": [
        {
            "ioc_value": "45.125.67.196:31337",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.sliver",
            "malware_alias": null,
            "malware_printable": "Sliver",
            "first_seen_utc": "2026-08-29 09:46:20",
            "last_seen_utc": "2026-08-31 07:47:07",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Sliver",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1891000": [
        {
            "ioc_value": "45.125.67.196:8888",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.sliver",
            "malware_alias": null,
            "malware_printable": "Sliver",
            "first_seen_utc": "2026-08-29 09:46:20",
            "last_seen_utc": "2026-08-31 07:47:07",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Sliver",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1890998": [
        {
            "ioc_value": "220.154.128.196:9443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-08-29 09:45:55",
            "last_seen_utc": "2026-08-31 07:46:38",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1890997": [
        {
            "ioc_value": "204.152.217.122:8443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.evilginx",
            "malware_alias": null,
            "malware_printable": "Evilginx",
            "first_seen_utc": "2026-08-29 09:45:09",
            "last_seen_utc": "2026-08-31 07:45:42",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Evilginx,EvilGoPhish",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1890996": [
        {
            "ioc_value": "172.111.198.212:56013",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-29 09:44:10",
            "last_seen_utc": "2026-08-31 07:44:21",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1890995": [
        {
            "ioc_value": "169.58.180.142:30300",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-08-29 09:44:07",
            "last_seen_utc": "2026-08-31 07:44:18",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1890994": [
        {
            "ioc_value": "163.5.210.229:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-29 09:44:04",
            "last_seen_utc": "2026-08-31 07:44:14",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1890993": [
        {
            "ioc_value": "144.172.117.108:4321",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-08-29 09:43:41",
            "last_seen_utc": "2026-08-31 07:43:49",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1890992": [
        {
            "ioc_value": "103.98.18.238:3333",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.dcrat",
            "malware_alias": "DarkCrystal RAT",
            "malware_printable": "DCRat",
            "first_seen_utc": "2026-08-29 09:43:10",
            "last_seen_utc": "2026-08-31 07:43:12",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DCRat,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1890991": [
        {
            "ioc_value": "103.116.52.203:4321",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-08-29 09:43:05",
            "last_seen_utc": "2026-08-31 07:43:06",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1890990": [
        {
            "ioc_value": "uuvtq10338.workers.dev",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "php.shin_webshell",
            "malware_alias": null,
            "malware_printable": "php.shin_webshell",
            "first_seen_utc": "2026-08-29 09:41:23",
            "last_seen_utc": null,
            "confidence_level": 50,
            "is_compromised": true,
            "reference": null,
            "tags": "Cloudflare,GIF,PHP,webshell,WordPress,workers.dev,wp-admin",
            "anonymous": 0,
            "reporter": "xscon"
        }
    ],
    "1890989": [
        {
            "ioc_value": "xyqulyme.workers.dev",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "php.shin_webshell",
            "malware_alias": null,
            "malware_printable": "php.shin_webshell",
            "first_seen_utc": "2026-08-29 09:36:07",
            "last_seen_utc": null,
            "confidence_level": 50,
            "is_compromised": true,
            "reference": null,
            "tags": "Cloudflare,GIF,PHP,webshell,WordPress,workers.dev,wp-admin",
            "anonymous": 0,
            "reporter": "xscon"
        }
    ],
    "1890988": [
        {
            "ioc_value": "gogetdsm.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-08-29 09:30:46",
            "last_seen_utc": "2026-08-29 09:31:44",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake",
            "anonymous": 0,
            "reporter": "threatcat_ch"
        }
    ],
    "1890987": [
        {
            "ioc_value": "http://piarl.site:9048/notifications",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.remus",
            "malware_alias": null,
            "malware_printable": "Remus",
            "first_seen_utc": "2026-08-29 09:30:24",
            "last_seen_utc": "2026-08-29 11:11:13",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://bazaar.abuse.ch/sample/30cf47caf9700a74a8ea4a728b8b7c88cb1f8e22261b4ac01575b112c1e224ca/",
            "tags": "remus",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1890986": [
        {
            "ioc_value": "z2svmka7bc.workers.dev",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "php.shin_webshell",
            "malware_alias": null,
            "malware_printable": "php.shin_webshell",
            "first_seen_utc": "2026-08-29 09:30:17",
            "last_seen_utc": null,
            "confidence_level": 50,
            "is_compromised": true,
            "reference": null,
            "tags": "Cloudflare,GIF,PHP,webshell,WordPress,workers.dev,wp-admin",
            "anonymous": 0,
            "reporter": "xscon"
        }
    ],
    "1890985": [
        {
            "ioc_value": "dorree8903.workers.dev",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "php.shin_webshell",
            "malware_alias": null,
            "malware_printable": "php.shin_webshell",
            "first_seen_utc": "2026-08-29 09:24:34",
            "last_seen_utc": null,
            "confidence_level": 50,
            "is_compromised": true,
            "reference": null,
            "tags": "Cloudflare,GIF,PHP,webshell,WordPress,workers.dev,wp-admin",
            "anonymous": 0,
            "reporter": "xscon"
        }
    ],
    "1890984": [
        {
            "ioc_value": "sodyruzu.workers.dev",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "php.shin_webshell",
            "malware_alias": null,
            "malware_printable": "php.shin_webshell",
            "first_seen_utc": "2026-08-29 09:08:28",
            "last_seen_utc": null,
            "confidence_level": 50,
            "is_compromised": true,
            "reference": null,
            "tags": "Cloudflare,GIF,PHP,webshell,WordPress,workers.dev,wp-admin",
            "anonymous": 0,
            "reporter": "xscon"
        }
    ],
    "1890983": [
        {
            "ioc_value": "115.159.226.190:54321",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-08-29 09:05:05",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "cobaltstrike",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1890982": [
        {
            "ioc_value": "e5wy6a5o.oncloudllc.com.mx",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-08-29 09:01:08",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,mac-0xdcf2,macos",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1890981": [
        {
            "ioc_value": "oncloudllc.com.mx",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-08-29 08:59:23",
            "last_seen_utc": "2026-08-29 08:59:29",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "29August2026,ClearFake,Commandline,MacOS",
            "anonymous": 0,
            "reporter": "Gi7w0rm"
        }
    ],
    "1890980": [
        {
            "ioc_value": "getdsmmarketing.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-08-29 08:57:57",
            "last_seen_utc": "2026-08-29 08:58:03",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "29August2026,ClearFake,Commandline,MacOS",
            "anonymous": 0,
            "reporter": "Gi7w0rm"
        }
    ],
    "1890979": [
        {
            "ioc_value": "letygoji.workers.dev",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "php.shin_webshell",
            "malware_alias": null,
            "malware_printable": "php.shin_webshell",
            "first_seen_utc": "2026-08-29 08:54:51",
            "last_seen_utc": null,
            "confidence_level": 50,
            "is_compromised": true,
            "reference": null,
            "tags": "Cloudflare,GIF,PHP,webshell,WordPress,workers.dev,wp-admin",
            "anonymous": 0,
            "reporter": "xscon"
        }
    ],
    "1890978": [
        {
            "ioc_value": "womose.workers.dev",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "php.shin_webshell",
            "malware_alias": null,
            "malware_printable": "php.shin_webshell",
            "first_seen_utc": "2026-08-29 08:31:35",
            "last_seen_utc": null,
            "confidence_level": 50,
            "is_compromised": true,
            "reference": null,
            "tags": "Cloudflare,GIF,PHP,webshell,WordPress,workers.dev,wp-admin",
            "anonymous": 0,
            "reporter": "xscon"
        }
    ],
    "1890977": [
        {
            "ioc_value": "xaucs09664.workers.dev",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "php.shin_webshell",
            "malware_alias": null,
            "malware_printable": "php.shin_webshell",
            "first_seen_utc": "2026-08-29 08:30:28",
            "last_seen_utc": null,
            "confidence_level": 50,
            "is_compromised": true,
            "reference": null,
            "tags": "Cloudflare,GIF,PHP,webshell,WordPress,workers.dev,wp-admin",
            "anonymous": 0,
            "reporter": "xscon"
        }
    ],
    "1890943": [
        {
            "ioc_value": "145.223.23.25:3215",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remus",
            "malware_alias": null,
            "malware_printable": "Remus",
            "first_seen_utc": "2026-08-29 06:49:54",
            "last_seen_utc": "2026-08-31 03:55:39",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "945c9f3c8cddcb7f33efce50a9a949ad,c2,remus",
            "anonymous": 0,
            "reporter": "Bitsight"
        }
    ],
    "1890941": [
        {
            "ioc_value": "barbashat.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-08-29 05:59:45",
            "last_seen_utc": "2026-08-30 23:01:33",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake",
            "anonymous": 0,
            "reporter": "threatcat_ch"
        }
    ],
    "1890877": [
        {
            "ioc_value": "104.248.41.207:8080",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.aisuru",
            "malware_alias": null,
            "malware_printable": "Aisuru",
            "first_seen_utc": "2026-08-29 05:55:05",
            "last_seen_utc": "2026-08-30 21:07:57",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "Aisuru,c2",
            "anonymous": 0,
            "reporter": "Bitsight"
        }
    ],
    "1890919": [
        {
            "ioc_value": "workwithgetdsm.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-08-29 03:49:53",
            "last_seen_utc": "2026-08-31 01:20:09",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "29August2026,ClearFake,Commandline,MacOS",
            "anonymous": 0,
            "reporter": "Gi7w0rm"
        }
    ],
    "1890912": [
        {
            "ioc_value": "43.133.164.200:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-08-29 03:05:06",
            "last_seen_utc": "2026-08-31 07:47:01",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "mythic",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1890897": [
        {
            "ioc_value": "trygetdsm.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-08-29 01:39:20",
            "last_seen_utc": "2026-08-30 20:09:19",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "29August2026,ClearFake,Commandline,MacOS",
            "anonymous": 0,
            "reporter": "Gi7w0rm"
        }
    ],
    "1890895": [
        {
            "ioc_value": "thegetdsm.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-08-29 01:36:17",
            "last_seen_utc": "2026-08-30 20:02:40",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake",
            "anonymous": 0,
            "reporter": "threatcat_ch"
        }
    ],
    "1890864": [
        {
            "ioc_value": "8.134.166.14:54451",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-08-28 23:47:33",
            "last_seen_utc": "2026-08-31 07:48:55",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1890859": [
        {
            "ioc_value": "getdsmwebagency.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-08-28 23:30:16",
            "last_seen_utc": "2026-08-31 07:03:35",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake",
            "anonymous": 0,
            "reporter": "threatcat_ch"
        }
    ],
    "1890853": [
        {
            "ioc_value": "getdsm.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-08-28 22:57:18",
            "last_seen_utc": "2026-08-31 05:03:15",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "28August2026,ClearFake,Commandline,MacOS",
            "anonymous": 0,
            "reporter": "Gi7w0rm"
        }
    ],
    "1890851": [
        {
            "ioc_value": "enus-theeloncode.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-08-28 22:44:17",
            "last_seen_utc": "2026-08-31 03:11:57",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "28August2026,ClearFake,Commandline,DomainShadowing,Windows",
            "anonymous": 0,
            "reporter": "Gi7w0rm"
        }
    ],
    "1890835": [
        {
            "ioc_value": "scalewithgetdsm.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-08-28 20:58:17",
            "last_seen_utc": "2026-08-30 20:35:07",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake",
            "anonymous": 0,
            "reporter": "threatcat_ch"
        }
    ],
    "1890815": [
        {
            "ioc_value": "91.92.241.38:8848",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.dcrat",
            "malware_alias": "DarkCrystal RAT",
            "malware_printable": "DCRat",
            "first_seen_utc": "2026-08-28 19:46:31",
            "last_seen_utc": "2026-08-31 07:47:59",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DCRat,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1890814": [
        {
            "ioc_value": "87.58.199.75:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "js.tsundere",
            "malware_alias": "DinDoor",
            "malware_printable": "Tsundere",
            "first_seen_utc": "2026-08-28 19:46:27",
            "last_seen_utc": "2026-08-31 07:47:53",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DinDoor,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1890812": [
        {
            "ioc_value": "84.201.20.74:56001",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-28 19:46:24",
            "last_seen_utc": "2026-08-31 07:47:49",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1890813": [
        {
            "ioc_value": "84.201.20.74:56002",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-28 19:46:24",
            "last_seen_utc": "2026-08-31 07:47:49",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1890811": [
        {
            "ioc_value": "82.165.202.90:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-08-28 19:46:23",
            "last_seen_utc": "2026-08-31 07:47:47",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1890810": [
        {
            "ioc_value": "80.190.77.86:20700",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-08-28 19:46:20",
            "last_seen_utc": "2026-08-31 07:47:44",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1890809": [
        {
            "ioc_value": "196.70.69.77:5001",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-08-28 19:44:36",
            "last_seen_utc": "2026-08-31 07:45:29",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1890808": [
        {
            "ioc_value": "195.177.94.91:56003",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-28 19:44:34",
            "last_seen_utc": "2026-08-31 07:45:27",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1890807": [
        {
            "ioc_value": "194.59.31.78:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.hype_agent",
            "malware_alias": null,
            "malware_printable": "HypeAgent",
            "first_seen_utc": "2026-08-28 19:44:31",
            "last_seen_utc": "2026-08-31 07:45:20",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,HypeAgent",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1890804": [
        {
            "ioc_value": "183.90.187.111:10888",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-28 19:44:10",
            "last_seen_utc": "2026-08-31 07:44:39",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1890805": [
        {
            "ioc_value": "183.90.187.2:10888",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-28 19:44:10",
            "last_seen_utc": "2026-08-31 07:44:39",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1890806": [
        {
            "ioc_value": "183.90.187.73:10888",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-28 19:44:10",
            "last_seen_utc": "2026-08-31 07:44:40",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1890803": [
        {
            "ioc_value": "179.61.227.213:55004",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-28 19:44:08",
            "last_seen_utc": "2026-08-31 07:44:37",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1890802": [
        {
            "ioc_value": "176.65.139.139:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.mirai",
            "malware_alias": "Katana",
            "malware_printable": "Mirai",
            "first_seen_utc": "2026-08-28 19:44:04",
            "last_seen_utc": "2026-08-31 07:44:30",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mirai",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1890800": [
        {
            "ioc_value": "154.201.82.108:56002",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-28 19:43:40",
            "last_seen_utc": "2026-08-31 07:43:58",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1890799": [
        {
            "ioc_value": "154.201.82.105:56001",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-28 19:43:39",
            "last_seen_utc": "2026-08-31 07:43:57",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1890798": [
        {
            "ioc_value": "136.0.213.135:56003",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-28 19:43:29",
            "last_seen_utc": "2026-08-31 07:43:44",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1890796": [
        {
            "ioc_value": "102.220.160.231:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.dcrat",
            "malware_alias": "DarkCrystal RAT",
            "malware_printable": "DCRat",
            "first_seen_utc": "2026-08-28 19:43:04",
            "last_seen_utc": "2026-08-31 07:43:05",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DCRat,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1890797": [
        {
            "ioc_value": "102.220.160.231:8848",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.dcrat",
            "malware_alias": "DarkCrystal RAT",
            "malware_printable": "DCRat",
            "first_seen_utc": "2026-08-28 19:43:04",
            "last_seen_utc": "2026-08-31 07:43:05",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DCRat,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1890795": [
        {
            "ioc_value": "102.117.171.26:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-08-28 19:43:03",
            "last_seen_utc": "2026-08-31 07:43:05",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1890744": [
        {
            "ioc_value": "https://46.29.26.35",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-08-28 19:27:30",
            "last_seen_utc": "2026-08-31 08:10:31",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "8e8e7920d1ac7f57735398887661bf8d,c2,loader,stealer,Vidar",
            "anonymous": 0,
            "reporter": "Bitsight"
        }
    ],
    "1890760": [
        {
            "ioc_value": "https://nsn.12naga.org",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-08-28 19:27:25",
            "last_seen_utc": "2026-08-31 08:13:40",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "279244a0387f7d5a1b68137bd9768de8,c2,loader,stealer,Vidar",
            "anonymous": 0,
            "reporter": "Bitsight"
        }
    ],
    "1890781": [
        {
            "ioc_value": "https://185.229.225.31",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-08-28 19:27:20",
            "last_seen_utc": "2026-08-30 09:56:04",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "c2,e53c0776fdba467447b61be1a2bc4027,loader,stealer,Vidar",
            "anonymous": 0,
            "reporter": "Bitsight"
        }
    ],
    "1890785": [
        {
            "ioc_value": "20.119.73.195:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-08-28 19:05:10",
            "last_seen_utc": "2026-08-31 07:45:37",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "mythic",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1890734": [
        {
            "ioc_value": "http://piarl.site:9048/tasks",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.remus",
            "malware_alias": null,
            "malware_printable": "Remus",
            "first_seen_utc": "2026-08-28 16:15:27",
            "last_seen_utc": "2026-08-29 11:43:04",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://bazaar.abuse.ch/sample/7b0d74d4ead227828f138f5488964bdc539f9bc2821aa450bca724227872becf/",
            "tags": "remus",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1890650": [
        {
            "ioc_value": "https://sss.fbdfsgfwrgerwefew.top/",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.stealc",
            "malware_alias": null,
            "malware_printable": "Stealc",
            "first_seen_utc": "2026-08-28 16:03:23",
            "last_seen_utc": "2026-08-31 08:10:27",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "123,c2,loader,StealC,stealer",
            "anonymous": 0,
            "reporter": "Bitsight"
        }
    ],
    "1890726": [
        {
            "ioc_value": "8d06b638ca1acca4815076ae9fa3a4d0",
            "ioc_type": "md5_hash",
            "threat_type": "payload",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-08-28 16:02:40",
            "last_seen_utc": "2026-08-30 01:34:51",
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1890722": [
        {
            "ioc_value": "48f8443f9e087064822a30c3e2f6ea6b4a57c490",
            "ioc_type": "sha1_hash",
            "threat_type": "payload",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-08-28 16:02:39",
            "last_seen_utc": "2026-08-30 01:34:50",
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1890723": [
        {
            "ioc_value": "0d0bb2656a73610b2695fc8f3db21723",
            "ioc_type": "md5_hash",
            "threat_type": "payload",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-08-28 16:02:39",
            "last_seen_utc": "2026-08-30 01:34:50",
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1890724": [
        {
            "ioc_value": "98fe10c077d59ab4a89dd551f76bba8ee220838f0c229498adb8471f50c65535",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-08-28 16:02:39",
            "last_seen_utc": "2026-08-30 01:34:50",
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1890725": [
        {
            "ioc_value": "b9213ac9ac3f11c1dde4ea678fef6795e09886f7",
            "ioc_type": "sha1_hash",
            "threat_type": "payload",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-08-28 16:02:39",
            "last_seen_utc": "2026-08-30 01:34:51",
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1890721": [
        {
            "ioc_value": "712e7912a669a71a7006fd1a0333b5da45dbbc78672c46ae62e794fbc1372959",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-08-28 16:02:38",
            "last_seen_utc": "2026-08-30 01:34:50",
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1890718": [
        {
            "ioc_value": "3ee9badaa810b2fb6db57e4644ec40c58e8fe15c6980059a3232a374df5ba4a3",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "win.valley_rat",
            "malware_alias": "Winos",
            "malware_printable": "ValleyRAT",
            "first_seen_utc": "2026-08-28 16:02:37",
            "last_seen_utc": "2026-08-30 01:34:47",
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1890719": [
        {
            "ioc_value": "b770903ba5c898d69db81dbafbd98f3eb32fc3fb",
            "ioc_type": "sha1_hash",
            "threat_type": "payload",
            "malware": "win.valley_rat",
            "malware_alias": "Winos",
            "malware_printable": "ValleyRAT",
            "first_seen_utc": "2026-08-28 16:02:37",
            "last_seen_utc": "2026-08-30 01:34:47",
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1890720": [
        {
            "ioc_value": "4818c691ec402f0f2251f1a8d1d8a3b9",
            "ioc_type": "md5_hash",
            "threat_type": "payload",
            "malware": "win.valley_rat",
            "malware_alias": "Winos",
            "malware_printable": "ValleyRAT",
            "first_seen_utc": "2026-08-28 16:02:37",
            "last_seen_utc": "2026-08-30 01:34:47",
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1890715": [
        {
            "ioc_value": "105195dfdfbfdce7cf13f50d92bba761eba5bc22c31000109a67708f61474e12",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "win.acr_stealer",
            "malware_alias": null,
            "malware_printable": "ACR Stealer",
            "first_seen_utc": "2026-08-28 16:02:35",
            "last_seen_utc": "2026-08-30 06:34:32",
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1890716": [
        {
            "ioc_value": "ba655e73a1c08143324ffeaf56b6f6bea0a134e6",
            "ioc_type": "sha1_hash",
            "threat_type": "payload",
            "malware": "win.acr_stealer",
            "malware_alias": null,
            "malware_printable": "ACR Stealer",
            "first_seen_utc": "2026-08-28 16:02:35",
            "last_seen_utc": "2026-08-30 06:34:32",
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1890717": [
        {
            "ioc_value": "8be48ea27f6cd6b2ec2ef3be4977322d",
            "ioc_type": "md5_hash",
            "threat_type": "payload",
            "malware": "win.acr_stealer",
            "malware_alias": null,
            "malware_printable": "ACR Stealer",
            "first_seen_utc": "2026-08-28 16:02:35",
            "last_seen_utc": "2026-08-30 06:34:33",
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1890713": [
        {
            "ioc_value": "4f6839725a41eee6426b1aeed61e7b27e40515d5",
            "ioc_type": "sha1_hash",
            "threat_type": "payload",
            "malware": "win.wannacryptor",
            "malware_alias": "Wana Decrypt0r,WannaCry,WannaCrypt,Wcry",
            "malware_printable": "WannaCryptor",
            "first_seen_utc": "2026-08-28 16:02:33",
            "last_seen_utc": "2026-08-30 06:34:29",
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1890714": [
        {
            "ioc_value": "6a4d5ab74aab4d6b8c24edb29d4b6d64",
            "ioc_type": "md5_hash",
            "threat_type": "payload",
            "malware": "win.wannacryptor",
            "malware_alias": "Wana Decrypt0r,WannaCry,WannaCrypt,Wcry",
            "malware_printable": "WannaCryptor",
            "first_seen_utc": "2026-08-28 16:02:33",
            "last_seen_utc": "2026-08-30 06:34:29",
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1890710": [
        {
            "ioc_value": "b07426979d61bbc20b209b88d2f6dd3f5cceb1ee",
            "ioc_type": "sha1_hash",
            "threat_type": "payload",
            "malware": "py.stealler",
            "malware_alias": null,
            "malware_printable": "stealler",
            "first_seen_utc": "2026-08-28 16:02:32",
            "last_seen_utc": "2026-08-30 06:34:28",
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1890711": [
        {
            "ioc_value": "57629b1f3807d324e3c51a340228fe5a",
            "ioc_type": "md5_hash",
            "threat_type": "payload",
            "malware": "py.stealler",
            "malware_alias": null,
            "malware_printable": "stealler",
            "first_seen_utc": "2026-08-28 16:02:32",
            "last_seen_utc": "2026-08-30 06:34:28",
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1890712": [
        {
            "ioc_value": "1738f890d5686b1c17b43166659643dde6ff57fc9ed4143dc9801ae331036273",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "win.wannacryptor",
            "malware_alias": "Wana Decrypt0r,WannaCry,WannaCrypt,Wcry",
            "malware_printable": "WannaCryptor",
            "first_seen_utc": "2026-08-28 16:02:32",
            "last_seen_utc": "2026-08-30 06:34:28",
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1890707": [
        {
            "ioc_value": "153d808ae3f57827a81024aa742ebbda96763f92",
            "ioc_type": "sha1_hash",
            "threat_type": "payload",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-08-28 16:02:31",
            "last_seen_utc": "2026-08-30 06:34:27",
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1890708": [
        {
            "ioc_value": "133027a245bc3253038e082b5115a9dc",
            "ioc_type": "md5_hash",
            "threat_type": "payload",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-08-28 16:02:31",
            "last_seen_utc": "2026-08-30 06:34:27",
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1890709": [
        {
            "ioc_value": "f19ce246b09aec504d8cb547f9d3344e14a6ca898f8d88f2207ece0d74f0d3f1",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "py.stealler",
            "malware_alias": null,
            "malware_printable": "stealler",
            "first_seen_utc": "2026-08-28 16:02:31",
            "last_seen_utc": "2026-08-30 06:34:28",
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1890705": [
        {
            "ioc_value": "846f4ed47a679e24505470f61d9110db",
            "ioc_type": "md5_hash",
            "threat_type": "payload",
            "malware": "win.valley_rat",
            "malware_alias": "Winos",
            "malware_printable": "ValleyRAT",
            "first_seen_utc": "2026-08-28 16:02:30",
            "last_seen_utc": "2026-08-30 06:34:26",
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1890706": [
        {
            "ioc_value": "0c8c4a99337505f79c05af524ef2c8ce810269a1896b9bd83bbd39454a618b8d",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-08-28 16:02:30",
            "last_seen_utc": "2026-08-30 06:34:27",
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1890701": [
        {
            "ioc_value": "92937973d50ddd6bff639bf35feb25b119f56edd",
            "ioc_type": "sha1_hash",
            "threat_type": "payload",
            "malware": "win.dcrat",
            "malware_alias": "DarkCrystal RAT",
            "malware_printable": "DCRat",
            "first_seen_utc": "2026-08-28 16:02:29",
            "last_seen_utc": "2026-08-30 06:34:25",
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1890702": [
        {
            "ioc_value": "9fce0558dd8b2061c7a8baf0877d5384",
            "ioc_type": "md5_hash",
            "threat_type": "payload",
            "malware": "win.dcrat",
            "malware_alias": "DarkCrystal RAT",
            "malware_printable": "DCRat",
            "first_seen_utc": "2026-08-28 16:02:29",
            "last_seen_utc": "2026-08-30 06:34:26",
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1890703": [
        {
            "ioc_value": "0bab062af7894bc44d68ebc5b9633a84ffaae1f17671ff3949002c43321ec86a",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "win.valley_rat",
            "malware_alias": "Winos",
            "malware_printable": "ValleyRAT",
            "first_seen_utc": "2026-08-28 16:02:29",
            "last_seen_utc": "2026-08-30 06:34:26",
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1890704": [
        {
            "ioc_value": "7be1989c25579401ac8638a889a1657d5182f7b8",
            "ioc_type": "sha1_hash",
            "threat_type": "payload",
            "malware": "win.valley_rat",
            "malware_alias": "Winos",
            "malware_printable": "ValleyRAT",
            "first_seen_utc": "2026-08-28 16:02:29",
            "last_seen_utc": "2026-08-30 06:34:26",
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1890698": [
        {
            "ioc_value": "5bfdc93f36ecf75b5be5590a48bdc58503c34fb0",
            "ioc_type": "sha1_hash",
            "threat_type": "payload",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-28 16:02:28",
            "last_seen_utc": "2026-08-30 06:34:24",
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1890699": [
        {
            "ioc_value": "2ca17777470b32e4e74b547e5f3f9306",
            "ioc_type": "md5_hash",
            "threat_type": "payload",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-28 16:02:28",
            "last_seen_utc": "2026-08-30 06:34:25",
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1890700": [
        {
            "ioc_value": "9b0e3f974dac0023599bb604b5b30e3e763c2d1d28ecff80d307ca73dc06243f",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "win.dcrat",
            "malware_alias": "DarkCrystal RAT",
            "malware_printable": "DCRat",
            "first_seen_utc": "2026-08-28 16:02:28",
            "last_seen_utc": "2026-08-30 06:34:25",
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1890695": [
        {
            "ioc_value": "bcf32c802a7a27b2bfe6ea5e26b75091c8a76175",
            "ioc_type": "sha1_hash",
            "threat_type": "payload",
            "malware": "py.venus_stealer",
            "malware_alias": null,
            "malware_printable": "Venus Stealer",
            "first_seen_utc": "2026-08-28 16:02:27",
            "last_seen_utc": "2026-08-30 06:34:24",
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1890696": [
        {
            "ioc_value": "4878d995e4e23c6961c91179e6e2c704",
            "ioc_type": "md5_hash",
            "threat_type": "payload",
            "malware": "py.venus_stealer",
            "malware_alias": null,
            "malware_printable": "Venus Stealer",
            "first_seen_utc": "2026-08-28 16:02:27",
            "last_seen_utc": "2026-08-30 06:34:24",
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1890697": [
        {
            "ioc_value": "f63eb2664ac9076250491b1cb0787042f75a056e235867d9f9967322c5cf20a4",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-28 16:02:27",
            "last_seen_utc": "2026-08-30 06:34:24",
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1890692": [
        {
            "ioc_value": "f4ecc1edd84194b94aceb5c3485b830081507508",
            "ioc_type": "sha1_hash",
            "threat_type": "payload",
            "malware": "win.coinminer",
            "malware_alias": null,
            "malware_printable": "Coinminer",
            "first_seen_utc": "2026-08-28 16:02:26",
            "last_seen_utc": "2026-08-30 06:34:23",
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1890693": [
        {
            "ioc_value": "18054d12b0ba2dc0c9918f455ec86699",
            "ioc_type": "md5_hash",
            "threat_type": "payload",
            "malware": "win.coinminer",
            "malware_alias": null,
            "malware_printable": "Coinminer",
            "first_seen_utc": "2026-08-28 16:02:26",
            "last_seen_utc": "2026-08-30 06:34:23",
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1890694": [
        {
            "ioc_value": "5cb54c53e2169a23a815d87229b00c63d1d3c8c0d19e0f92b5e83bd231481419",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "py.venus_stealer",
            "malware_alias": null,
            "malware_printable": "Venus Stealer",
            "first_seen_utc": "2026-08-28 16:02:26",
            "last_seen_utc": "2026-08-30 06:34:23",
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1890690": [
        {
            "ioc_value": "c5616af2cef3dcdb095d8cc55db75c96",
            "ioc_type": "md5_hash",
            "threat_type": "payload",
            "malware": "win.amadey",
            "malware_alias": null,
            "malware_printable": "Amadey",
            "first_seen_utc": "2026-08-28 16:02:25",
            "last_seen_utc": "2026-08-30 06:34:22",
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1890691": [
        {
            "ioc_value": "245f6e3f6750701d58c06bd96f4623c62942305fb32bcdc5a99bf367becaafd0",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "win.coinminer",
            "malware_alias": null,
            "malware_printable": "Coinminer",
            "first_seen_utc": "2026-08-28 16:02:25",
            "last_seen_utc": "2026-08-30 06:34:23",
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1890686": [
        {
            "ioc_value": "3941abf37772bfdeefa1d8b8bc617f9e1ce4bd48",
            "ioc_type": "sha1_hash",
            "threat_type": "payload",
            "malware": "win.gcleaner",
            "malware_alias": null,
            "malware_printable": "GCleaner",
            "first_seen_utc": "2026-08-28 16:02:24",
            "last_seen_utc": "2026-08-30 06:34:21",
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1890687": [
        {
            "ioc_value": "801e7911d8ef33ab7843bb638c0b5abc",
            "ioc_type": "md5_hash",
            "threat_type": "payload",
            "malware": "win.gcleaner",
            "malware_alias": null,
            "malware_printable": "GCleaner",
            "first_seen_utc": "2026-08-28 16:02:24",
            "last_seen_utc": "2026-08-30 06:34:22",
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1890688": [
        {
            "ioc_value": "76e6367d8123171afa540fe92a3758424ec7d1e029c4e5a3b9771e24fe0085c1",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "win.amadey",
            "malware_alias": null,
            "malware_printable": "Amadey",
            "first_seen_utc": "2026-08-28 16:02:24",
            "last_seen_utc": "2026-08-30 06:34:22",
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1890689": [
        {
            "ioc_value": "3c584320e4f7523645ed71d09321d2f5a476f103",
            "ioc_type": "sha1_hash",
            "threat_type": "payload",
            "malware": "win.amadey",
            "malware_alias": null,
            "malware_printable": "Amadey",
            "first_seen_utc": "2026-08-28 16:02:24",
            "last_seen_utc": "2026-08-30 06:34:22",
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1890684": [
        {
            "ioc_value": "356484cecd7e391a8376ad70afa8f97a",
            "ioc_type": "md5_hash",
            "threat_type": "payload",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-08-28 16:02:23",
            "last_seen_utc": "2026-08-30 06:34:20",
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1890685": [
        {
            "ioc_value": "c496e8e8f7cc2e40c515c9dbd98ffce43861acaf504466f478ceaebf712214b8",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "win.gcleaner",
            "malware_alias": null,
            "malware_printable": "GCleaner",
            "first_seen_utc": "2026-08-28 16:02:23",
            "last_seen_utc": "2026-08-30 06:34:20",
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1890681": [
        {
            "ioc_value": "bb65c6e1104854b87418a16fffd59230",
            "ioc_type": "md5_hash",
            "threat_type": "payload",
            "malware": "win.luca_stealer",
            "malware_alias": null,
            "malware_printable": "Luca Stealer",
            "first_seen_utc": "2026-08-28 16:02:22",
            "last_seen_utc": "2026-08-30 06:34:19",
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1890682": [
        {
            "ioc_value": "16168cc3b16d768beffaf0fd10f74f86f79da7a2c7ca26edd91c09c1c101811d",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-08-28 16:02:22",
            "last_seen_utc": "2026-08-30 06:34:20",
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1890683": [
        {
            "ioc_value": "eaf41de301f2e71c912836fd1eac285043ee841f",
            "ioc_type": "sha1_hash",
            "threat_type": "payload",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-08-28 16:02:22",
            "last_seen_utc": "2026-08-30 06:34:20",
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1890678": [
        {
            "ioc_value": "98f00e36daaf4c4bae91031d4b53ea9b",
            "ioc_type": "md5_hash",
            "threat_type": "payload",
            "malware": "win.acr_stealer",
            "malware_alias": null,
            "malware_printable": "ACR Stealer",
            "first_seen_utc": "2026-08-28 16:02:21",
            "last_seen_utc": "2026-08-30 06:34:18",
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1890679": [
        {
            "ioc_value": "b926a44910e4f4d55c53fdc6d9cdbfb043059355d55fb3595a3434bd69b1e7e3",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "win.luca_stealer",
            "malware_alias": null,
            "malware_printable": "Luca Stealer",
            "first_seen_utc": "2026-08-28 16:02:21",
            "last_seen_utc": "2026-08-30 06:34:19",
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1890680": [
        {
            "ioc_value": "32452cd6c337772b89c6a83dfd1c96ab7af565c8",
            "ioc_type": "sha1_hash",
            "threat_type": "payload",
            "malware": "win.luca_stealer",
            "malware_alias": null,
            "malware_printable": "Luca Stealer",
            "first_seen_utc": "2026-08-28 16:02:21",
            "last_seen_utc": "2026-08-30 06:34:19",
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1890674": [
        {
            "ioc_value": "be6714ad8e992e7ef38c3d5c61edfb73259bb64b",
            "ioc_type": "sha1_hash",
            "threat_type": "payload",
            "malware": "win.formbook",
            "malware_alias": "win.xloader",
            "malware_printable": "Formbook",
            "first_seen_utc": "2026-08-28 16:02:20",
            "last_seen_utc": "2026-08-30 06:34:17",
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1890675": [
        {
            "ioc_value": "bedeeefa188f9fea4f050848adcb3f0a",
            "ioc_type": "md5_hash",
            "threat_type": "payload",
            "malware": "win.formbook",
            "malware_alias": "win.xloader",
            "malware_printable": "Formbook",
            "first_seen_utc": "2026-08-28 16:02:20",
            "last_seen_utc": "2026-08-30 06:34:17",
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1890676": [
        {
            "ioc_value": "46ced738ab9a9a37df3e36c6a8603742f26783f0be2fa845bdec10b5ddb50bfb",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "win.acr_stealer",
            "malware_alias": null,
            "malware_printable": "ACR Stealer",
            "first_seen_utc": "2026-08-28 16:02:20",
            "last_seen_utc": "2026-08-30 06:34:18",
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1890677": [
        {
            "ioc_value": "6c19930c2b6b2ec49b42399dcd8e477de347c010",
            "ioc_type": "sha1_hash",
            "threat_type": "payload",
            "malware": "win.acr_stealer",
            "malware_alias": null,
            "malware_printable": "ACR Stealer",
            "first_seen_utc": "2026-08-28 16:02:20",
            "last_seen_utc": "2026-08-30 06:34:18",
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1890671": [
        {
            "ioc_value": "dd10660387c33c8be281991f55a03f0f1a683b62",
            "ioc_type": "sha1_hash",
            "threat_type": "payload",
            "malware": "win.formbook",
            "malware_alias": "win.xloader",
            "malware_printable": "Formbook",
            "first_seen_utc": "2026-08-28 16:02:19",
            "last_seen_utc": "2026-08-30 06:34:16",
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1890672": [
        {
            "ioc_value": "c44e30aa705a5d352079d63eaa1f3dce",
            "ioc_type": "md5_hash",
            "threat_type": "payload",
            "malware": "win.formbook",
            "malware_alias": "win.xloader",
            "malware_printable": "Formbook",
            "first_seen_utc": "2026-08-28 16:02:19",
            "last_seen_utc": "2026-08-30 06:34:17",
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1890673": [
        {
            "ioc_value": "a2fc3ab543e72decbea89ff3479cc9d813324bccccb291cba2536d95b0bdc64c",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "win.formbook",
            "malware_alias": "win.xloader",
            "malware_printable": "Formbook",
            "first_seen_utc": "2026-08-28 16:02:19",
            "last_seen_utc": "2026-08-30 06:34:17",
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1890669": [
        {
            "ioc_value": "9c61f3f9e04f32f1d66edbf131ba9a6b",
            "ioc_type": "md5_hash",
            "threat_type": "payload",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-08-28 16:02:18",
            "last_seen_utc": "2026-08-30 06:34:16",
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1890670": [
        {
            "ioc_value": "94a33fc48ecb504091be4ab6c64cb3b828ac0efe1c9449c8ee952774de38b44f",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "win.formbook",
            "malware_alias": "win.xloader",
            "malware_printable": "Formbook",
            "first_seen_utc": "2026-08-28 16:02:18",
            "last_seen_utc": "2026-08-30 06:34:16",
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1890665": [
        {
            "ioc_value": "8f1d05b224256caed347c500259b721ac97d70fc",
            "ioc_type": "sha1_hash",
            "threat_type": "payload",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-08-28 16:02:17",
            "last_seen_utc": "2026-08-30 06:34:14",
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1890666": [
        {
            "ioc_value": "13f0f22fab59d7475a4ff3d926b1de63",
            "ioc_type": "md5_hash",
            "threat_type": "payload",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-08-28 16:02:17",
            "last_seen_utc": "2026-08-30 06:34:15",
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1890667": [
        {
            "ioc_value": "97fdbb5506534af805db9e23503d93439322650eeaba8132c2627d8a1b9c2dfb",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-08-28 16:02:17",
            "last_seen_utc": "2026-08-30 06:34:15",
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1890668": [
        {
            "ioc_value": "8376ef7e11d99d7b14e2b5d2750fc0978dcf4a8a",
            "ioc_type": "sha1_hash",
            "threat_type": "payload",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-08-28 16:02:17",
            "last_seen_utc": "2026-08-30 06:34:15",
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1890662": [
        {
            "ioc_value": "dd0012a6ba2ffda25354d1a998178b9dce62a482",
            "ioc_type": "sha1_hash",
            "threat_type": "payload",
            "malware": "win.ghost_rat",
            "malware_alias": "Farfli,Gh0st RAT,PCRat",
            "malware_printable": "Ghost RAT",
            "first_seen_utc": "2026-08-28 16:02:16",
            "last_seen_utc": "2026-08-30 06:34:11",
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1890663": [
        {
            "ioc_value": "ba2ff4a8b689fab54670cf87b4008528",
            "ioc_type": "md5_hash",
            "threat_type": "payload",
            "malware": "win.ghost_rat",
            "malware_alias": "Farfli,Gh0st RAT,PCRat",
            "malware_printable": "Ghost RAT",
            "first_seen_utc": "2026-08-28 16:02:16",
            "last_seen_utc": "2026-08-30 06:34:12",
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1890664": [
        {
            "ioc_value": "4f8f926c45e51aa51bea9f95d3e8f34a29bcdc9dec1d3ea40354e50bb69c986b",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-08-28 16:02:16",
            "last_seen_utc": "2026-08-30 06:34:14",
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1890660": [
        {
            "ioc_value": "c7d899d6f7ccecb85c409767d8645906",
            "ioc_type": "md5_hash",
            "threat_type": "payload",
            "malware": "win.coinminer",
            "malware_alias": null,
            "malware_printable": "Coinminer",
            "first_seen_utc": "2026-08-28 16:02:15",
            "last_seen_utc": "2026-08-30 06:34:10",
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1890661": [
        {
            "ioc_value": "c40eac770e2bc5081175b782c4455d977ccff123571a73c3ab8c8c882db38b85",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "win.ghost_rat",
            "malware_alias": "Farfli,Gh0st RAT,PCRat",
            "malware_printable": "Ghost RAT",
            "first_seen_utc": "2026-08-28 16:02:15",
            "last_seen_utc": "2026-08-30 06:34:11",
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1890658": [
        {
            "ioc_value": "656b90c4553ec077f0ff60bf35edee765dffa4d63d4e2148221f9ef1171bb437",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "win.coinminer",
            "malware_alias": null,
            "malware_printable": "Coinminer",
            "first_seen_utc": "2026-08-28 16:02:14",
            "last_seen_utc": "2026-08-30 06:34:09",
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1890659": [
        {
            "ioc_value": "4cecb2462dfdbf0869cab54eef5de1d793c21c80",
            "ioc_type": "sha1_hash",
            "threat_type": "payload",
            "malware": "win.coinminer",
            "malware_alias": null,
            "malware_printable": "Coinminer",
            "first_seen_utc": "2026-08-28 16:02:14",
            "last_seen_utc": "2026-08-30 06:34:10",
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1890655": [
        {
            "ioc_value": "b6296bad0fdf16df0811053e5c5cee71946d05e06222324e76dc26ec676ff976",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "py.creal_stealer",
            "malware_alias": null,
            "malware_printable": "Creal Stealer",
            "first_seen_utc": "2026-08-28 16:02:13",
            "last_seen_utc": "2026-08-30 06:34:09",
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1890656": [
        {
            "ioc_value": "58376e7466c7ca80e9040d28a17d16800ff7d956",
            "ioc_type": "sha1_hash",
            "threat_type": "payload",
            "malware": "py.creal_stealer",
            "malware_alias": null,
            "malware_printable": "Creal Stealer",
            "first_seen_utc": "2026-08-28 16:02:13",
            "last_seen_utc": "2026-08-30 06:34:09",
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1890657": [
        {
            "ioc_value": "579933376ffc365ca48eb14046655171",
            "ioc_type": "md5_hash",
            "threat_type": "payload",
            "malware": "py.creal_stealer",
            "malware_alias": null,
            "malware_printable": "Creal Stealer",
            "first_seen_utc": "2026-08-28 16:02:13",
            "last_seen_utc": "2026-08-30 06:34:09",
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1890653": [
        {
            "ioc_value": "da282e209c707c015745f578076f892cc10d3e24",
            "ioc_type": "sha1_hash",
            "threat_type": "payload",
            "malware": "win.luca_stealer",
            "malware_alias": null,
            "malware_printable": "Luca Stealer",
            "first_seen_utc": "2026-08-28 16:02:12",
            "last_seen_utc": "2026-08-30 06:34:08",
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1890654": [
        {
            "ioc_value": "38588342e64c159b60e1530aef1081bc",
            "ioc_type": "md5_hash",
            "threat_type": "payload",
            "malware": "win.luca_stealer",
            "malware_alias": null,
            "malware_printable": "Luca Stealer",
            "first_seen_utc": "2026-08-28 16:02:12",
            "last_seen_utc": "2026-08-30 06:34:08",
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1890652": [
        {
            "ioc_value": "d47a793404c4bb0419c9ae1fda9847aa6a75a029e60ed65f05645dad9ee9573b",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "win.luca_stealer",
            "malware_alias": null,
            "malware_printable": "Luca Stealer",
            "first_seen_utc": "2026-08-28 16:02:11",
            "last_seen_utc": "2026-08-30 06:34:08",
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1890651": [
        {
            "ioc_value": "96.9.226.22:9462",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-08-28 16:00:52",
            "last_seen_utc": "2026-08-31 07:21:57",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://bazaar.abuse.ch/sample/a4498a429e9b3efe12e2070e454449dc713253d15f0cb575057ca15993403cd4/",
            "tags": "remcos",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1890615": [
        {
            "ioc_value": "34.24.127.255:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-08-28 14:05:05",
            "last_seen_utc": "2026-08-31 07:46:51",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "mythic",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1890601": [
        {
            "ioc_value": "104.207.93.167:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-08-28 13:05:10",
            "last_seen_utc": "2026-08-31 07:43:14",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "mythic",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1890600": [
        {
            "ioc_value": "103.41.177.238:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-08-28 13:05:09",
            "last_seen_utc": "2026-08-31 07:43:10",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "mythic",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1889841": [
        {
            "ioc_value": "185.169.52.99:9001",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remus",
            "malware_alias": null,
            "malware_printable": "Remus",
            "first_seen_utc": "2026-08-28 13:04:03",
            "last_seen_utc": "2026-08-31 02:52:30",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "0f81469cc7638ba7c82eaddbd6b3c20a,c2,remus",
            "anonymous": 0,
            "reporter": "Bitsight"
        }
    ],
    "1890503": [
        {
            "ioc_value": "172.111.163.164:65070",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-08-28 13:03:44",
            "last_seen_utc": "2026-08-30 10:12:52",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "c2,Crypters&tools,Remcos",
            "anonymous": 0,
            "reporter": "Bitsight"
        }
    ],
    "1890592": [
        {
            "ioc_value": "home-power-shield.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-08-28 12:56:23",
            "last_seen_utc": "2026-08-31 05:34:38",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "28August2026,ClearFake,Commandline,DomainShadowing,Windows",
            "anonymous": 0,
            "reporter": "Gi7w0rm"
        }
    ],
    "1890556": [
        {
            "ioc_value": "162.251.92.64:18888",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-08-28 11:47:52",
            "last_seen_utc": "2026-08-31 07:48:38",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1889875": [
        {
            "ioc_value": "94.26.3.30:7081",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.hype_agent",
            "malware_alias": null,
            "malware_printable": "HypeAgent",
            "first_seen_utc": "2026-08-28 09:47:31",
            "last_seen_utc": "2026-08-31 07:48:10",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,HypeAgent",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1889874": [
        {
            "ioc_value": "64.118.140.156:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-08-28 09:46:59",
            "last_seen_utc": "2026-08-31 07:47:33",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1889873": [
        {
            "ioc_value": "52.221.246.243:8443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pupy",
            "malware_alias": "Patpoopy",
            "malware_printable": "pupy",
            "first_seen_utc": "2026-08-28 09:46:55",
            "last_seen_utc": "2026-08-31 07:47:28",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PupyRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1889872": [
        {
            "ioc_value": "37.244.238.125:4433",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.danabot",
            "malware_alias": "DanaTools",
            "malware_printable": "DanaBot",
            "first_seen_utc": "2026-08-28 09:46:25",
            "last_seen_utc": "2026-08-31 07:46:54",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DanBot,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1889871": [
        {
            "ioc_value": "203.159.90.177:55006",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-28 09:45:18",
            "last_seen_utc": "2026-08-31 07:45:41",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1889870": [
        {
            "ioc_value": "20.115.227.161:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-08-28 09:45:14",
            "last_seen_utc": "2026-08-31 07:45:37",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1889869": [
        {
            "ioc_value": "198.23.177.210:7080",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.hype_agent",
            "malware_alias": null,
            "malware_printable": "HypeAgent",
            "first_seen_utc": "2026-08-28 09:45:01",
            "last_seen_utc": "2026-08-31 07:45:30",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,HypeAgent",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1889868": [
        {
            "ioc_value": "194.59.31.78:7080",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.hype_agent",
            "malware_alias": null,
            "malware_printable": "HypeAgent",
            "first_seen_utc": "2026-08-28 09:44:55",
            "last_seen_utc": "2026-08-31 07:45:20",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,HypeAgent",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1889867": [
        {
            "ioc_value": "186.244.245.91:45702",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-08-28 09:44:42",
            "last_seen_utc": "2026-08-31 07:44:58",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1889866": [
        {
            "ioc_value": "172.245.155.83:7080",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.hype_agent",
            "malware_alias": null,
            "malware_printable": "HypeAgent",
            "first_seen_utc": "2026-08-28 09:44:14",
            "last_seen_utc": "2026-08-31 07:44:23",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,HypeAgent",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1889864": [
        {
            "ioc_value": "172.111.198.212:56012",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-28 09:44:12",
            "last_seen_utc": "2026-08-31 07:44:21",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1889865": [
        {
            "ioc_value": "172.111.247.65:7707",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-08-28 09:44:12",
            "last_seen_utc": "2026-08-31 07:44:21",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1889862": [
        {
            "ioc_value": "172.111.177.77:5000",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-08-28 09:44:11",
            "last_seen_utc": "2026-08-31 07:44:20",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1889863": [
        {
            "ioc_value": "172.111.177.77:8888",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-08-28 09:44:11",
            "last_seen_utc": "2026-08-31 07:44:20",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1889861": [
        {
            "ioc_value": "159.203.69.210:8008",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-08-28 09:44:00",
            "last_seen_utc": "2026-08-31 07:44:09",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1889860": [
        {
            "ioc_value": "158.94.209.180:7707",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-08-28 09:43:58",
            "last_seen_utc": "2026-08-31 07:44:08",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1889859": [
        {
            "ioc_value": "154.37.213.27:8443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.havoc",
            "malware_alias": "Havokiz",
            "malware_printable": "Havoc",
            "first_seen_utc": "2026-08-28 09:43:52",
            "last_seen_utc": "2026-08-31 07:43:59",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Havoc",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1889831": [
        {
            "ioc_value": "117.72.182.5:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-08-28 08:05:06",
            "last_seen_utc": "2026-08-31 07:48:28",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "cobaltstrike",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1889817": [
        {
            "ioc_value": "103.41.177.64:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-08-28 07:05:06",
            "last_seen_utc": "2026-08-31 07:43:10",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "mythic",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1889813": [
        {
            "ioc_value": "104.248.41.207:9034",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.aisuru",
            "malware_alias": null,
            "malware_printable": "Aisuru",
            "first_seen_utc": "2026-08-28 06:57:28",
            "last_seen_utc": "2026-08-29 20:39:53",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "Aisuru,c2",
            "anonymous": 0,
            "reporter": "Bitsight"
        }
    ],
    "1889814": [
        {
            "ioc_value": "159.89.24.55:8080",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.aisuru",
            "malware_alias": null,
            "malware_printable": "Aisuru",
            "first_seen_utc": "2026-08-28 06:57:28",
            "last_seen_utc": "2026-08-31 06:01:02",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "Aisuru,c2",
            "anonymous": 0,
            "reporter": "Bitsight"
        }
    ],
    "1889802": [
        {
            "ioc_value": "93.152.221.220:42867",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-08-28 06:25:13",
            "last_seen_utc": "2026-08-31 04:25:55",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "c2,HEAVYFUNDS,Remcos",
            "anonymous": 0,
            "reporter": "Bitsight"
        }
    ],
    "1889447": [
        {
            "ioc_value": "139.59.154.153:9034",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.aisuru",
            "malware_alias": null,
            "malware_printable": "Aisuru",
            "first_seen_utc": "2026-08-28 06:00:30",
            "last_seen_utc": "2026-08-30 23:21:35",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "Aisuru,c2",
            "anonymous": 0,
            "reporter": "Bitsight"
        }
    ],
    "1889452": [
        {
            "ioc_value": "185.169.52.99:6527",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remus",
            "malware_alias": null,
            "malware_printable": "Remus",
            "first_seen_utc": "2026-08-28 06:00:30",
            "last_seen_utc": "2026-08-31 08:13:25",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "6efb1e0ab361cda1dd534e37e543789c,c2,remus",
            "anonymous": 0,
            "reporter": "Bitsight"
        }
    ],
    "1889504": [
        {
            "ioc_value": "140.228.29.51:47701",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-08-28 06:00:29",
            "last_seen_utc": "2026-08-30 02:59:57",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "c2,Remcos,RemoteHost",
            "anonymous": 0,
            "reporter": "Bitsight"
        }
    ],
    "1889550": [
        {
            "ioc_value": "104.248.41.207:8443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.aisuru",
            "malware_alias": null,
            "malware_printable": "Aisuru",
            "first_seen_utc": "2026-08-28 06:00:22",
            "last_seen_utc": "2026-08-31 07:51:47",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "Aisuru,c2",
            "anonymous": 0,
            "reporter": "Bitsight"
        }
    ],
    "1889553": [
        {
            "ioc_value": "https://194.146.39.66",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-08-28 06:00:22",
            "last_seen_utc": "2026-08-30 09:59:39",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "2549bffcf949a19ce487546b5948fdfa,c2,loader,stealer,Vidar",
            "anonymous": 0,
            "reporter": "Bitsight"
        }
    ],
    "1889552": [
        {
            "ioc_value": "http://2.26.126.74/",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.stealc",
            "malware_alias": null,
            "malware_printable": "Stealc",
            "first_seen_utc": "2026-08-28 06:00:21",
            "last_seen_utc": "2026-08-31 08:06:19",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "73f82eed6521,c2,loader,StealC,stealer",
            "anonymous": 0,
            "reporter": "Bitsight"
        }
    ],
    "1889565": [
        {
            "ioc_value": "104.248.247.126:8443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.aisuru",
            "malware_alias": null,
            "malware_printable": "Aisuru",
            "first_seen_utc": "2026-08-28 06:00:20",
            "last_seen_utc": "2026-08-31 07:08:26",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "Aisuru,c2",
            "anonymous": 0,
            "reporter": "Bitsight"
        }
    ],
    "1889741": [
        {
            "ioc_value": "https://kiprihorycom.com/work/",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.latrodectus",
            "malware_alias": "BLACKWIDOW,IceNova,Latrodectus,Lotus",
            "malware_printable": "Latrodectus",
            "first_seen_utc": "2026-08-28 06:00:11",
            "last_seen_utc": "2026-08-31 07:57:45",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "c2,Latrodectus",
            "anonymous": 0,
            "reporter": "Bitsight"
        }
    ],
    "1889745": [
        {
            "ioc_value": "46.101.146.87:8443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.aisuru",
            "malware_alias": null,
            "malware_printable": "Aisuru",
            "first_seen_utc": "2026-08-28 06:00:10",
            "last_seen_utc": "2026-08-30 23:22:10",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "Aisuru,c2",
            "anonymous": 0,
            "reporter": "Bitsight"
        }
    ],
    "1889626": [
        {
            "ioc_value": "68219544dd25a1ab4c2d7184af63a3a367f2850cd4e3b927ab498d27a8960ea8",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "win.netwire",
            "malware_alias": "NetWeird,NetWire,Recam",
            "malware_printable": "NetWire RC",
            "first_seen_utc": "2026-08-28 02:34:38",
            "last_seen_utc": "2026-08-30 01:34:48",
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1889627": [
        {
            "ioc_value": "b9e20e63775d84c0d526c2cf5c234046d7000107",
            "ioc_type": "sha1_hash",
            "threat_type": "payload",
            "malware": "win.netwire",
            "malware_alias": "NetWeird,NetWire,Recam",
            "malware_printable": "NetWire RC",
            "first_seen_utc": "2026-08-28 02:34:38",
            "last_seen_utc": "2026-08-30 01:34:49",
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1889628": [
        {
            "ioc_value": "9823c6808b6a115e65b36335b88742ce",
            "ioc_type": "md5_hash",
            "threat_type": "payload",
            "malware": "win.netwire",
            "malware_alias": "NetWeird,NetWire,Recam",
            "malware_printable": "NetWire RC",
            "first_seen_utc": "2026-08-28 02:34:38",
            "last_seen_utc": "2026-08-30 01:34:49",
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1889623": [
        {
            "ioc_value": "7c71762aae512f7ec674a1f4aa407380184abf2a01b85de8264375b1ae2bcca4",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "win.coinminer",
            "malware_alias": null,
            "malware_printable": "Coinminer",
            "first_seen_utc": "2026-08-28 02:34:37",
            "last_seen_utc": "2026-08-30 06:34:33",
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1889624": [
        {
            "ioc_value": "8f4a7a4b4a9320dadf7b91ac4580f4ea95206421",
            "ioc_type": "sha1_hash",
            "threat_type": "payload",
            "malware": "win.coinminer",
            "malware_alias": null,
            "malware_printable": "Coinminer",
            "first_seen_utc": "2026-08-28 02:34:37",
            "last_seen_utc": "2026-08-30 06:34:33",
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1889625": [
        {
            "ioc_value": "140117db527bee77a2830f1576ce8997",
            "ioc_type": "md5_hash",
            "threat_type": "payload",
            "malware": "win.coinminer",
            "malware_alias": null,
            "malware_printable": "Coinminer",
            "first_seen_utc": "2026-08-28 02:34:37",
            "last_seen_utc": "2026-08-30 06:34:33",
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1889620": [
        {
            "ioc_value": "178b290d24527fda41dcaa0960b289e024e4fac39b96a3d8aebf9be14f51a635",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "win.quasar_rat",
            "malware_alias": "CinaRAT,QuasarRAT,Yggdrasil",
            "malware_printable": "Quasar RAT",
            "first_seen_utc": "2026-08-28 02:34:36",
            "last_seen_utc": "2026-08-30 06:34:30",
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1889621": [
        {
            "ioc_value": "3de514f7e96a69e607258c05c68ddc58145a1531",
            "ioc_type": "sha1_hash",
            "threat_type": "payload",
            "malware": "win.quasar_rat",
            "malware_alias": "CinaRAT,QuasarRAT,Yggdrasil",
            "malware_printable": "Quasar RAT",
            "first_seen_utc": "2026-08-28 02:34:36",
            "last_seen_utc": "2026-08-30 06:34:31",
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1889622": [
        {
            "ioc_value": "3135bf9c620aea1463c948d1be481493",
            "ioc_type": "md5_hash",
            "threat_type": "payload",
            "malware": "win.quasar_rat",
            "malware_alias": "CinaRAT,QuasarRAT,Yggdrasil",
            "malware_printable": "Quasar RAT",
            "first_seen_utc": "2026-08-28 02:34:36",
            "last_seen_utc": "2026-08-30 06:34:31",
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1889617": [
        {
            "ioc_value": "27d22c374ffa52ab63cfb05c09b7925100f6ccd0eb00e314cf8f20be231da250",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "win.quasar_rat",
            "malware_alias": "CinaRAT,QuasarRAT,Yggdrasil",
            "malware_printable": "Quasar RAT",
            "first_seen_utc": "2026-08-28 02:34:35",
            "last_seen_utc": "2026-08-30 06:34:29",
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1889618": [
        {
            "ioc_value": "ce1f829dec06ac8558bc4d2a9973ac85cba073c0",
            "ioc_type": "sha1_hash",
            "threat_type": "payload",
            "malware": "win.quasar_rat",
            "malware_alias": "CinaRAT,QuasarRAT,Yggdrasil",
            "malware_printable": "Quasar RAT",
            "first_seen_utc": "2026-08-28 02:34:35",
            "last_seen_utc": "2026-08-30 06:34:30",
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1889619": [
        {
            "ioc_value": "3304b81686f03893b0a931f23c6665ba",
            "ioc_type": "md5_hash",
            "threat_type": "payload",
            "malware": "win.quasar_rat",
            "malware_alias": "CinaRAT,QuasarRAT,Yggdrasil",
            "malware_printable": "Quasar RAT",
            "first_seen_utc": "2026-08-28 02:34:35",
            "last_seen_utc": "2026-08-30 06:34:30",
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1889613": [
        {
            "ioc_value": "sha.123ful.net",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-08-28 02:25:47",
            "last_seen_utc": "2026-08-30 18:46:33",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "vidar",
            "anonymous": 0,
            "reporter": "crep1x"
        }
    ],
    "1889614": [
        {
            "ioc_value": "https://sha.123ful.net/",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-08-28 02:25:47",
            "last_seen_utc": "2026-08-31 08:12:03",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "vidar",
            "anonymous": 0,
            "reporter": "crep1x"
        }
    ],
    "1889561": [
        {
            "ioc_value": "185.130.46.191:44882",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-08-27 23:47:17",
            "last_seen_utc": "2026-08-31 07:48:40",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1889562": [
        {
            "ioc_value": "185.130.46.191:44884",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-08-27 23:47:17",
            "last_seen_utc": "2026-08-31 07:48:40",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1889563": [
        {
            "ioc_value": "185.130.46.191:44885",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-08-27 23:47:17",
            "last_seen_utc": "2026-08-31 07:48:40",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1889560": [
        {
            "ioc_value": "114.55.250.233:1128",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-08-27 23:47:07",
            "last_seen_utc": "2026-08-31 07:48:26",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1889559": [
        {
            "ioc_value": "ajax.graphwindows.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-08-27 23:46:56",
            "last_seen_utc": "2026-08-31 07:48:14",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1889527": [
        {
            "ioc_value": "rsc.123ful.net",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-08-27 21:05:47",
            "last_seen_utc": "2026-08-30 18:46:33",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "vidar",
            "anonymous": 0,
            "reporter": "crep1x"
        }
    ],
    "1889528": [
        {
            "ioc_value": "https://rsc.123ful.net/",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-08-27 21:05:47",
            "last_seen_utc": "2026-08-31 08:14:31",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "vidar",
            "anonymous": 0,
            "reporter": "crep1x"
        }
    ],
    "1889525": [
        {
            "ioc_value": "cdn14.quran.edu.eu.org",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "js.fakeupdates",
            "malware_alias": "FakeUpdate,GhoLoader,SocGholish",
            "malware_printable": "FAKEUPDATES",
            "first_seen_utc": "2026-08-27 20:41:52",
            "last_seen_utc": "2026-08-29 20:54:18",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": "",
            "tags": "SocGholish",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1889511": [
        {
            "ioc_value": "94.26.3.112:30173",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.hype_agent",
            "malware_alias": null,
            "malware_printable": "HypeAgent",
            "first_seen_utc": "2026-08-27 19:47:51",
            "last_seen_utc": "2026-08-31 07:48:09",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,HypeAgent",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1889510": [
        {
            "ioc_value": "94.154.43.60:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.mirai",
            "malware_alias": "Katana",
            "malware_printable": "Mirai",
            "first_seen_utc": "2026-08-27 19:47:49",
            "last_seen_utc": "2026-08-31 07:48:07",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mirai",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1889509": [
        {
            "ioc_value": "89.125.13.158:36626",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.hype_agent",
            "malware_alias": null,
            "malware_printable": "HypeAgent",
            "first_seen_utc": "2026-08-27 19:47:36",
            "last_seen_utc": "2026-08-31 07:47:54",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,HypeAgent",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1889508": [
        {
            "ioc_value": "64.89.160.76:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.hype_agent",
            "malware_alias": null,
            "malware_printable": "HypeAgent",
            "first_seen_utc": "2026-08-27 19:47:18",
            "last_seen_utc": "2026-08-31 07:47:36",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,HypeAgent",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1889507": [
        {
            "ioc_value": "5.230.201.54:56003",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-27 19:47:08",
            "last_seen_utc": "2026-08-31 07:47:26",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1889506": [
        {
            "ioc_value": "46.246.84.10:8848",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.dcrat",
            "malware_alias": "DarkCrystal RAT",
            "malware_printable": "DCRat",
            "first_seen_utc": "2026-08-27 19:47:05",
            "last_seen_utc": "2026-08-31 07:47:23",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DCRat,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1889505": [
        {
            "ioc_value": "45.94.31.187:56015",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-27 19:47:01",
            "last_seen_utc": "2026-08-31 07:47:20",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1889502": [
        {
            "ioc_value": "217.60.102.3:56001",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-27 19:46:17",
            "last_seen_utc": "2026-08-31 07:46:33",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1889503": [
        {
            "ioc_value": "217.60.102.3:56002",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-27 19:46:17",
            "last_seen_utc": "2026-08-31 07:46:33",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1889501": [
        {
            "ioc_value": "192.229.115.243:56002",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-27 19:44:53",
            "last_seen_utc": "2026-08-31 07:45:09",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1889500": [
        {
            "ioc_value": "191.252.184.198:1337",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.havoc",
            "malware_alias": "Havokiz",
            "malware_printable": "Havoc",
            "first_seen_utc": "2026-08-27 19:44:50",
            "last_seen_utc": "2026-08-31 07:45:01",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Havoc",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1889499": [
        {
            "ioc_value": "185.254.96.155:7000",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-27 19:44:41",
            "last_seen_utc": "2026-08-31 07:44:50",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1889497": [
        {
            "ioc_value": "185.212.128.90:9000",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.evilginx",
            "malware_alias": null,
            "malware_printable": "Evilginx",
            "first_seen_utc": "2026-08-27 19:44:38",
            "last_seen_utc": "2026-08-31 07:44:46",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Evilginx,EvilGoPhish",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1889498": [
        {
            "ioc_value": "185.212.128.96:9000",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.evilginx",
            "malware_alias": null,
            "malware_printable": "Evilginx",
            "first_seen_utc": "2026-08-27 19:44:38",
            "last_seen_utc": "2026-08-31 07:44:46",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Evilginx,EvilGoPhish",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1889496": [
        {
            "ioc_value": "172.111.247.65:6666",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-08-27 19:44:18",
            "last_seen_utc": "2026-08-31 07:44:21",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1889495": [
        {
            "ioc_value": "172.111.198.212:3001",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-27 19:44:17",
            "last_seen_utc": "2026-08-31 07:44:20",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1889494": [
        {
            "ioc_value": "159.195.242.22:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-08-27 19:44:07",
            "last_seen_utc": "2026-08-31 07:44:08",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1889493": [
        {
            "ioc_value": "157.20.182.21:1997",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-08-27 19:44:04",
            "last_seen_utc": "2026-08-31 07:44:05",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1889492": [
        {
            "ioc_value": "154.201.82.108:56001",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-27 19:43:54",
            "last_seen_utc": "2026-08-31 07:43:57",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1889490": [
        {
            "ioc_value": "154.198.49.31:8444",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-08-27 19:43:53",
            "last_seen_utc": "2026-08-31 07:43:57",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1889491": [
        {
            "ioc_value": "154.201.82.106:56001",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-27 19:43:53",
            "last_seen_utc": "2026-08-31 07:43:57",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1889487": [
        {
            "ioc_value": "134.122.187.68:56001",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-27 19:43:39",
            "last_seen_utc": "2026-08-31 07:43:43",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1889488": [
        {
            "ioc_value": "134.122.187.68:56002",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-27 19:43:39",
            "last_seen_utc": "2026-08-31 07:43:43",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1889489": [
        {
            "ioc_value": "134.122.187.68:56003",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-27 19:43:39",
            "last_seen_utc": "2026-08-31 07:43:43",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1889486": [
        {
            "ioc_value": "105.155.16.5:5000",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-08-27 19:43:19",
            "last_seen_utc": "2026-08-31 07:43:21",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1889485": [
        {
            "ioc_value": "105.111.84.214:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-27 19:43:18",
            "last_seen_utc": "2026-08-31 07:43:20",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1889484": [
        {
            "ioc_value": "104.243.248.63:302",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-08-27 19:43:14",
            "last_seen_utc": "2026-08-31 07:43:16",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1889483": [
        {
            "ioc_value": "103.54.153.49:56003",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-27 19:43:09",
            "last_seen_utc": "2026-08-31 07:43:11",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1889482": [
        {
            "ioc_value": "102.117.174.189:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-08-27 19:43:04",
            "last_seen_utc": "2026-08-31 07:43:05",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1889443": [
        {
            "ioc_value": "en-us-theeloncod.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-08-27 16:34:54",
            "last_seen_utc": "2026-08-31 03:13:13",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "27August2026,ClearFake,Commandline,DomainShadowing,Windows",
            "anonymous": 0,
            "reporter": "Gi7w0rm"
        }
    ],
    "1889432": [
        {
            "ioc_value": "bnb.123ful.net",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-08-27 15:45:47",
            "last_seen_utc": "2026-08-30 18:46:34",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "vidar",
            "anonymous": 0,
            "reporter": "crep1x"
        }
    ],
    "1889303": [
        {
            "ioc_value": "159.89.24.55:8443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.aisuru",
            "malware_alias": null,
            "malware_printable": "Aisuru",
            "first_seen_utc": "2026-08-27 14:54:27",
            "last_seen_utc": "2026-08-30 22:47:36",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "Aisuru,c2",
            "anonymous": 0,
            "reporter": "Bitsight"
        }
    ],
    "1889306": [
        {
            "ioc_value": "217.60.195.33:17542",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-08-27 14:54:27",
            "last_seen_utc": "2026-08-31 03:56:24",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "c2,DonRemoteHost,Remcos",
            "anonymous": 0,
            "reporter": "Bitsight"
        }
    ],
    "1889307": [
        {
            "ioc_value": "109.248.151.101:2404",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-08-27 14:54:26",
            "last_seen_utc": "2026-08-31 04:15:31",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "c2,Remcos,RemoteHost",
            "anonymous": 0,
            "reporter": "Bitsight"
        }
    ],
    "1889310": [
        {
            "ioc_value": "155.103.71.126:2405",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-08-27 14:54:25",
            "last_seen_utc": "2026-08-31 03:58:29",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "c2,Remcos,RemoteHost",
            "anonymous": 0,
            "reporter": "Bitsight"
        }
    ],
    "1889311": [
        {
            "ioc_value": "203.202.232.155:2444",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-08-27 14:54:25",
            "last_seen_utc": "2026-08-31 04:21:23",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "c2,Remcos,RemoteHost",
            "anonymous": 0,
            "reporter": "Bitsight"
        }
    ],
    "1889312": [
        {
            "ioc_value": "209.99.188.27:2404",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-08-27 14:54:24",
            "last_seen_utc": "2026-08-31 04:03:18",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "4,c2,Remcos",
            "anonymous": 0,
            "reporter": "Bitsight"
        }
    ],
    "1889313": [
        {
            "ioc_value": "31.40.204.219:3467",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-08-27 14:54:24",
            "last_seen_utc": "2026-08-31 03:57:44",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "c2,Remcos,RemoteHost",
            "anonymous": 0,
            "reporter": "Bitsight"
        }
    ],
    "1889315": [
        {
            "ioc_value": "45.92.1.39:2404",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-08-27 14:54:22",
            "last_seen_utc": "2026-08-29 21:54:08",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "c2,Remcos,RemoteHost",
            "anonymous": 0,
            "reporter": "Bitsight"
        }
    ],
    "1889318": [
        {
            "ioc_value": "161.248.179.102:1604",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-08-27 14:54:21",
            "last_seen_utc": "2026-08-31 04:07:23",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "c2,Remcos,SALES",
            "anonymous": 0,
            "reporter": "Bitsight"
        }
    ],
    "1889321": [
        {
            "ioc_value": "45.225.135.55:8080",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-08-27 14:54:13",
            "last_seen_utc": "2026-08-31 08:13:21",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "23_06_64B,c2,Remcos",
            "anonymous": 0,
            "reporter": "Bitsight"
        }
    ],
    "1889322": [
        {
            "ioc_value": "23.95.117.233:2404",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-08-27 14:54:12",
            "last_seen_utc": "2026-08-31 05:50:09",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "c2,Remcos,RemoteHost",
            "anonymous": 0,
            "reporter": "Bitsight"
        }
    ],
    "1889323": [
        {
            "ioc_value": "185.91.126.34:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-08-27 14:54:12",
            "last_seen_utc": "2026-08-30 18:03:43",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "c2,Remcos,Server",
            "anonymous": 0,
            "reporter": "Bitsight"
        }
    ],
    "1889324": [
        {
            "ioc_value": "185.39.18.230:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-08-27 14:54:11",
            "last_seen_utc": "2026-08-30 04:51:52",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "avpagent,c2,Remcos",
            "anonymous": 0,
            "reporter": "Bitsight"
        }
    ],
    "1889289": [
        {
            "ioc_value": "209.97.138.100:8443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.aisuru",
            "malware_alias": null,
            "malware_printable": "Aisuru",
            "first_seen_utc": "2026-08-27 13:54:16",
            "last_seen_utc": "2026-08-31 04:58:09",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "Aisuru,c2",
            "anonymous": 0,
            "reporter": "Bitsight"
        }
    ],
    "1889245": [
        {
            "ioc_value": "8.162.1.240:10087",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-08-27 11:48:55",
            "last_seen_utc": "2026-08-31 07:48:57",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1889244": [
        {
            "ioc_value": "47.79.21.106:45678",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-08-27 11:48:51",
            "last_seen_utc": "2026-08-31 07:48:53",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1889243": [
        {
            "ioc_value": "39.97.57.155:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-08-27 11:48:44",
            "last_seen_utc": "2026-08-31 07:48:47",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1889242": [
        {
            "ioc_value": "38.207.177.73:9966",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-08-27 11:48:43",
            "last_seen_utc": "2026-08-31 07:48:46",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1889241": [
        {
            "ioc_value": "186.244.245.91:28446",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-08-27 11:48:39",
            "last_seen_utc": "2026-08-31 07:48:42",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1889239": [
        {
            "ioc_value": "106.15.10.2:11111",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-08-27 11:48:21",
            "last_seen_utc": "2026-08-31 07:48:23",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1889240": [
        {
            "ioc_value": "106.15.10.2:6789",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-08-27 11:48:21",
            "last_seen_utc": "2026-08-31 07:48:24",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1889238": [
        {
            "ioc_value": "c-proxy-xjmkjgbsdn.cn-hangzhou.fcapp.run",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-08-27 11:48:13",
            "last_seen_utc": "2026-08-31 07:48:14",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1889201": [
        {
            "ioc_value": "https://46.29.26.32",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-08-27 11:45:54",
            "last_seen_utc": "2026-08-31 08:12:38",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ac7d2c4b87323734e60ab2166f449356,c2,loader,stealer,Vidar",
            "anonymous": 0,
            "reporter": "Bitsight"
        }
    ],
    "1889212": [
        {
            "ioc_value": "rmv.123ful.net",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-08-27 10:20:47",
            "last_seen_utc": "2026-08-30 18:46:33",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "vidar",
            "anonymous": 0,
            "reporter": "crep1x"
        }
    ],
    "1889205": [
        {
            "ioc_value": "185.34.147.32:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-08-27 10:05:10",
            "last_seen_utc": "2026-08-31 07:44:53",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "asyncrat",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1889206": [
        {
            "ioc_value": "45.61.170.105:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-08-27 10:05:10",
            "last_seen_utc": "2026-08-31 07:47:15",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "mythic",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1889181": [
        {
            "ioc_value": "62.238.110.216:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-08-27 09:47:08",
            "last_seen_utc": "2026-08-31 07:47:33",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1889180": [
        {
            "ioc_value": "56.69.251.23:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-27 09:47:06",
            "last_seen_utc": "2026-08-31 07:47:31",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1889179": [
        {
            "ioc_value": "38.240.48.155:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-27 09:46:35",
            "last_seen_utc": "2026-08-31 07:46:57",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1889178": [
        {
            "ioc_value": "217.60.195.139:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-27 09:46:14",
            "last_seen_utc": "2026-08-31 07:46:34",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1889177": [
        {
            "ioc_value": "217.217.97.164:8443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.havoc",
            "malware_alias": "Havokiz",
            "malware_printable": "Havoc",
            "first_seen_utc": "2026-08-27 09:46:13",
            "last_seen_utc": "2026-08-31 07:46:32",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Havoc",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1889175": [
        {
            "ioc_value": "209.97.166.99:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.sliver",
            "malware_alias": null,
            "malware_printable": "Sliver",
            "first_seen_utc": "2026-08-27 09:45:31",
            "last_seen_utc": "2026-08-31 07:45:47",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Sliver",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1889174": [
        {
            "ioc_value": "203.202.232.132:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-27 09:45:24",
            "last_seen_utc": "2026-08-31 07:45:41",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1889173": [
        {
            "ioc_value": "201.51.2.186:8443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-08-27 09:45:22",
            "last_seen_utc": "2026-08-31 07:45:39",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1889172": [
        {
            "ioc_value": "2.27.203.59:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.mirai",
            "malware_alias": "Katana",
            "malware_printable": "Mirai",
            "first_seen_utc": "2026-08-27 09:45:16",
            "last_seen_utc": "2026-08-31 07:45:33",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mirai",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1889171": [
        {
            "ioc_value": "199.245.176.147:7707",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-08-27 09:45:14",
            "last_seen_utc": "2026-08-31 07:45:32",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1889170": [
        {
            "ioc_value": "198.23.177.210:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.hype_agent",
            "malware_alias": null,
            "malware_printable": "HypeAgent",
            "first_seen_utc": "2026-08-27 09:45:10",
            "last_seen_utc": "2026-08-31 07:45:30",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,HypeAgent",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1889169": [
        {
            "ioc_value": "188.190.23.7:4343",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-08-27 09:44:46",
            "last_seen_utc": "2026-08-31 07:44:59",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1889167": [
        {
            "ioc_value": "172.86.119.225:8443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.evilginx",
            "malware_alias": null,
            "malware_printable": "Evilginx",
            "first_seen_utc": "2026-08-27 09:44:17",
            "last_seen_utc": "2026-08-31 07:44:26",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Evilginx,EvilGoPhish",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1889168": [
        {
            "ioc_value": "172.93.187.109:13901",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.sliver",
            "malware_alias": null,
            "malware_printable": "Sliver",
            "first_seen_utc": "2026-08-27 09:44:17",
            "last_seen_utc": "2026-08-31 07:44:27",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Sliver",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1889166": [
        {
            "ioc_value": "158.94.210.136:7707",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-08-27 09:43:59",
            "last_seen_utc": "2026-08-31 07:44:08",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1889165": [
        {
            "ioc_value": "155.117.183.31:7080",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.hype_agent",
            "malware_alias": null,
            "malware_printable": "HypeAgent",
            "first_seen_utc": "2026-08-27 09:43:53",
            "last_seen_utc": "2026-08-31 07:44:00",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,HypeAgent",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1889163": [
        {
            "ioc_value": "154.201.82.105:56002",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-27 09:43:50",
            "last_seen_utc": "2026-08-31 07:43:57",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1889164": [
        {
            "ioc_value": "154.201.82.106:56002",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-27 09:43:50",
            "last_seen_utc": "2026-08-31 07:43:57",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1889162": [
        {
            "ioc_value": "144.31.6.21:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-27 09:43:43",
            "last_seen_utc": "2026-08-31 07:43:50",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1889161": [
        {
            "ioc_value": "144.217.94.115:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.evilginx",
            "malware_alias": null,
            "malware_printable": "Evilginx",
            "first_seen_utc": "2026-08-27 09:43:42",
            "last_seen_utc": "2026-08-31 07:43:49",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Evilginx,EvilGoPhish",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1889159": [
        {
            "ioc_value": "105.159.4.49:5000",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-08-27 09:43:18",
            "last_seen_utc": "2026-08-31 07:43:21",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1889160": [
        {
            "ioc_value": "106.15.65.247:8443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.havoc",
            "malware_alias": "Havokiz",
            "malware_printable": "Havoc",
            "first_seen_utc": "2026-08-27 09:43:18",
            "last_seen_utc": "2026-08-31 07:43:21",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Havoc",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1889154": [
        {
            "ioc_value": "en-us-nurvealive.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-08-27 09:21:32",
            "last_seen_utc": "2026-08-29 14:53:17",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "27August2026,ClearFake,Commandline,DomainShadowing,Windows",
            "anonymous": 0,
            "reporter": "Gi7w0rm"
        }
    ],
    "1889149": [
        {
            "ioc_value": "206.123.137.133:56090",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-08-27 09:05:07",
            "last_seen_utc": "2026-08-31 04:07:56",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "RAT,RemcosRAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1889127": [
        {
            "ioc_value": "217.60.195.34:18622",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-08-27 08:50:41",
            "last_seen_utc": "2026-08-31 04:17:17",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://bazaar.abuse.ch/sample/1be4ef70585595235b1f6b4890552228382101ba41226661aa6a86585e5fc458/",
            "tags": "remcos",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1889092": [
        {
            "ioc_value": "172.245.155.83:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.hype_agent",
            "malware_alias": null,
            "malware_printable": "HypeAgent",
            "first_seen_utc": "2026-08-27 08:38:11",
            "last_seen_utc": "2026-08-31 07:44:23",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "",
            "tags": "HypeAgent",
            "anonymous": 0,
            "reporter": "whoamix302"
        }
    ],
    "1889093": [
        {
            "ioc_value": "94.26.3.112:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.hype_agent",
            "malware_alias": null,
            "malware_printable": "HypeAgent",
            "first_seen_utc": "2026-08-27 08:38:10",
            "last_seen_utc": "2026-08-31 07:48:09",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "",
            "tags": "HypeAgent",
            "anonymous": 0,
            "reporter": "whoamix302"
        }
    ],
    "1889094": [
        {
            "ioc_value": "94.26.3.112:7080",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.hype_agent",
            "malware_alias": null,
            "malware_printable": "HypeAgent",
            "first_seen_utc": "2026-08-27 08:38:10",
            "last_seen_utc": "2026-08-31 07:48:09",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "",
            "tags": "HypeAgent",
            "anonymous": 0,
            "reporter": "whoamix302"
        }
    ],
    "1889095": [
        {
            "ioc_value": "198.23.177.206:7080",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.hype_agent",
            "malware_alias": null,
            "malware_printable": "HypeAgent",
            "first_seen_utc": "2026-08-27 08:38:09",
            "last_seen_utc": "2026-08-31 07:45:30",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "",
            "tags": "HypeAgent",
            "anonymous": 0,
            "reporter": "whoamix302"
        }
    ],
    "1889096": [
        {
            "ioc_value": "198.23.177.206:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.hype_agent",
            "malware_alias": null,
            "malware_printable": "HypeAgent",
            "first_seen_utc": "2026-08-27 08:38:09",
            "last_seen_utc": "2026-08-31 07:45:30",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "",
            "tags": "HypeAgent",
            "anonymous": 0,
            "reporter": "whoamix302"
        }
    ],
    "1889097": [
        {
            "ioc_value": "46.151.182.98:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.hype_agent",
            "malware_alias": null,
            "malware_printable": "HypeAgent",
            "first_seen_utc": "2026-08-27 08:38:09",
            "last_seen_utc": "2026-08-31 07:47:22",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "",
            "tags": "HypeAgent",
            "anonymous": 0,
            "reporter": "whoamix302"
        }
    ],
    "1889098": [
        {
            "ioc_value": "196.251.121.137:7080",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.hype_agent",
            "malware_alias": null,
            "malware_printable": "HypeAgent",
            "first_seen_utc": "2026-08-27 08:38:09",
            "last_seen_utc": "2026-08-31 07:45:29",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "",
            "tags": "HypeAgent",
            "anonymous": 0,
            "reporter": "whoamix302"
        }
    ],
    "1889104": [
        {
            "ioc_value": "69.166.66.88:4480",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.quasar_rat",
            "malware_alias": "CinaRAT,QuasarRAT,Yggdrasil",
            "malware_printable": "Quasar RAT",
            "first_seen_utc": "2026-08-27 08:38:05",
            "last_seen_utc": "2026-08-31 03:05:06",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "",
            "tags": "CinaRAT,Quasar RAT,QuasarRAT,Yggdrasil",
            "anonymous": 0,
            "reporter": "whoamix302"
        }
    ],
    "1888320": [
        {
            "ioc_value": "94.154.43.249:8001",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.aisuru",
            "malware_alias": null,
            "malware_printable": "Aisuru",
            "first_seen_utc": "2026-08-27 07:22:35",
            "last_seen_utc": "2026-08-29 16:41:10",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "Aisuru,c2",
            "anonymous": 0,
            "reporter": "Bitsight"
        }
    ],
    "1888334": [
        {
            "ioc_value": "159.65.50.202:8443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.aisuru",
            "malware_alias": null,
            "malware_printable": "Aisuru",
            "first_seen_utc": "2026-08-27 07:22:34",
            "last_seen_utc": "2026-08-31 03:15:29",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "Aisuru,c2",
            "anonymous": 0,
            "reporter": "Bitsight"
        }
    ],
    "1888903": [
        {
            "ioc_value": "154.94.224.35:2096",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-08-27 07:21:34",
            "last_seen_utc": "2026-08-31 07:48:36",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": null,
            "tags": "141159,c2,censys,cobalt strike",
            "anonymous": 0,
            "reporter": "sojubear"
        }
    ],
    "1888905": [
        {
            "ioc_value": "154.94.224.35:2087",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-08-27 07:21:33",
            "last_seen_utc": "2026-08-31 07:48:36",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": null,
            "tags": "141159,c2,censys,cobalt strike",
            "anonymous": 0,
            "reporter": "sojubear"
        }
    ],
    "1888911": [
        {
            "ioc_value": "http://144.31.40.80/",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.stealc",
            "malware_alias": null,
            "malware_printable": "Stealc",
            "first_seen_utc": "2026-08-27 07:21:33",
            "last_seen_utc": "2026-08-31 08:09:45",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "c2,loader,mix,StealC,stealer",
            "anonymous": 0,
            "reporter": "Bitsight"
        }
    ],
    "1888938": [
        {
            "ioc_value": "104.248.247.126:8080",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.aisuru",
            "malware_alias": null,
            "malware_printable": "Aisuru",
            "first_seen_utc": "2026-08-27 07:21:32",
            "last_seen_utc": "2026-08-31 04:56:55",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "Aisuru,c2",
            "anonymous": 0,
            "reporter": "Bitsight"
        }
    ],
    "1888928": [
        {
            "ioc_value": "139.59.154.153:8080",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.aisuru",
            "malware_alias": null,
            "malware_printable": "Aisuru",
            "first_seen_utc": "2026-08-27 07:21:31",
            "last_seen_utc": "2026-08-30 11:18:17",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "Aisuru,c2",
            "anonymous": 0,
            "reporter": "Bitsight"
        }
    ],
    "1888939": [
        {
            "ioc_value": "139.59.154.153:8443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.aisuru",
            "malware_alias": null,
            "malware_printable": "Aisuru",
            "first_seen_utc": "2026-08-27 07:21:30",
            "last_seen_utc": "2026-08-31 06:34:03",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "Aisuru,c2",
            "anonymous": 0,
            "reporter": "Bitsight"
        }
    ],
    "1888914": [
        {
            "ioc_value": "vcd.123ful.net",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-08-27 02:05:47",
            "last_seen_utc": "2026-08-30 18:46:33",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "vidar",
            "anonymous": 0,
            "reporter": "crep1x"
        }
    ],
    "1888915": [
        {
            "ioc_value": "https://vcd.123ful.net/",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-08-27 02:05:47",
            "last_seen_utc": "2026-08-31 08:12:31",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "vidar",
            "anonymous": 0,
            "reporter": "crep1x"
        }
    ],
    "1888814": [
        {
            "ioc_value": "198.23.209.155:6466",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-08-26 22:03:27",
            "last_seen_utc": "2026-08-31 07:45:31",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "",
            "tags": "AsyncRAT",
            "anonymous": 0,
            "reporter": "whoamix302"
        }
    ],
    "1888807": [
        {
            "ioc_value": "209.99.186.142:55009",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-26 22:01:47",
            "last_seen_utc": "2026-08-31 07:45:47",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "",
            "tags": "PureHVNC,PureRAT,ResolverRAT",
            "anonymous": 0,
            "reporter": "whoamix302"
        }
    ],
    "1888726": [
        {
            "ioc_value": "cosmeticstakara.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.iclickfix",
            "malware_alias": null,
            "malware_printable": "IClickFix",
            "first_seen_utc": "2026-08-26 21:54:38",
            "last_seen_utc": "2026-08-29 12:21:36",
            "confidence_level": 50,
            "is_compromised": true,
            "reference": "",
            "tags": "ClearFake,ClickFix",
            "anonymous": 0,
            "reporter": "skocherhan"
        }
    ],
    "1888731": [
        {
            "ioc_value": "tempsgraphie.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.iclickfix",
            "malware_alias": null,
            "malware_printable": "IClickFix",
            "first_seen_utc": "2026-08-26 21:54:38",
            "last_seen_utc": "2026-08-29 12:21:36",
            "confidence_level": 50,
            "is_compromised": true,
            "reference": "",
            "tags": "ClearFake,ClickFix",
            "anonymous": 0,
            "reporter": "skocherhan"
        }
    ],
    "1888736": [
        {
            "ioc_value": "gascreative.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.iclickfix",
            "malware_alias": null,
            "malware_printable": "IClickFix",
            "first_seen_utc": "2026-08-26 21:54:38",
            "last_seen_utc": "2026-08-29 12:11:34",
            "confidence_level": 50,
            "is_compromised": true,
            "reference": "",
            "tags": "ClearFake,ClickFix",
            "anonymous": 0,
            "reporter": "skocherhan"
        }
    ],
    "1888716": [
        {
            "ioc_value": "lootguys.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.iclickfix",
            "malware_alias": null,
            "malware_printable": "IClickFix",
            "first_seen_utc": "2026-08-26 21:54:37",
            "last_seen_utc": "2026-08-29 12:11:35",
            "confidence_level": 50,
            "is_compromised": true,
            "reference": "",
            "tags": "ClearFake,ClickFix",
            "anonymous": 0,
            "reporter": "skocherhan"
        }
    ],
    "1888601": [
        {
            "ioc_value": "202.155.9.186:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-26 21:44:55",
            "last_seen_utc": "2026-08-31 07:45:39",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1888600": [
        {
            "ioc_value": "195.177.94.91:56002",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-26 21:44:46",
            "last_seen_utc": "2026-08-31 07:45:27",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1888599": [
        {
            "ioc_value": "195.177.94.91:56001",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-26 21:44:45",
            "last_seen_utc": "2026-08-31 07:45:26",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1888598": [
        {
            "ioc_value": "193.233.126.164:56002",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-26 21:44:39",
            "last_seen_utc": "2026-08-31 07:45:14",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1888597": [
        {
            "ioc_value": "193.233.126.164:56001",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-26 21:44:38",
            "last_seen_utc": "2026-08-31 07:45:14",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1888593": [
        {
            "ioc_value": "192.229.115.246:56001",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-26 21:44:36",
            "last_seen_utc": "2026-08-31 07:45:09",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1888594": [
        {
            "ioc_value": "192.229.115.246:56002",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-26 21:44:36",
            "last_seen_utc": "2026-08-31 07:45:09",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1888595": [
        {
            "ioc_value": "192.229.115.254:56001",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-26 21:44:36",
            "last_seen_utc": "2026-08-31 07:45:10",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1888596": [
        {
            "ioc_value": "192.229.115.254:56002",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-26 21:44:36",
            "last_seen_utc": "2026-08-31 07:45:10",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1888592": [
        {
            "ioc_value": "192.229.115.243:56001",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-26 21:44:35",
            "last_seen_utc": "2026-08-31 07:45:09",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1888591": [
        {
            "ioc_value": "147.45.61.65:56002",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-26 21:43:39",
            "last_seen_utc": "2026-08-31 07:43:52",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1888590": [
        {
            "ioc_value": "105.103.57.94:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-26 21:43:15",
            "last_seen_utc": "2026-08-31 07:43:20",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1888588": [
        {
            "ioc_value": "103.54.153.49:56001",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-26 21:43:08",
            "last_seen_utc": "2026-08-31 07:43:10",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1888589": [
        {
            "ioc_value": "103.54.153.49:56002",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-26 21:43:08",
            "last_seen_utc": "2026-08-31 07:43:11",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1888543": [
        {
            "ioc_value": "31.77.220.21:62020",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.hype_agent",
            "malware_alias": null,
            "malware_printable": "HypeAgent",
            "first_seen_utc": "2026-08-26 20:53:46",
            "last_seen_utc": "2026-08-31 07:46:50",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "",
            "tags": "HypeAgent",
            "anonymous": 0,
            "reporter": "whoamix302"
        }
    ],
    "1888544": [
        {
            "ioc_value": "155.117.183.31:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.hype_agent",
            "malware_alias": null,
            "malware_printable": "HypeAgent",
            "first_seen_utc": "2026-08-26 20:53:46",
            "last_seen_utc": "2026-08-31 07:44:00",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "",
            "tags": "HypeAgent",
            "anonymous": 0,
            "reporter": "whoamix302"
        }
    ],
    "1888539": [
        {
            "ioc_value": "31.57.219.139:56003",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-26 20:50:46",
            "last_seen_utc": "2026-08-31 07:46:47",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "",
            "tags": "PureHVNC,PureRAT,ResolverRAT",
            "anonymous": 0,
            "reporter": "whoamix302"
        }
    ],
    "1888540": [
        {
            "ioc_value": "38.240.48.155:56003",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-26 20:50:46",
            "last_seen_utc": "2026-08-31 07:46:57",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "",
            "tags": "PureHVNC,PureRAT,ResolverRAT",
            "anonymous": 0,
            "reporter": "whoamix302"
        }
    ],
    "1888533": [
        {
            "ioc_value": "209.97.166.99:9999",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.sliver",
            "malware_alias": null,
            "malware_printable": "Sliver",
            "first_seen_utc": "2026-08-26 20:46:55",
            "last_seen_utc": "2026-08-31 07:45:47",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "",
            "tags": "Sliver",
            "anonymous": 0,
            "reporter": "whoamix302"
        }
    ],
    "1888487": [
        {
            "ioc_value": "2.88.92.98:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.havoc",
            "malware_alias": "Havokiz",
            "malware_printable": "Havoc",
            "first_seen_utc": "2026-08-26 20:05:06",
            "last_seen_utc": "2026-08-31 07:45:36",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "havoc",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1888479": [
        {
            "ioc_value": "77.110.109.229:8848",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.dcrat",
            "malware_alias": "DarkCrystal RAT",
            "malware_printable": "DCRat",
            "first_seen_utc": "2026-08-26 19:46:34",
            "last_seen_utc": "2026-08-31 07:47:41",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DCRat,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1888478": [
        {
            "ioc_value": "52.41.190.254:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.poshc2",
            "malware_alias": null,
            "malware_printable": "PoshC2",
            "first_seen_utc": "2026-08-26 19:46:23",
            "last_seen_utc": "2026-08-31 07:47:29",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PoshC2",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1888477": [
        {
            "ioc_value": "49.232.135.25:8080",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.havoc",
            "malware_alias": "Havokiz",
            "malware_printable": "Havoc",
            "first_seen_utc": "2026-08-26 19:46:20",
            "last_seen_utc": "2026-08-31 07:47:25",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Havoc",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1888476": [
        {
            "ioc_value": "46.246.6.27:8848",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.dcrat",
            "malware_alias": "DarkCrystal RAT",
            "malware_printable": "DCRat",
            "first_seen_utc": "2026-08-26 19:46:19",
            "last_seen_utc": "2026-08-31 07:47:23",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DCRat,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1888475": [
        {
            "ioc_value": "45.142.30.157:7770",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.dcrat",
            "malware_alias": "DarkCrystal RAT",
            "malware_printable": "DCRat",
            "first_seen_utc": "2026-08-26 19:46:07",
            "last_seen_utc": "2026-08-31 07:47:08",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DCRat,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1888474": [
        {
            "ioc_value": "45.131.182.88:6606",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-08-26 19:46:05",
            "last_seen_utc": "2026-08-31 07:47:07",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1888473": [
        {
            "ioc_value": "199.245.176.147:8808",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-08-26 19:44:42",
            "last_seen_utc": "2026-08-31 07:45:32",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1888472": [
        {
            "ioc_value": "193.111.117.26:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-08-26 19:44:32",
            "last_seen_utc": "2026-08-31 07:45:11",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1888471": [
        {
            "ioc_value": "192.121.163.188:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.havoc",
            "malware_alias": "Havokiz",
            "malware_printable": "Havoc",
            "first_seen_utc": "2026-08-26 19:44:29",
            "last_seen_utc": "2026-08-31 07:45:05",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Havoc",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1888470": [
        {
            "ioc_value": "188.23.175.25:8000",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.eye_pyramid",
            "malware_alias": null,
            "malware_printable": "Eye Pyramid",
            "first_seen_utc": "2026-08-26 19:44:28",
            "last_seen_utc": "2026-08-31 07:45:00",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,EyePyramid",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1888469": [
        {
            "ioc_value": "187.145.56.252:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-08-26 19:44:27",
            "last_seen_utc": "2026-08-31 07:44:58",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1888466": [
        {
            "ioc_value": "158.220.96.15:3321",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-08-26 19:43:49",
            "last_seen_utc": "2026-08-31 07:44:07",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1888465": [
        {
            "ioc_value": "157.20.182.21:1998",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-08-26 19:43:47",
            "last_seen_utc": "2026-08-31 07:44:05",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1888396": [
        {
            "ioc_value": "tak.123ful.net",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-08-26 18:10:47",
            "last_seen_utc": "2026-08-30 18:46:33",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "vidar",
            "anonymous": 0,
            "reporter": "crep1x"
        }
    ],
    "1888397": [
        {
            "ioc_value": "https://tak.123ful.net/",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-08-26 18:10:47",
            "last_seen_utc": "2026-08-31 08:13:10",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "vidar",
            "anonymous": 0,
            "reporter": "crep1x"
        }
    ],
    "1888271": [
        {
            "ioc_value": "102.220.160.221:2404",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-08-26 15:09:39",
            "last_seen_utc": "2026-08-31 08:10:23",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://bazaar.abuse.ch/sample/306e7d78929cb893e2ecde6bb182b0c8423991275a999704c69eaf9282be1091/",
            "tags": "RAT,RemcosRAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1888148": [
        {
            "ioc_value": "46.101.179.59:8443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.aisuru",
            "malware_alias": null,
            "malware_printable": "Aisuru",
            "first_seen_utc": "2026-08-26 12:43:55",
            "last_seen_utc": "2026-08-31 07:10:50",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "Aisuru,c2",
            "anonymous": 0,
            "reporter": "Bitsight"
        }
    ],
    "1888193": [
        {
            "ioc_value": "204.77.9.71:7080",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.hype_agent",
            "malware_alias": null,
            "malware_printable": "HypeAgent",
            "first_seen_utc": "2026-08-26 12:08:13",
            "last_seen_utc": "2026-08-31 07:45:43",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "",
            "tags": "HypeAgent",
            "anonymous": 0,
            "reporter": "whoamix302"
        }
    ],
    "1888190": [
        {
            "ioc_value": "108.186.112.147:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.hype_agent",
            "malware_alias": null,
            "malware_printable": "HypeAgent",
            "first_seen_utc": "2026-08-26 12:08:12",
            "last_seen_utc": "2026-08-31 07:43:25",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "",
            "tags": "HypeAgent",
            "anonymous": 0,
            "reporter": "whoamix302"
        }
    ],
    "1888176": [
        {
            "ioc_value": "34.45.74.63:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-08-26 12:05:07",
            "last_seen_utc": "2026-08-31 07:46:52",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "asyncrat",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1888158": [
        {
            "ioc_value": "178.208.169.166:7070",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-08-26 12:03:30",
            "last_seen_utc": "2026-08-31 07:44:35",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "",
            "tags": "AsyncRAT",
            "anonymous": 0,
            "reporter": "whoamix302"
        }
    ],
    "1888159": [
        {
            "ioc_value": "107.175.88.79:30305",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-08-26 12:03:30",
            "last_seen_utc": "2026-08-31 07:43:24",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "",
            "tags": "AsyncRAT",
            "anonymous": 0,
            "reporter": "whoamix302"
        }
    ],
    "1888154": [
        {
            "ioc_value": "91.108.189.81:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-08-26 11:48:52",
            "last_seen_utc": "2026-08-31 07:48:58",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1888153": [
        {
            "ioc_value": "online-r.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-08-26 11:48:12",
            "last_seen_utc": "2026-08-31 07:48:19",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1888124": [
        {
            "ioc_value": "eos.123ful.net",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-08-26 10:50:47",
            "last_seen_utc": "2026-08-30 18:46:34",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "vidar",
            "anonymous": 0,
            "reporter": "crep1x"
        }
    ],
    "1888125": [
        {
            "ioc_value": "https://eos.123ful.net/",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-08-26 10:50:47",
            "last_seen_utc": "2026-08-31 08:12:39",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "vidar",
            "anonymous": 0,
            "reporter": "crep1x"
        }
    ],
    "1888109": [
        {
            "ioc_value": "94.154.32.6:7080",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.hype_agent",
            "malware_alias": null,
            "malware_printable": "HypeAgent",
            "first_seen_utc": "2026-08-26 09:47:09",
            "last_seen_utc": "2026-08-31 07:48:06",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,HypeAgent",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1888110": [
        {
            "ioc_value": "94.154.32.6:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.hype_agent",
            "malware_alias": null,
            "malware_printable": "HypeAgent",
            "first_seen_utc": "2026-08-26 09:47:09",
            "last_seen_utc": "2026-08-31 07:48:06",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,HypeAgent",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1888108": [
        {
            "ioc_value": "64.89.160.77:7080",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.hype_agent",
            "malware_alias": null,
            "malware_printable": "HypeAgent",
            "first_seen_utc": "2026-08-26 09:46:43",
            "last_seen_utc": "2026-08-31 07:47:36",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,HypeAgent",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1888107": [
        {
            "ioc_value": "49.235.130.208:60000",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-08-26 09:46:34",
            "last_seen_utc": "2026-08-31 07:47:25",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1888106": [
        {
            "ioc_value": "45.9.12.6:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-26 09:46:30",
            "last_seen_utc": "2026-08-31 07:47:19",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1888105": [
        {
            "ioc_value": "45.85.94.195:36626",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.hype_agent",
            "malware_alias": null,
            "malware_printable": "HypeAgent",
            "first_seen_utc": "2026-08-26 09:46:29",
            "last_seen_utc": "2026-08-31 07:47:18",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,HypeAgent",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1888104": [
        {
            "ioc_value": "38.147.188.28:9001",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pupy",
            "malware_alias": "Patpoopy",
            "malware_printable": "pupy",
            "first_seen_utc": "2026-08-26 09:46:11",
            "last_seen_utc": "2026-08-31 07:46:56",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PupyRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1888103": [
        {
            "ioc_value": "31.77.248.3:7080",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.hype_agent",
            "malware_alias": null,
            "malware_printable": "HypeAgent",
            "first_seen_utc": "2026-08-26 09:46:05",
            "last_seen_utc": "2026-08-31 07:46:50",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,HypeAgent",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1888102": [
        {
            "ioc_value": "203.159.90.177:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-26 09:44:58",
            "last_seen_utc": "2026-08-31 07:45:41",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1888101": [
        {
            "ioc_value": "193.233.220.65:4321",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-08-26 09:44:43",
            "last_seen_utc": "2026-08-31 07:45:14",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1888100": [
        {
            "ioc_value": "192.255.195.141:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.hype_agent",
            "malware_alias": null,
            "malware_printable": "HypeAgent",
            "first_seen_utc": "2026-08-26 09:44:41",
            "last_seen_utc": "2026-08-31 07:45:11",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,HypeAgent",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1888099": [
        {
            "ioc_value": "176.96.138.2:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-26 09:44:16",
            "last_seen_utc": "2026-08-31 07:44:31",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1888098": [
        {
            "ioc_value": "176.124.204.23:45051",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "apk.hook",
            "malware_alias": null,
            "malware_printable": "Hook",
            "first_seen_utc": "2026-08-26 09:44:15",
            "last_seen_utc": "2026-08-31 07:44:30",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Hook",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1888097": [
        {
            "ioc_value": "172.93.187.109:40572",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.sliver",
            "malware_alias": null,
            "malware_printable": "Sliver",
            "first_seen_utc": "2026-08-26 09:44:12",
            "last_seen_utc": "2026-08-31 07:44:27",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Sliver",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1888096": [
        {
            "ioc_value": "172.245.209.209:7080",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.hype_agent",
            "malware_alias": null,
            "malware_printable": "HypeAgent",
            "first_seen_utc": "2026-08-26 09:44:09",
            "last_seen_utc": "2026-08-31 07:44:24",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,HypeAgent",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1888095": [
        {
            "ioc_value": "171.113.116.219:8001",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-08-26 09:44:07",
            "last_seen_utc": "2026-08-31 07:44:19",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1888094": [
        {
            "ioc_value": "144.172.107.81:8444",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-08-26 09:43:40",
            "last_seen_utc": "2026-08-31 07:43:49",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1888093": [
        {
            "ioc_value": "108.186.112.147:7080",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.hype_agent",
            "malware_alias": null,
            "malware_printable": "HypeAgent",
            "first_seen_utc": "2026-08-26 09:43:20",
            "last_seen_utc": "2026-08-31 07:43:25",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,HypeAgent",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1888092": [
        {
            "ioc_value": "107.173.47.158:7707",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-08-26 09:43:18",
            "last_seen_utc": "2026-08-31 07:43:23",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1888091": [
        {
            "ioc_value": "104.243.248.63:400",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-08-26 09:43:14",
            "last_seen_utc": "2026-08-31 07:43:16",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1888090": [
        {
            "ioc_value": "104.105.15.96:8443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.evilginx",
            "malware_alias": null,
            "malware_printable": "Evilginx",
            "first_seen_utc": "2026-08-26 09:43:10",
            "last_seen_utc": "2026-08-31 07:43:12",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Evilginx,EvilGoPhish",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1888089": [
        {
            "ioc_value": "101.99.92.134:4788",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-08-26 09:43:04",
            "last_seen_utc": "2026-08-31 07:43:04",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1888081": [
        {
            "ioc_value": "128.90.136.110:4444",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-08-26 09:23:04",
            "last_seen_utc": "2026-08-31 07:43:38",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "",
            "tags": "AsyncRAT",
            "anonymous": 0,
            "reporter": "whoamix302"
        }
    ],
    "1888082": [
        {
            "ioc_value": "199.245.176.147:6606",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-08-26 09:23:04",
            "last_seen_utc": "2026-08-31 07:45:32",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "",
            "tags": "AsyncRAT",
            "anonymous": 0,
            "reporter": "whoamix302"
        }
    ],
    "1888071": [
        {
            "ioc_value": "68.221.168.156:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.havoc",
            "malware_alias": "Havokiz",
            "malware_printable": "Havoc",
            "first_seen_utc": "2026-08-26 09:05:06",
            "last_seen_utc": "2026-08-31 07:47:39",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "havoc",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1888053": [
        {
            "ioc_value": "207.180.29.217:2404",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-08-26 08:00:43",
            "last_seen_utc": "2026-08-31 04:01:43",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://bazaar.abuse.ch/sample/0e27227f011931ac1eb53596299df5a7b6223f155c80093db19471e9b4abec6f/",
            "tags": "remcos",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1888054": [
        {
            "ioc_value": "207.180.29.85:2404",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-08-26 08:00:43",
            "last_seen_utc": "2026-08-31 04:25:35",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://bazaar.abuse.ch/sample/6b5ded751fcf17c56d5f8f9701397cc1e1f675437cd22dcd83f21c8f7a2ff107/",
            "tags": "remcos",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1887900": [
        {
            "ioc_value": "13.231.27.0:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.brute_ratel_c4",
            "malware_alias": "BOLDBADGER,BruteRatel",
            "malware_printable": "Brute Ratel C4",
            "first_seen_utc": "2026-08-26 05:46:26",
            "last_seen_utc": "2026-08-31 07:43:39",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": null,
            "tags": "16509,brute ratel,c2,censys",
            "anonymous": 0,
            "reporter": "sojubear"
        }
    ],
    "1887271": [
        {
            "ioc_value": "46.101.146.87:8080",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.aisuru",
            "malware_alias": null,
            "malware_printable": "Aisuru",
            "first_seen_utc": "2026-08-26 05:46:19",
            "last_seen_utc": "2026-08-30 12:22:11",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "Aisuru,c2",
            "anonymous": 0,
            "reporter": "Bitsight"
        }
    ],
    "1887882": [
        {
            "ioc_value": "https://77.42.69.149",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-08-26 05:46:18",
            "last_seen_utc": "2026-08-31 08:14:18",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "a6d2471547d36419d2976bfb5f58f7b6,c2,loader,stealer,Vidar",
            "anonymous": 0,
            "reporter": "Bitsight"
        }
    ],
    "1887947": [
        {
            "ioc_value": "167.99.194.254:8443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.aisuru",
            "malware_alias": null,
            "malware_printable": "Aisuru",
            "first_seen_utc": "2026-08-26 05:46:17",
            "last_seen_utc": "2026-08-30 09:38:02",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "Aisuru,c2",
            "anonymous": 0,
            "reporter": "Bitsight"
        }
    ],
    "1887955": [
        {
            "ioc_value": "bratusferramentas.grupomoltz.com.br",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-08-26 05:05:30",
            "last_seen_utc": "2026-08-31 01:56:57",
            "confidence_level": 90,
            "is_compromised": true,
            "reference": null,
            "tags": "ClickFix,compromised",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1887930": [
        {
            "ioc_value": "uza.123ful.net",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-08-26 03:05:47",
            "last_seen_utc": "2026-08-30 18:46:33",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "vidar",
            "anonymous": 0,
            "reporter": "crep1x"
        }
    ],
    "1887931": [
        {
            "ioc_value": "https://uza.123ful.net/",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-08-26 03:05:47",
            "last_seen_utc": "2026-08-31 08:15:22",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "vidar",
            "anonymous": 0,
            "reporter": "crep1x"
        }
    ],
    "1887929": [
        {
            "ioc_value": "176.65.144.177:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-08-26 03:05:07",
            "last_seen_utc": "2026-08-31 07:44:31",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "mythic",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1887901": [
        {
            "ioc_value": "en-us-glucotrustt-bites.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-08-26 01:05:37",
            "last_seen_utc": "2026-08-31 03:02:38",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake",
            "anonymous": 0,
            "reporter": "threatcat_ch"
        }
    ],
    "1887862": [
        {
            "ioc_value": "124.198.132.77:1458",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.dcrat",
            "malware_alias": "DarkCrystal RAT",
            "malware_printable": "DCRat",
            "first_seen_utc": "2026-08-25 22:16:21",
            "last_seen_utc": "2026-08-31 07:43:36",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "",
            "tags": "DarkCrystal RAT,DCRat",
            "anonymous": 0,
            "reporter": "whoamix302"
        }
    ],
    "1887854": [
        {
            "ioc_value": "207.56.26.11:2222",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-25 22:13:16",
            "last_seen_utc": "2026-08-31 07:45:45",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "",
            "tags": "PureHVNC,PureRAT,ResolverRAT",
            "anonymous": 0,
            "reporter": "whoamix302"
        }
    ],
    "1887855": [
        {
            "ioc_value": "207.56.26.2:2222",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-25 22:13:16",
            "last_seen_utc": "2026-08-31 07:45:45",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "",
            "tags": "PureHVNC,PureRAT,ResolverRAT",
            "anonymous": 0,
            "reporter": "whoamix302"
        }
    ],
    "1887850": [
        {
            "ioc_value": "119.45.225.53:8889",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-08-25 21:47:10",
            "last_seen_utc": "2026-08-31 07:48:30",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1887849": [
        {
            "ioc_value": "ck.erloro.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-08-25 21:46:58",
            "last_seen_utc": "2026-08-31 07:48:15",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1887630": [
        {
            "ioc_value": "jij.123ful.net",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-08-25 20:05:47",
            "last_seen_utc": "2026-08-30 18:46:33",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "vidar",
            "anonymous": 0,
            "reporter": "crep1x"
        }
    ],
    "1887631": [
        {
            "ioc_value": "https://jij.123ful.net/",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-08-25 20:05:47",
            "last_seen_utc": "2026-08-31 08:10:33",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "vidar",
            "anonymous": 0,
            "reporter": "crep1x"
        }
    ],
    "1887625": [
        {
            "ioc_value": "66.179.29.5:5000",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-25 19:47:17",
            "last_seen_utc": "2026-08-31 07:47:38",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1887626": [
        {
            "ioc_value": "66.235.175.82:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.hype_agent",
            "malware_alias": null,
            "malware_printable": "HypeAgent",
            "first_seen_utc": "2026-08-25 19:47:17",
            "last_seen_utc": "2026-08-31 07:47:38",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,HypeAgent",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1887624": [
        {
            "ioc_value": "66.179.29.5:2000",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-25 19:47:16",
            "last_seen_utc": "2026-08-31 07:47:38",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1887622": [
        {
            "ioc_value": "64.89.160.140:7040",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.hype_agent",
            "malware_alias": null,
            "malware_printable": "HypeAgent",
            "first_seen_utc": "2026-08-25 19:47:14",
            "last_seen_utc": "2026-08-31 07:47:35",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,HypeAgent",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1887623": [
        {
            "ioc_value": "64.89.160.140:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.hype_agent",
            "malware_alias": null,
            "malware_printable": "HypeAgent",
            "first_seen_utc": "2026-08-25 19:47:14",
            "last_seen_utc": "2026-08-31 07:47:36",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,HypeAgent",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1887621": [
        {
            "ioc_value": "45.61.178.41:3333",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.evilginx",
            "malware_alias": null,
            "malware_printable": "Evilginx",
            "first_seen_utc": "2026-08-25 19:46:57",
            "last_seen_utc": "2026-08-31 07:47:16",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Evilginx,EvilGoPhish",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1887620": [
        {
            "ioc_value": "45.145.41.185:6767",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-25 19:46:50",
            "last_seen_utc": "2026-08-31 07:47:09",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1887619": [
        {
            "ioc_value": "38.54.88.188:65533",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-08-25 19:46:42",
            "last_seen_utc": "2026-08-31 07:46:59",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1887618": [
        {
            "ioc_value": "37.244.224.146:4433",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.danabot",
            "malware_alias": "DanaTools",
            "malware_printable": "DanaBot",
            "first_seen_utc": "2026-08-25 19:46:37",
            "last_seen_utc": "2026-08-31 07:46:54",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DanBot,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1887617": [
        {
            "ioc_value": "23.226.68.34:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-25 19:46:24",
            "last_seen_utc": "2026-08-31 07:46:40",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1887616": [
        {
            "ioc_value": "213.35.118.205:4322",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-08-25 19:45:14",
            "last_seen_utc": "2026-08-31 07:45:51",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1887615": [
        {
            "ioc_value": "185.242.3.249:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.hype_agent",
            "malware_alias": null,
            "malware_printable": "HypeAgent",
            "first_seen_utc": "2026-08-25 19:44:28",
            "last_seen_utc": "2026-08-31 07:44:49",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,HypeAgent",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1887614": [
        {
            "ioc_value": "172.245.209.209:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.hype_agent",
            "malware_alias": null,
            "malware_printable": "HypeAgent",
            "first_seen_utc": "2026-08-25 19:44:08",
            "last_seen_utc": "2026-08-31 07:44:24",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,HypeAgent",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1887613": [
        {
            "ioc_value": "172.237.88.168:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-25 19:44:07",
            "last_seen_utc": "2026-08-31 07:44:22",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1887612": [
        {
            "ioc_value": "172.111.134.94:3001",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-25 19:44:05",
            "last_seen_utc": "2026-08-31 07:44:19",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1887611": [
        {
            "ioc_value": "157.20.182.22:1973",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-08-25 19:43:53",
            "last_seen_utc": "2026-08-31 07:44:05",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1887610": [
        {
            "ioc_value": "147.124.212.136:7080",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.hype_agent",
            "malware_alias": null,
            "malware_printable": "HypeAgent",
            "first_seen_utc": "2026-08-25 19:43:41",
            "last_seen_utc": "2026-08-31 07:43:51",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,HypeAgent",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1887609": [
        {
            "ioc_value": "104.239.66.99:56401",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-25 19:43:12",
            "last_seen_utc": "2026-08-31 07:43:15",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1887608": [
        {
            "ioc_value": "104.143.204.239:52310",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-08-25 19:43:09",
            "last_seen_utc": "2026-08-31 07:43:12",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1887525": [
        {
            "ioc_value": "217.60.195.89:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-25 17:15:08",
            "last_seen_utc": "2026-08-31 07:46:36",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "",
            "tags": "PureHVNC,PureRAT,ResolverRAT",
            "anonymous": 0,
            "reporter": "whoamix302"
        }
    ],
    "1887526": [
        {
            "ioc_value": "193.233.126.164:56003",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-25 17:15:08",
            "last_seen_utc": "2026-08-31 07:45:14",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "",
            "tags": "PureHVNC,PureRAT,ResolverRAT",
            "anonymous": 0,
            "reporter": "whoamix302"
        }
    ],
    "1887527": [
        {
            "ioc_value": "192.229.115.243:56003",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-25 17:15:08",
            "last_seen_utc": "2026-08-31 07:45:09",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "",
            "tags": "PureHVNC,PureRAT,ResolverRAT",
            "anonymous": 0,
            "reporter": "whoamix302"
        }
    ],
    "1887528": [
        {
            "ioc_value": "192.229.115.243:56004",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-25 17:15:08",
            "last_seen_utc": "2026-08-31 07:45:09",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "",
            "tags": "PureHVNC,PureRAT,ResolverRAT",
            "anonymous": 0,
            "reporter": "whoamix302"
        }
    ],
    "1887523": [
        {
            "ioc_value": "217.60.195.25:56003",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-25 17:15:07",
            "last_seen_utc": "2026-08-31 07:46:36",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "",
            "tags": "PureHVNC,PureRAT,ResolverRAT",
            "anonymous": 0,
            "reporter": "whoamix302"
        }
    ],
    "1887521": [
        {
            "ioc_value": "77.110.124.109:1882",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.dcrat",
            "malware_alias": "DarkCrystal RAT",
            "malware_printable": "DCRat",
            "first_seen_utc": "2026-08-25 17:13:45",
            "last_seen_utc": "2026-08-31 07:47:41",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "",
            "tags": "DarkCrystal RAT,DCRat",
            "anonymous": 0,
            "reporter": "whoamix302"
        }
    ],
    "1887522": [
        {
            "ioc_value": "46.246.14.6:8848",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.dcrat",
            "malware_alias": "DarkCrystal RAT",
            "malware_printable": "DCRat",
            "first_seen_utc": "2026-08-25 17:13:45",
            "last_seen_utc": "2026-08-31 07:47:22",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "",
            "tags": "DarkCrystal RAT,DCRat",
            "anonymous": 0,
            "reporter": "whoamix302"
        }
    ],
    "1887519": [
        {
            "ioc_value": "107.173.47.158:8808",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-08-25 17:13:00",
            "last_seen_utc": "2026-08-31 07:43:23",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "",
            "tags": "AsyncRAT",
            "anonymous": 0,
            "reporter": "whoamix302"
        }
    ],
    "1887520": [
        {
            "ioc_value": "107.173.47.158:6606",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-08-25 17:13:00",
            "last_seen_utc": "2026-08-31 07:43:23",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "",
            "tags": "AsyncRAT",
            "anonymous": 0,
            "reporter": "whoamix302"
        }
    ],
    "1887245": [
        {
            "ioc_value": "x0x.123ful.net",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-08-25 15:50:47",
            "last_seen_utc": "2026-08-30 18:46:33",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "vidar",
            "anonymous": 0,
            "reporter": "crep1x"
        }
    ],
    "1887207": [
        {
            "ioc_value": "45.94.31.187:55012",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-25 15:00:45",
            "last_seen_utc": "2026-08-31 07:47:20",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "",
            "tags": "PureHVNC,PureRAT,ResolverRAT",
            "anonymous": 0,
            "reporter": "whoamix302"
        }
    ],
    "1887208": [
        {
            "ioc_value": "192.229.115.254:56003",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-25 15:00:43",
            "last_seen_utc": "2026-08-31 07:45:10",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "",
            "tags": "PureHVNC,PureRAT,ResolverRAT",
            "anonymous": 0,
            "reporter": "whoamix302"
        }
    ],
    "1887209": [
        {
            "ioc_value": "192.229.115.254:56004",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-25 15:00:42",
            "last_seen_utc": "2026-08-31 07:45:10",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "",
            "tags": "PureHVNC,PureRAT,ResolverRAT",
            "anonymous": 0,
            "reporter": "whoamix302"
        }
    ],
    "1887210": [
        {
            "ioc_value": "192.229.115.246:56004",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-25 15:00:42",
            "last_seen_utc": "2026-08-31 07:45:10",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "",
            "tags": "PureHVNC,PureRAT,ResolverRAT",
            "anonymous": 0,
            "reporter": "whoamix302"
        }
    ],
    "1887211": [
        {
            "ioc_value": "192.229.115.246:56003",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-25 15:00:41",
            "last_seen_utc": "2026-08-31 07:45:09",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "",
            "tags": "PureHVNC,PureRAT,ResolverRAT",
            "anonymous": 0,
            "reporter": "whoamix302"
        }
    ],
    "1887212": [
        {
            "ioc_value": "178.16.55.133:56003",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-25 15:00:41",
            "last_seen_utc": "2026-08-31 07:44:35",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "",
            "tags": "PureHVNC,PureRAT,ResolverRAT",
            "anonymous": 0,
            "reporter": "whoamix302"
        }
    ],
    "1887132": [
        {
            "ioc_value": "167.71.217.41:8839",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remus",
            "malware_alias": null,
            "malware_printable": "Remus",
            "first_seen_utc": "2026-08-25 14:18:09",
            "last_seen_utc": "2026-08-31 07:10:05",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "c2,d7d7f50ed686001c727dbd987b7fc7e7,remus",
            "anonymous": 0,
            "reporter": "Bitsight"
        }
    ],
    "1887000": [
        {
            "ioc_value": "2.27.202.130:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-08-25 13:05:06",
            "last_seen_utc": "2026-08-31 07:45:33",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "mythic",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1886835": [
        {
            "ioc_value": "http://downloadfreemanager.com/",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.stealc",
            "malware_alias": null,
            "malware_printable": "Stealc",
            "first_seen_utc": "2026-08-25 12:20:23",
            "last_seen_utc": "2026-08-31 08:09:33",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "2,c2,loader,StealC,stealer",
            "anonymous": 0,
            "reporter": "Bitsight"
        }
    ],
    "1886770": [
        {
            "ioc_value": "hh3.123ful.net",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-08-25 11:25:47",
            "last_seen_utc": "2026-08-30 18:46:33",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "vidar",
            "anonymous": 0,
            "reporter": "crep1x"
        }
    ],
    "1886768": [
        {
            "ioc_value": "104.143.204.239:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-08-25 11:05:07",
            "last_seen_utc": "2026-08-31 07:43:13",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "mythic",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1886754": [
        {
            "ioc_value": "175.43.223.195:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-08-25 10:05:16",
            "last_seen_utc": "2026-08-31 07:44:29",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "mythic",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1886746": [
        {
            "ioc_value": "80.76.49.47:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.hype_agent",
            "malware_alias": null,
            "malware_printable": "HypeAgent",
            "first_seen_utc": "2026-08-25 09:46:47",
            "last_seen_utc": "2026-08-31 07:47:45",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,HypeAgent",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1886745": [
        {
            "ioc_value": "66.235.175.82:7080",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.hype_agent",
            "malware_alias": null,
            "malware_printable": "HypeAgent",
            "first_seen_utc": "2026-08-25 09:46:42",
            "last_seen_utc": "2026-08-31 07:47:38",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,HypeAgent",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1886744": [
        {
            "ioc_value": "31.77.248.3:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.hype_agent",
            "malware_alias": null,
            "malware_printable": "HypeAgent",
            "first_seen_utc": "2026-08-25 09:46:05",
            "last_seen_utc": "2026-08-31 07:46:51",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,HypeAgent",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1886743": [
        {
            "ioc_value": "195.177.94.155:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.hype_agent",
            "malware_alias": null,
            "malware_printable": "HypeAgent",
            "first_seen_utc": "2026-08-25 09:44:41",
            "last_seen_utc": "2026-08-31 07:45:24",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,HypeAgent",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1886742": [
        {
            "ioc_value": "155.117.40.213:7721",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-08-25 09:43:47",
            "last_seen_utc": "2026-08-31 07:44:00",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1886741": [
        {
            "ioc_value": "151.241.154.55:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.hype_agent",
            "malware_alias": null,
            "malware_printable": "HypeAgent",
            "first_seen_utc": "2026-08-25 09:43:42",
            "last_seen_utc": "2026-08-31 07:43:54",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,HypeAgent",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1886720": [
        {
            "ioc_value": "http://31.76.30.6/",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.stealc",
            "malware_alias": null,
            "malware_printable": "Stealc",
            "first_seen_utc": "2026-08-25 09:41:59",
            "last_seen_utc": "2026-08-31 07:30:40",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "c2,loader,StealC,stealer,tst100",
            "anonymous": 0,
            "reporter": "Bitsight"
        }
    ],
    "1886731": [
        {
            "ioc_value": "69.167.11.198:7777",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.dcrat",
            "malware_alias": "DarkCrystal RAT",
            "malware_printable": "DCRat",
            "first_seen_utc": "2026-08-25 09:41:58",
            "last_seen_utc": "2026-08-31 07:47:40",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "",
            "tags": "DarkCrystal RAT,DCRat",
            "anonymous": 0,
            "reporter": "whoamix302"
        }
    ],
    "1886718": [
        {
            "ioc_value": "121.4.38.18:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-08-25 08:52:09",
            "last_seen_utc": "2026-08-31 07:48:31",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-1234567890",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1886686": [
        {
            "ioc_value": "ggk.sm188dnsxx.top",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-08-25 07:17:25",
            "last_seen_utc": "2026-08-30 18:46:34",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "Vidar",
            "anonymous": 0,
            "reporter": "crep1x"
        }
    ],
    "1886688": [
        {
            "ioc_value": "hbd.sm188dnsxx.top",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-08-25 07:17:25",
            "last_seen_utc": "2026-08-30 18:46:34",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "Vidar",
            "anonymous": 0,
            "reporter": "crep1x"
        }
    ],
    "1886682": [
        {
            "ioc_value": "https://178.104.211.128/",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-08-25 07:17:07",
            "last_seen_utc": "2026-08-31 08:12:50",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "Vidar",
            "anonymous": 0,
            "reporter": "crep1x"
        }
    ],
    "1886601": [
        {
            "ioc_value": "en-prosta-fense.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-08-25 02:13:07",
            "last_seen_utc": "2026-08-30 10:02:36",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "25August2026,ClearFake,Commandline,MacOS",
            "anonymous": 0,
            "reporter": "Gi7w0rm"
        }
    ],
    "1886524": [
        {
            "ioc_value": "ibi.123ful.net",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-08-24 23:45:47",
            "last_seen_utc": "2026-08-30 18:46:33",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "vidar",
            "anonymous": 0,
            "reporter": "crep1x"
        }
    ],
    "1886525": [
        {
            "ioc_value": "https://ibi.123ful.net/",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-08-24 23:45:47",
            "last_seen_utc": "2026-08-31 08:11:03",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "vidar",
            "anonymous": 0,
            "reporter": "crep1x"
        }
    ],
    "1886411": [
        {
            "ioc_value": "en-hero-up.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-08-24 20:11:37",
            "last_seen_utc": "2026-08-29 15:40:01",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "24August2026,ClearFake,Commandline,DomainShadowing,Windows",
            "anonymous": 0,
            "reporter": "Gi7w0rm"
        }
    ],
    "1886402": [
        {
            "ioc_value": "91.107.211.179:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-08-24 20:05:05",
            "last_seen_utc": "2026-08-31 07:47:56",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "mythic",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1886368": [
        {
            "ioc_value": "https://hit.123ful.net/",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-08-24 18:50:48",
            "last_seen_utc": "2026-08-31 08:14:55",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "vidar",
            "anonymous": 0,
            "reporter": "crep1x"
        }
    ],
    "1886367": [
        {
            "ioc_value": "hit.123ful.net",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-08-24 18:50:47",
            "last_seen_utc": "2026-08-30 18:46:33",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "vidar",
            "anonymous": 0,
            "reporter": "crep1x"
        }
    ],
    "1886350": [
        {
            "ioc_value": "8.152.218.153:9090",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.vshell",
            "malware_alias": null,
            "malware_printable": "VShell",
            "first_seen_utc": "2026-08-24 18:06:05",
            "last_seen_utc": "2026-08-29 10:05:05",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "",
            "tags": "VShell",
            "anonymous": 0,
            "reporter": "whoamix302"
        }
    ],
    "1886345": [
        {
            "ioc_value": "175.27.214.144:4433",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-08-24 17:39:33",
            "last_seen_utc": "2026-08-31 07:48:39",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "",
            "tags": "BEACON,Cobalt Strike,CobaltStrike,cobeacon",
            "anonymous": 0,
            "reporter": "whoamix302"
        }
    ],
    "1886341": [
        {
            "ioc_value": "154.201.82.108:56003",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-24 17:37:46",
            "last_seen_utc": "2026-08-31 07:43:58",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "",
            "tags": "PureHVNC,PureRAT,ResolverRAT",
            "anonymous": 0,
            "reporter": "whoamix302"
        }
    ],
    "1886342": [
        {
            "ioc_value": "154.201.82.105:56003",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-24 17:37:46",
            "last_seen_utc": "2026-08-31 07:43:57",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "",
            "tags": "PureHVNC,PureRAT,ResolverRAT",
            "anonymous": 0,
            "reporter": "whoamix302"
        }
    ],
    "1886304": [
        {
            "ioc_value": "https://ggk.123ful.net/",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-08-24 14:10:48",
            "last_seen_utc": "2026-08-31 08:14:42",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "vidar",
            "anonymous": 0,
            "reporter": "crep1x"
        }
    ],
    "1886303": [
        {
            "ioc_value": "ggk.123ful.net",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-08-24 14:10:47",
            "last_seen_utc": "2026-08-30 18:46:34",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "vidar",
            "anonymous": 0,
            "reporter": "crep1x"
        }
    ],
    "1886118": [
        {
            "ioc_value": "167.99.194.254:8080",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.aisuru",
            "malware_alias": null,
            "malware_printable": "Aisuru",
            "first_seen_utc": "2026-08-24 13:10:47",
            "last_seen_utc": "2026-08-30 05:46:35",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "Aisuru,c2",
            "anonymous": 0,
            "reporter": "Bitsight"
        }
    ],
    "1886132": [
        {
            "ioc_value": "45.131.182.88:8808",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-08-24 13:05:05",
            "last_seen_utc": "2026-08-31 07:47:07",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "asyncrat",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1886106": [
        {
            "ioc_value": "209.200.246.194:24563",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-08-24 11:47:51",
            "last_seen_utc": "2026-08-31 07:48:44",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1886098": [
        {
            "ioc_value": "dor.123ful.net",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-08-24 11:25:47",
            "last_seen_utc": "2026-08-30 18:46:34",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "vidar",
            "anonymous": 0,
            "reporter": "crep1x"
        }
    ],
    "1886046": [
        {
            "ioc_value": "159.89.24.55:8001",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.aisuru",
            "malware_alias": null,
            "malware_printable": "Aisuru",
            "first_seen_utc": "2026-08-24 10:22:43",
            "last_seen_utc": "2026-08-31 08:13:10",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AISURU",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1886045": [
        {
            "ioc_value": "46.101.146.87:8001",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.aisuru",
            "malware_alias": null,
            "malware_printable": "Aisuru",
            "first_seen_utc": "2026-08-24 10:22:42",
            "last_seen_utc": "2026-08-31 08:13:10",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AISURU",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1886044": [
        {
            "ioc_value": "104.248.247.126:8001",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.aisuru",
            "malware_alias": null,
            "malware_printable": "Aisuru",
            "first_seen_utc": "2026-08-24 10:22:41",
            "last_seen_utc": "2026-08-31 08:13:09",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AISURU",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1886043": [
        {
            "ioc_value": "46.101.179.59:8001",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.aisuru",
            "malware_alias": null,
            "malware_printable": "Aisuru",
            "first_seen_utc": "2026-08-24 10:22:40",
            "last_seen_utc": "2026-08-31 08:13:09",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AISURU",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1886042": [
        {
            "ioc_value": "159.65.50.202:8001",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.aisuru",
            "malware_alias": null,
            "malware_printable": "Aisuru",
            "first_seen_utc": "2026-08-24 10:22:39",
            "last_seen_utc": "2026-08-31 08:13:08",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AISURU",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1886041": [
        {
            "ioc_value": "167.99.194.254:8001",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.aisuru",
            "malware_alias": null,
            "malware_printable": "Aisuru",
            "first_seen_utc": "2026-08-24 10:22:38",
            "last_seen_utc": "2026-08-31 08:13:08",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AISURU",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1886040": [
        {
            "ioc_value": "165.22.122.89:8001",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.aisuru",
            "malware_alias": null,
            "malware_printable": "Aisuru",
            "first_seen_utc": "2026-08-24 10:22:37",
            "last_seen_utc": "2026-08-31 08:13:07",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AISURU",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1886038": [
        {
            "ioc_value": "104.248.41.207:8001",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.aisuru",
            "malware_alias": null,
            "malware_printable": "Aisuru",
            "first_seen_utc": "2026-08-24 10:22:36",
            "last_seen_utc": "2026-08-31 08:13:06",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AISURU",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1886039": [
        {
            "ioc_value": "209.97.138.100:8001",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.aisuru",
            "malware_alias": null,
            "malware_printable": "Aisuru",
            "first_seen_utc": "2026-08-24 10:22:36",
            "last_seen_utc": "2026-08-31 08:13:07",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AISURU",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1886037": [
        {
            "ioc_value": "139.59.154.153:8001",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.aisuru",
            "malware_alias": null,
            "malware_printable": "Aisuru",
            "first_seen_utc": "2026-08-24 10:22:35",
            "last_seen_utc": "2026-08-31 08:13:06",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AISURU",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1886022": [
        {
            "ioc_value": "151.242.63.248:7080",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.hype_agent",
            "malware_alias": null,
            "malware_printable": "HypeAgent",
            "first_seen_utc": "2026-08-24 09:43:42",
            "last_seen_utc": "2026-08-31 07:43:55",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,HypeAgent",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1885836": [
        {
            "ioc_value": "585697.us20.myftpupload.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.iclickfix",
            "malware_alias": null,
            "malware_printable": "IClickFix",
            "first_seen_utc": "2026-08-24 07:51:09",
            "last_seen_utc": "2026-08-31 01:06:53",
            "confidence_level": 50,
            "is_compromised": true,
            "reference": "",
            "tags": "ClearFake,ClickFix",
            "anonymous": 0,
            "reporter": "skocherhan"
        }
    ],
    "1885837": [
        {
            "ioc_value": "dueelletappezzeria.it",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.iclickfix",
            "malware_alias": null,
            "malware_printable": "IClickFix",
            "first_seen_utc": "2026-08-24 07:51:09",
            "last_seen_utc": "2026-08-31 00:56:52",
            "confidence_level": 50,
            "is_compromised": true,
            "reference": "",
            "tags": "ClearFake,ClickFix",
            "anonymous": 0,
            "reporter": "skocherhan"
        }
    ],
    "1885578": [
        {
            "ioc_value": "43.134.49.218:9035",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.aisuru",
            "malware_alias": null,
            "malware_printable": "Aisuru",
            "first_seen_utc": "2026-08-24 07:46:22",
            "last_seen_utc": "2026-08-29 13:37:26",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "Aisuru,c2",
            "anonymous": 0,
            "reporter": "Bitsight"
        }
    ],
    "1885930": [
        {
            "ioc_value": "109.123.242.4:8954",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remus",
            "malware_alias": null,
            "malware_printable": "Remus",
            "first_seen_utc": "2026-08-24 07:45:45",
            "last_seen_utc": "2026-08-29 12:40:53",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "c2,dcf2d40b491fed66d221b13e6daea39c,remus",
            "anonymous": 0,
            "reporter": "Bitsight"
        }
    ],
    "1885954": [
        {
            "ioc_value": "wsp.sm188dnsxx.top",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-08-24 07:43:11",
            "last_seen_utc": "2026-08-30 18:46:33",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "Vidar",
            "anonymous": 0,
            "reporter": "crep1x"
        }
    ],
    "1885935": [
        {
            "ioc_value": "wsp.1234e.org",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-08-24 07:40:47",
            "last_seen_utc": "2026-08-30 18:46:33",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "vidar",
            "anonymous": 0,
            "reporter": "crep1x"
        }
    ],
    "1885759": [
        {
            "ioc_value": "krishnamyfriend.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.iclickfix",
            "malware_alias": null,
            "malware_printable": "IClickFix",
            "first_seen_utc": "2026-08-24 00:37:06",
            "last_seen_utc": "2026-08-31 00:26:50",
            "confidence_level": 50,
            "is_compromised": true,
            "reference": "",
            "tags": "ClearFake,ClickFix",
            "anonymous": 0,
            "reporter": "skocherhan"
        }
    ],
    "1885710": [
        {
            "ioc_value": "md-fliesenleger.de",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.iclickfix",
            "malware_alias": null,
            "malware_printable": "IClickFix",
            "first_seen_utc": "2026-08-24 00:37:03",
            "last_seen_utc": "2026-08-31 00:16:49",
            "confidence_level": 50,
            "is_compromised": true,
            "reference": "",
            "tags": "ClearFake,ClickFix",
            "anonymous": 0,
            "reporter": "skocherhan"
        }
    ],
    "1885715": [
        {
            "ioc_value": "charteredglobal.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.iclickfix",
            "malware_alias": null,
            "malware_printable": "IClickFix",
            "first_seen_utc": "2026-08-24 00:37:03",
            "last_seen_utc": "2026-08-31 00:16:49",
            "confidence_level": 50,
            "is_compromised": true,
            "reference": "",
            "tags": "ClearFake,ClickFix",
            "anonymous": 0,
            "reporter": "skocherhan"
        }
    ],
    "1885696": [
        {
            "ioc_value": "sarahstephensescapes.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.iclickfix",
            "malware_alias": null,
            "malware_printable": "IClickFix",
            "first_seen_utc": "2026-08-24 00:37:01",
            "last_seen_utc": "2026-08-31 00:26:50",
            "confidence_level": 50,
            "is_compromised": true,
            "reference": "",
            "tags": "ClearFake,ClickFix",
            "anonymous": 0,
            "reporter": "skocherhan"
        }
    ],
    "1885701": [
        {
            "ioc_value": "cantinastage.wpengine.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.iclickfix",
            "malware_alias": null,
            "malware_printable": "IClickFix",
            "first_seen_utc": "2026-08-24 00:37:01",
            "last_seen_utc": "2026-08-30 09:05:57",
            "confidence_level": 50,
            "is_compromised": true,
            "reference": "",
            "tags": "ClearFake,ClickFix",
            "anonymous": 0,
            "reporter": "skocherhan"
        }
    ],
    "1885685": [
        {
            "ioc_value": "eclipseworldfest.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.iclickfix",
            "malware_alias": null,
            "malware_printable": "IClickFix",
            "first_seen_utc": "2026-08-24 00:37:00",
            "last_seen_utc": "2026-08-31 00:16:48",
            "confidence_level": 50,
            "is_compromised": true,
            "reference": "",
            "tags": "ClearFake,ClickFix",
            "anonymous": 0,
            "reporter": "skocherhan"
        }
    ],
    "1885678": [
        {
            "ioc_value": "209.200.246.194:32126",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-08-23 23:46:54",
            "last_seen_utc": "2026-08-31 07:48:44",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1885677": [
        {
            "ioc_value": "acsdomaindsadas.click",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-08-23 23:46:32",
            "last_seen_utc": "2026-08-31 07:48:13",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1885595": [
        {
            "ioc_value": "203.159.90.155:56002",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-23 19:44:44",
            "last_seen_utc": "2026-08-31 07:45:40",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1885594": [
        {
            "ioc_value": "196.251.121.124:56001",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-23 19:44:37",
            "last_seen_utc": "2026-08-31 07:45:28",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1885593": [
        {
            "ioc_value": "194.9.6.125:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-23 19:44:33",
            "last_seen_utc": "2026-08-31 07:45:22",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1885592": [
        {
            "ioc_value": "154.201.82.106:56003",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-23 19:43:41",
            "last_seen_utc": "2026-08-31 07:43:57",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1885591": [
        {
            "ioc_value": "13.205.33.34:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-08-23 19:43:26",
            "last_seen_utc": "2026-08-31 07:43:39",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1885545": [
        {
            "ioc_value": "nicolapeloso.it",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.iclickfix",
            "malware_alias": null,
            "malware_printable": "IClickFix",
            "first_seen_utc": "2026-08-23 18:38:47",
            "last_seen_utc": "2026-08-30 02:57:28",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": "",
            "tags": "ClickFix,clusterY,etherhiding",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1885540": [
        {
            "ioc_value": "morrisnanning.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.iclickfix",
            "malware_alias": null,
            "malware_printable": "IClickFix",
            "first_seen_utc": "2026-08-23 18:38:46",
            "last_seen_utc": "2026-08-30 03:10:30",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": "",
            "tags": "ClickFix,clusterY,etherhiding",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1885536": [
        {
            "ioc_value": "maximatelecom.net",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.iclickfix",
            "malware_alias": null,
            "malware_printable": "IClickFix",
            "first_seen_utc": "2026-08-23 18:38:45",
            "last_seen_utc": "2026-08-30 03:15:38",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": "",
            "tags": "ClickFix,clusterY,etherhiding",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1885532": [
        {
            "ioc_value": "lamaisonbleue.restaurant",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.iclickfix",
            "malware_alias": null,
            "malware_printable": "IClickFix",
            "first_seen_utc": "2026-08-23 18:38:44",
            "last_seen_utc": "2026-08-30 03:10:00",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": "",
            "tags": "ClickFix,clusterY,etherhiding",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1885533": [
        {
            "ioc_value": "lesclesdelaubrac.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.iclickfix",
            "malware_alias": null,
            "malware_printable": "IClickFix",
            "first_seen_utc": "2026-08-23 18:38:44",
            "last_seen_utc": "2026-08-30 03:09:29",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": "",
            "tags": "ClickFix,clusterY,etherhiding",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1885520": [
        {
            "ioc_value": "figuraynutricion.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.iclickfix",
            "malware_alias": null,
            "malware_printable": "IClickFix",
            "first_seen_utc": "2026-08-23 18:38:40",
            "last_seen_utc": "2026-08-30 03:10:37",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": "",
            "tags": "ClickFix,clusterY,etherhiding",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1885516": [
        {
            "ioc_value": "dlasl.es",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.iclickfix",
            "malware_alias": null,
            "malware_printable": "IClickFix",
            "first_seen_utc": "2026-08-23 18:38:39",
            "last_seen_utc": "2026-08-30 03:08:59",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": "",
            "tags": "ClickFix,clusterY,etherhiding",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1884663": [
        {
            "ioc_value": "https://peermangoz.me/live/",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.latrodectus",
            "malware_alias": "BLACKWIDOW,IceNova,Latrodectus,Lotus",
            "malware_printable": "Latrodectus",
            "first_seen_utc": "2026-08-23 16:11:13",
            "last_seen_utc": "2026-08-31 07:58:14",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "c2,Latrodectus",
            "anonymous": 0,
            "reporter": "Bitsight"
        }
    ],
    "1884669": [
        {
            "ioc_value": "https://aprettopizza.world/live/",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.latrodectus",
            "malware_alias": "BLACKWIDOW,IceNova,Latrodectus,Lotus",
            "malware_printable": "Latrodectus",
            "first_seen_utc": "2026-08-23 16:11:12",
            "last_seen_utc": "2026-08-31 08:08:18",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "c2,Latrodectus",
            "anonymous": 0,
            "reporter": "Bitsight"
        }
    ],
    "1884742": [
        {
            "ioc_value": "http://5.252.177.69/",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.stealc",
            "malware_alias": null,
            "malware_printable": "Stealc",
            "first_seen_utc": "2026-08-23 16:11:07",
            "last_seen_utc": "2026-08-31 07:36:54",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "auto1,c2,loader,StealC,stealer",
            "anonymous": 0,
            "reporter": "Bitsight"
        }
    ],
    "1884746": [
        {
            "ioc_value": "165.22.158.1:7728",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remus",
            "malware_alias": null,
            "malware_printable": "Remus",
            "first_seen_utc": "2026-08-23 16:11:07",
            "last_seen_utc": "2026-08-31 07:59:11",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "6efb1e0ab361cda1dd534e37e543789c,c2,remus",
            "anonymous": 0,
            "reporter": "Bitsight"
        }
    ],
    "1884751": [
        {
            "ioc_value": "http://31.76.87.171/",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.stealc",
            "malware_alias": null,
            "malware_printable": "Stealc",
            "first_seen_utc": "2026-08-23 16:11:07",
            "last_seen_utc": "2026-08-31 08:11:10",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "AMG63,c2,loader,StealC,stealer",
            "anonymous": 0,
            "reporter": "Bitsight"
        }
    ],
    "1884834": [
        {
            "ioc_value": "119.45.225.53:8888",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-08-23 16:11:06",
            "last_seen_utc": "2026-08-31 07:48:30",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": null,
            "tags": "45090,c2,censys,cobalt strike",
            "anonymous": 0,
            "reporter": "sojubear"
        }
    ],
    "1885146": [
        {
            "ioc_value": "31.187.72.99:8654",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remus",
            "malware_alias": null,
            "malware_printable": "Remus",
            "first_seen_utc": "2026-08-23 16:11:00",
            "last_seen_utc": "2026-08-31 07:27:28",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "945c9f3c8cddcb7f33efce50a9a949ad,c2,remus",
            "anonymous": 0,
            "reporter": "Bitsight"
        }
    ],
    "1885174": [
        {
            "ioc_value": "147.182.132.149:2958",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remus",
            "malware_alias": null,
            "malware_printable": "Remus",
            "first_seen_utc": "2026-08-23 16:11:00",
            "last_seen_utc": "2026-08-30 18:17:22",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "c2,d7f27ef1d93b25ea58fb91b39d5a6f49,remus",
            "anonymous": 0,
            "reporter": "Bitsight"
        }
    ],
    "1885381": [
        {
            "ioc_value": "182.255.91.104:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-08-23 13:05:05",
            "last_seen_utc": "2026-08-31 07:48:39",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "cobaltstrike",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1885188": [
        {
            "ioc_value": "130.12.182.39:2600",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-08-23 09:43:34",
            "last_seen_utc": "2026-08-31 07:43:40",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1885180": [
        {
            "ioc_value": "89.144.53.144:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-08-23 09:05:05",
            "last_seen_utc": "2026-08-31 07:47:54",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "mythic",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1885175": [
        {
            "ioc_value": "eng--neurowave.us",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-08-23 08:27:38",
            "last_seen_utc": "2026-08-29 18:03:51",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "23August2026,ClearFake,Commandline,MacOS",
            "anonymous": 0,
            "reporter": "Gi7w0rm"
        }
    ],
    "1885088": [
        {
            "ioc_value": "oraclepacificltd.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.iclickfix",
            "malware_alias": null,
            "malware_printable": "IClickFix",
            "first_seen_utc": "2026-08-23 03:19:29",
            "last_seen_utc": "2026-08-31 03:02:00",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": "",
            "tags": "ClickFix,fake-plugin,hw-fingerprinting",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1885077": [
        {
            "ioc_value": "agenciaarco.com.br",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.iclickfix",
            "malware_alias": null,
            "malware_printable": "IClickFix",
            "first_seen_utc": "2026-08-23 03:19:28",
            "last_seen_utc": "2026-08-31 03:02:30",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": "",
            "tags": "ClickFix,fake-plugin,hw-fingerprinting",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1884824": [
        {
            "ioc_value": "167.71.217.41:7242",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remus",
            "malware_alias": null,
            "malware_printable": "Remus",
            "first_seen_utc": "2026-08-23 00:40:21",
            "last_seen_utc": "2026-08-31 08:13:43",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://bazaar.abuse.ch/sample/0325bda37ee3ae51de29b706986ee9345d9e110b14cdcbde615dd11f959c085a/",
            "tags": "remus",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1884753": [
        {
            "ioc_value": "eng-trump-token.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-08-22 23:00:32",
            "last_seen_utc": "2026-08-31 01:01:56",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "22August2026,ClearFake,Commandline,MacOS",
            "anonymous": 0,
            "reporter": "Gi7w0rm"
        }
    ],
    "1884712": [
        {
            "ioc_value": "35.73.165.146:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.brute_ratel_c4",
            "malware_alias": "BOLDBADGER,BruteRatel",
            "malware_printable": "Brute Ratel C4",
            "first_seen_utc": "2026-08-22 19:46:00",
            "last_seen_utc": "2026-08-31 07:46:53",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "BruteRatel,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1884710": [
        {
            "ioc_value": "195.177.94.193:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.hype_agent",
            "malware_alias": null,
            "malware_printable": "HypeAgent",
            "first_seen_utc": "2026-08-22 19:44:46",
            "last_seen_utc": "2026-08-31 07:45:25",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,HypeAgent",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1884711": [
        {
            "ioc_value": "195.177.94.217:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.hype_agent",
            "malware_alias": null,
            "malware_printable": "HypeAgent",
            "first_seen_utc": "2026-08-22 19:44:46",
            "last_seen_utc": "2026-08-31 07:45:25",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,HypeAgent",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1884305": [
        {
            "ioc_value": "93.152.223.39:28447",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.havoc",
            "malware_alias": "Havokiz",
            "malware_printable": "Havoc",
            "first_seen_utc": "2026-08-22 09:47:02",
            "last_seen_utc": "2026-08-31 07:48:05",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Havoc",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1884304": [
        {
            "ioc_value": "80.76.49.47:7080",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.hype_agent",
            "malware_alias": null,
            "malware_printable": "HypeAgent",
            "first_seen_utc": "2026-08-22 09:46:45",
            "last_seen_utc": "2026-08-31 07:47:45",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,HypeAgent",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1884303": [
        {
            "ioc_value": "45.61.182.3:2030",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.evilginx",
            "malware_alias": null,
            "malware_printable": "Evilginx",
            "first_seen_utc": "2026-08-22 09:46:22",
            "last_seen_utc": "2026-08-31 07:47:17",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Evilginx,EvilGoPhish",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1884302": [
        {
            "ioc_value": "45.131.182.88:7707",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-08-22 09:46:13",
            "last_seen_utc": "2026-08-31 07:47:07",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1884301": [
        {
            "ioc_value": "31.77.138.156:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.hype_agent",
            "malware_alias": null,
            "malware_printable": "HypeAgent",
            "first_seen_utc": "2026-08-22 09:45:59",
            "last_seen_utc": "2026-08-31 07:46:50",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,HypeAgent",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1884300": [
        {
            "ioc_value": "185.42.163.55:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.mirai",
            "malware_alias": "Katana",
            "malware_printable": "Mirai",
            "first_seen_utc": "2026-08-22 09:44:35",
            "last_seen_utc": "2026-08-31 07:44:57",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mirai",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1884299": [
        {
            "ioc_value": "137.184.139.185:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.poshc2",
            "malware_alias": null,
            "malware_printable": "PoshC2",
            "first_seen_utc": "2026-08-22 09:43:35",
            "last_seen_utc": "2026-08-31 07:43:44",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PoshC2",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1884298": [
        {
            "ioc_value": "117.72.192.13:4321",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-08-22 09:43:24",
            "last_seen_utc": "2026-08-31 07:43:32",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1884297": [
        {
            "ioc_value": "104.243.248.63:100",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-08-22 09:43:12",
            "last_seen_utc": "2026-08-31 07:43:15",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1884159": [
        {
            "ioc_value": "165.227.199.109:8539",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remus",
            "malware_alias": null,
            "malware_printable": "Remus",
            "first_seen_utc": "2026-08-22 09:03:33",
            "last_seen_utc": "2026-08-31 08:13:53",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "6efb1e0ab361cda1dd534e37e543789c,c2,remus",
            "anonymous": 0,
            "reporter": "Bitsight"
        }
    ],
    "1884193": [
        {
            "ioc_value": "128.90.105.164:6666",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.dcrat",
            "malware_alias": "DarkCrystal RAT",
            "malware_printable": "DCRat",
            "first_seen_utc": "2026-08-22 09:03:23",
            "last_seen_utc": "2026-08-31 07:43:37",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "",
            "tags": "DarkCrystal RAT,DCRat",
            "anonymous": 0,
            "reporter": "whoamix302"
        }
    ],
    "1884130": [
        {
            "ioc_value": "150.109.93.78:12345",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.aisuru",
            "malware_alias": null,
            "malware_printable": "Aisuru",
            "first_seen_utc": "2026-08-22 07:00:00",
            "last_seen_utc": "2026-08-30 13:17:11",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "Aisuru,c2",
            "anonymous": 0,
            "reporter": "Bitsight"
        }
    ],
    "1884148": [
        {
            "ioc_value": "217.60.195.33:17541",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-08-22 06:30:39",
            "last_seen_utc": "2026-08-31 04:06:21",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://bazaar.abuse.ch/sample/10e00b5609e2579472202fa80d3f7cb27d3d5f6e975c5497107dde55237b4ae0/",
            "tags": "remcos",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1883965": [
        {
            "ioc_value": "82.29.101.38:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.hype_agent",
            "malware_alias": null,
            "malware_printable": "HypeAgent",
            "first_seen_utc": "2026-08-21 19:46:56",
            "last_seen_utc": "2026-08-31 07:47:48",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,HypeAgent",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1883964": [
        {
            "ioc_value": "31.59.41.79:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-08-21 19:46:06",
            "last_seen_utc": "2026-08-31 07:46:49",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1883963": [
        {
            "ioc_value": "31.57.184.154:56003",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-21 19:46:05",
            "last_seen_utc": "2026-08-31 07:46:47",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1883961": [
        {
            "ioc_value": "185.34.147.35:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-08-21 19:44:39",
            "last_seen_utc": "2026-08-31 07:44:57",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1883960": [
        {
            "ioc_value": "185.34.147.34:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-08-21 19:44:38",
            "last_seen_utc": "2026-08-31 07:44:55",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1883959": [
        {
            "ioc_value": "185.34.147.33:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-08-21 19:44:37",
            "last_seen_utc": "2026-08-31 07:44:54",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1883958": [
        {
            "ioc_value": "185.34.147.31:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-08-21 19:44:35",
            "last_seen_utc": "2026-08-31 07:44:52",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1883956": [
        {
            "ioc_value": "104.249.10.86:56001",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-21 19:43:15",
            "last_seen_utc": "2026-08-31 07:43:18",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1883957": [
        {
            "ioc_value": "104.249.10.86:56002",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-21 19:43:15",
            "last_seen_utc": "2026-08-31 07:43:18",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1883945": [
        {
            "ioc_value": "172.93.187.109:4433",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.sliver",
            "malware_alias": null,
            "malware_printable": "Sliver",
            "first_seen_utc": "2026-08-21 19:18:37",
            "last_seen_utc": "2026-08-31 07:44:27",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "",
            "tags": null,
            "anonymous": 0,
            "reporter": "whoamix302"
        }
    ],
    "1883942": [
        {
            "ioc_value": "91.92.240.98:7707",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-08-21 19:18:24",
            "last_seen_utc": "2026-08-31 07:47:59",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "",
            "tags": "AsyncRAT",
            "anonymous": 0,
            "reporter": "whoamix302"
        }
    ],
    "1883934": [
        {
            "ioc_value": "104.239.66.192:56003",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-21 19:13:47",
            "last_seen_utc": "2026-08-31 07:43:14",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "",
            "tags": "PureHVNC,PureRAT,ResolverRAT",
            "anonymous": 0,
            "reporter": "whoamix302"
        }
    ],
    "1883825": [
        {
            "ioc_value": "104.238.57.209:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-08-21 14:05:04",
            "last_seen_utc": "2026-08-31 07:43:14",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "mythic",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1883810": [
        {
            "ioc_value": "ses.1001gacor.org",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-08-21 13:07:09",
            "last_seen_utc": "2026-08-30 18:46:33",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "Vidar",
            "anonymous": 0,
            "reporter": "crep1x"
        }
    ],
    "1883812": [
        {
            "ioc_value": "ljr.1001gacor.org",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-08-21 13:07:09",
            "last_seen_utc": "2026-08-30 18:46:33",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "Vidar",
            "anonymous": 0,
            "reporter": "crep1x"
        }
    ],
    "1883813": [
        {
            "ioc_value": "nhg.1001gacor.org",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-08-21 13:07:09",
            "last_seen_utc": "2026-08-30 18:46:33",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "Vidar",
            "anonymous": 0,
            "reporter": "crep1x"
        }
    ],
    "1883814": [
        {
            "ioc_value": "bob.1001gacor.org",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-08-21 13:07:09",
            "last_seen_utc": "2026-08-30 18:46:34",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "Vidar",
            "anonymous": 0,
            "reporter": "crep1x"
        }
    ],
    "1883817": [
        {
            "ioc_value": "sto.1001gacor.org",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-08-21 13:07:09",
            "last_seen_utc": "2026-08-30 18:46:33",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "Vidar",
            "anonymous": 0,
            "reporter": "crep1x"
        }
    ],
    "1883818": [
        {
            "ioc_value": "rex.1001gacor.org",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-08-21 13:07:09",
            "last_seen_utc": "2026-08-30 18:46:33",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "Vidar",
            "anonymous": 0,
            "reporter": "crep1x"
        }
    ],
    "1883819": [
        {
            "ioc_value": "bib.1001gacor.org",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-08-21 13:07:09",
            "last_seen_utc": "2026-08-30 18:46:34",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "Vidar",
            "anonymous": 0,
            "reporter": "crep1x"
        }
    ],
    "1883799": [
        {
            "ioc_value": "20.74.145.114:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-08-21 13:05:05",
            "last_seen_utc": "2026-08-31 07:45:39",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "mythic",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1883789": [
        {
            "ioc_value": "8.137.92.225:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-08-21 11:48:09",
            "last_seen_utc": "2026-08-31 07:48:56",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1883787": [
        {
            "ioc_value": "68.64.178.130:8081",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-08-21 11:48:07",
            "last_seen_utc": "2026-08-31 07:48:55",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1883788": [
        {
            "ioc_value": "68.64.178.130:9443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-08-21 11:48:07",
            "last_seen_utc": "2026-08-31 07:48:55",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1883786": [
        {
            "ioc_value": "162.251.92.64:800",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-08-21 11:47:47",
            "last_seen_utc": "2026-08-31 07:48:38",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1883785": [
        {
            "ioc_value": "156.225.18.45:33333",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-08-21 11:47:46",
            "last_seen_utc": "2026-08-31 07:48:37",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1883784": [
        {
            "ioc_value": "122.51.12.180:8443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-08-21 11:47:41",
            "last_seen_utc": "2026-08-31 07:48:32",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1883765": [
        {
            "ioc_value": "66.85.27.43:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-08-21 11:05:04",
            "last_seen_utc": "2026-08-31 07:47:39",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "mythic",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1883727": [
        {
            "ioc_value": "94.154.32.73:7080",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.hype_agent",
            "malware_alias": null,
            "malware_printable": "HypeAgent",
            "first_seen_utc": "2026-08-21 09:47:34",
            "last_seen_utc": "2026-08-31 07:48:07",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,HypeAgent",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1883726": [
        {
            "ioc_value": "91.92.40.209:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-21 09:47:29",
            "last_seen_utc": "2026-08-31 07:48:00",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1883724": [
        {
            "ioc_value": "80.190.77.86:7007",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-08-21 09:47:15",
            "last_seen_utc": "2026-08-31 07:47:44",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1883722": [
        {
            "ioc_value": "64.95.13.219:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-21 09:47:09",
            "last_seen_utc": "2026-08-31 07:47:38",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1883723": [
        {
            "ioc_value": "65.1.70.222:56001",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-21 09:47:09",
            "last_seen_utc": "2026-08-31 07:47:38",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1883719": [
        {
            "ioc_value": "198.23.185.98:6666",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-08-21 09:44:59",
            "last_seen_utc": "2026-08-31 07:45:31",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1883720": [
        {
            "ioc_value": "198.23.185.98:7777",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-08-21 09:44:59",
            "last_seen_utc": "2026-08-31 07:45:31",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1883718": [
        {
            "ioc_value": "188.49.86.25:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.havoc",
            "malware_alias": "Havokiz",
            "malware_printable": "Havoc",
            "first_seen_utc": "2026-08-21 09:44:45",
            "last_seen_utc": "2026-08-31 07:45:00",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Havoc",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1883717": [
        {
            "ioc_value": "185.34.147.35:7707",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-08-21 09:44:42",
            "last_seen_utc": "2026-08-31 07:44:57",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1883716": [
        {
            "ioc_value": "185.34.147.34:7707",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-08-21 09:44:41",
            "last_seen_utc": "2026-08-31 07:44:55",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1883715": [
        {
            "ioc_value": "185.34.147.33:7707",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-08-21 09:44:40",
            "last_seen_utc": "2026-08-31 07:44:54",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1883714": [
        {
            "ioc_value": "185.212.129.143:9000",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.evilginx",
            "malware_alias": null,
            "malware_printable": "Evilginx",
            "first_seen_utc": "2026-08-21 09:44:34",
            "last_seen_utc": "2026-08-31 07:44:47",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Evilginx,EvilGoPhish",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1883713": [
        {
            "ioc_value": "172.239.45.42:8443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.havoc",
            "malware_alias": "Havokiz",
            "malware_printable": "Havoc",
            "first_seen_utc": "2026-08-21 09:44:14",
            "last_seen_utc": "2026-08-31 07:44:23",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Havoc",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1883712": [
        {
            "ioc_value": "172.236.157.30:56001",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-21 09:44:13",
            "last_seen_utc": "2026-08-31 07:44:22",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1883711": [
        {
            "ioc_value": "169.58.201.247:5000",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.evilginx",
            "malware_alias": null,
            "malware_printable": "Evilginx",
            "first_seen_utc": "2026-08-21 09:44:10",
            "last_seen_utc": "2026-08-31 07:44:18",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Evilginx,EvilGoPhish",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1883710": [
        {
            "ioc_value": "162.35.170.53:2030",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.evilginx",
            "malware_alias": null,
            "malware_printable": "Evilginx",
            "first_seen_utc": "2026-08-21 09:44:05",
            "last_seen_utc": "2026-08-31 07:44:13",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Evilginx,EvilGoPhish",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1883709": [
        {
            "ioc_value": "162.35.105.100:8443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.evilginx",
            "malware_alias": null,
            "malware_printable": "Evilginx",
            "first_seen_utc": "2026-08-21 09:44:04",
            "last_seen_utc": "2026-08-31 07:44:13",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Evilginx,EvilGoPhish",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1883708": [
        {
            "ioc_value": "128.90.105.217:7209",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.dcrat",
            "malware_alias": "DarkCrystal RAT",
            "malware_printable": "DCRat",
            "first_seen_utc": "2026-08-21 09:43:30",
            "last_seen_utc": "2026-08-31 07:43:37",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DCRat,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1883707": [
        {
            "ioc_value": "125.62.77.141:56001",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-21 09:43:29",
            "last_seen_utc": "2026-08-31 07:43:36",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1883706": [
        {
            "ioc_value": "121.127.253.146:4321",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-08-21 09:43:27",
            "last_seen_utc": "2026-08-31 07:43:34",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1883705": [
        {
            "ioc_value": "109.227.36.61:4433",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.danabot",
            "malware_alias": "DanaTools",
            "malware_printable": "DanaBot",
            "first_seen_utc": "2026-08-21 09:43:21",
            "last_seen_utc": "2026-08-31 07:43:27",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DanBot,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1883673": [
        {
            "ioc_value": "ges.1001gacor.org",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-08-21 08:50:30",
            "last_seen_utc": "2026-08-30 18:46:34",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "Vidar",
            "anonymous": 0,
            "reporter": "crep1x"
        }
    ],
    "1883656": [
        {
            "ioc_value": "172.111.198.212:56011",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-21 08:48:14",
            "last_seen_utc": "2026-08-31 07:44:20",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "",
            "tags": "PureHVNC,PureRAT,ResolverRAT",
            "anonymous": 0,
            "reporter": "whoamix302"
        }
    ],
    "1883540": [
        {
            "ioc_value": "176.98.182.216:34567",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.aisuru",
            "malware_alias": null,
            "malware_printable": "Aisuru",
            "first_seen_utc": "2026-08-21 06:05:10",
            "last_seen_utc": "2026-08-30 07:27:28",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "Aisuru,c2",
            "anonymous": 0,
            "reporter": "Bitsight"
        }
    ],
    "1883530": [
        {
            "ioc_value": "43.140.219.182:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-08-20 23:47:00",
            "last_seen_utc": "2026-08-31 07:48:48",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1883459": [
        {
            "ioc_value": "95.133.229.173:56002",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-20 19:46:45",
            "last_seen_utc": "2026-08-31 07:48:11",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1883460": [
        {
            "ioc_value": "95.164.123.132:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.hype_agent",
            "malware_alias": null,
            "malware_printable": "HypeAgent",
            "first_seen_utc": "2026-08-20 19:46:45",
            "last_seen_utc": "2026-08-31 07:48:12",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,HypeAgent",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1883458": [
        {
            "ioc_value": "91.92.243.36:56001",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-20 19:46:38",
            "last_seen_utc": "2026-08-31 07:47:59",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1883456": [
        {
            "ioc_value": "5.230.201.54:56001",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-20 19:46:12",
            "last_seen_utc": "2026-08-31 07:47:25",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1883457": [
        {
            "ioc_value": "5.230.201.54:56002",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-20 19:46:12",
            "last_seen_utc": "2026-08-31 07:47:25",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1883455": [
        {
            "ioc_value": "46.246.84.10:2703",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-08-20 19:46:10",
            "last_seen_utc": "2026-08-31 07:47:23",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1883454": [
        {
            "ioc_value": "45.141.215.40:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.hype_agent",
            "malware_alias": null,
            "malware_printable": "HypeAgent",
            "first_seen_utc": "2026-08-20 19:45:57",
            "last_seen_utc": "2026-08-31 07:47:08",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,HypeAgent",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1883453": [
        {
            "ioc_value": "31.59.137.166:56003",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-20 19:45:44",
            "last_seen_utc": "2026-08-31 07:46:48",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1883451": [
        {
            "ioc_value": "217.60.195.196:56001",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-20 19:45:31",
            "last_seen_utc": "2026-08-31 07:46:34",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1883452": [
        {
            "ioc_value": "217.60.195.196:56002",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-20 19:45:31",
            "last_seen_utc": "2026-08-31 07:46:35",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1883450": [
        {
            "ioc_value": "217.217.97.125:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.hype_agent",
            "malware_alias": null,
            "malware_printable": "HypeAgent",
            "first_seen_utc": "2026-08-20 19:45:30",
            "last_seen_utc": "2026-08-31 07:46:32",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,HypeAgent",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1883448": [
        {
            "ioc_value": "193.161.193.99:36731",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-08-20 19:44:32",
            "last_seen_utc": "2026-08-31 07:45:13",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1883447": [
        {
            "ioc_value": "172.86.113.226:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-08-20 19:44:04",
            "last_seen_utc": "2026-08-31 07:44:26",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1883446": [
        {
            "ioc_value": "159.203.69.210:4500",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-08-20 19:43:50",
            "last_seen_utc": "2026-08-31 07:44:09",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1883445": [
        {
            "ioc_value": "147.124.221.0:62020",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.hype_agent",
            "malware_alias": null,
            "malware_printable": "HypeAgent",
            "first_seen_utc": "2026-08-20 19:43:37",
            "last_seen_utc": "2026-08-31 07:43:51",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,HypeAgent",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1883413": [
        {
            "ioc_value": "94.26.68.54:4782",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.quasar_rat",
            "malware_alias": "CinaRAT,QuasarRAT,Yggdrasil",
            "malware_printable": "Quasar RAT",
            "first_seen_utc": "2026-08-20 19:29:22",
            "last_seen_utc": "2026-08-30 04:05:05",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "",
            "tags": "CinaRAT,Quasar RAT,QuasarRAT,Yggdrasil",
            "anonymous": 0,
            "reporter": "whoamix302"
        }
    ],
    "1883375": [
        {
            "ioc_value": "45.61.180.161:56001",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-20 19:24:37",
            "last_seen_utc": "2026-08-31 07:47:16",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "",
            "tags": "PureHVNC,PureRAT,ResolverRAT",
            "anonymous": 0,
            "reporter": "whoamix302"
        }
    ],
    "1883376": [
        {
            "ioc_value": "104.249.10.86:56003",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-20 19:24:37",
            "last_seen_utc": "2026-08-31 07:43:18",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "",
            "tags": "PureHVNC,PureRAT,ResolverRAT",
            "anonymous": 0,
            "reporter": "whoamix302"
        }
    ],
    "1883373": [
        {
            "ioc_value": "45.154.98.38:8808",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-08-20 19:23:27",
            "last_seen_utc": "2026-08-31 07:47:10",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "",
            "tags": "AsyncRAT",
            "anonymous": 0,
            "reporter": "whoamix302"
        }
    ],
    "1883374": [
        {
            "ioc_value": "216.250.252.108:6680",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-08-20 19:23:27",
            "last_seen_utc": "2026-08-31 07:46:32",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "",
            "tags": "AsyncRAT",
            "anonymous": 0,
            "reporter": "whoamix302"
        }
    ],
    "1883212": [
        {
            "ioc_value": "95.164.123.132:53105",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.hype_agent",
            "malware_alias": null,
            "malware_printable": "HypeAgent",
            "first_seen_utc": "2026-08-20 16:47:30",
            "last_seen_utc": "2026-08-31 07:48:11",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,HypeAgent",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1883213": [
        {
            "ioc_value": "95.164.123.132:56545",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.hype_agent",
            "malware_alias": null,
            "malware_printable": "HypeAgent",
            "first_seen_utc": "2026-08-20 16:47:30",
            "last_seen_utc": "2026-08-31 07:48:11",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,HypeAgent",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1883214": [
        {
            "ioc_value": "95.164.123.132:7080",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.hype_agent",
            "malware_alias": null,
            "malware_printable": "HypeAgent",
            "first_seen_utc": "2026-08-20 16:47:30",
            "last_seen_utc": "2026-08-31 07:48:11",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,HypeAgent",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1883210": [
        {
            "ioc_value": "91.92.47.94:7080",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.hype_agent",
            "malware_alias": null,
            "malware_printable": "HypeAgent",
            "first_seen_utc": "2026-08-20 16:47:23",
            "last_seen_utc": "2026-08-31 07:48:02",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,HypeAgent",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1883211": [
        {
            "ioc_value": "91.92.47.94:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.hype_agent",
            "malware_alias": null,
            "malware_printable": "HypeAgent",
            "first_seen_utc": "2026-08-20 16:47:23",
            "last_seen_utc": "2026-08-31 07:48:03",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,HypeAgent",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1883208": [
        {
            "ioc_value": "91.124.98.25:7080",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.hype_agent",
            "malware_alias": null,
            "malware_printable": "HypeAgent",
            "first_seen_utc": "2026-08-20 16:47:18",
            "last_seen_utc": "2026-08-31 07:47:56",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,HypeAgent",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1883209": [
        {
            "ioc_value": "91.124.98.25:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.hype_agent",
            "malware_alias": null,
            "malware_printable": "HypeAgent",
            "first_seen_utc": "2026-08-20 16:47:18",
            "last_seen_utc": "2026-08-31 07:47:56",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,HypeAgent",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1883207": [
        {
            "ioc_value": "45.141.215.40:7080",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.hype_agent",
            "malware_alias": null,
            "malware_printable": "HypeAgent",
            "first_seen_utc": "2026-08-20 16:46:35",
            "last_seen_utc": "2026-08-31 07:47:08",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,HypeAgent",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1883206": [
        {
            "ioc_value": "217.217.97.125:7080",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.hype_agent",
            "malware_alias": null,
            "malware_printable": "HypeAgent",
            "first_seen_utc": "2026-08-20 16:46:04",
            "last_seen_utc": "2026-08-31 07:46:32",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,HypeAgent",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1883204": [
        {
            "ioc_value": "213.152.186.188:32605",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.hype_agent",
            "malware_alias": null,
            "malware_printable": "HypeAgent",
            "first_seen_utc": "2026-08-20 16:45:27",
            "last_seen_utc": "2026-08-31 07:45:50",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,HypeAgent",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1883205": [
        {
            "ioc_value": "213.152.186.188:32635",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.hype_agent",
            "malware_alias": null,
            "malware_printable": "HypeAgent",
            "first_seen_utc": "2026-08-20 16:45:27",
            "last_seen_utc": "2026-08-31 07:45:50",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,HypeAgent",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1883203": [
        {
            "ioc_value": "192.109.139.69:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.hype_agent",
            "malware_alias": null,
            "malware_printable": "HypeAgent",
            "first_seen_utc": "2026-08-20 16:44:49",
            "last_seen_utc": "2026-08-31 07:45:03",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,HypeAgent",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1883202": [
        {
            "ioc_value": "192.109.139.69:7080",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.hype_agent",
            "malware_alias": null,
            "malware_printable": "HypeAgent",
            "first_seen_utc": "2026-08-20 16:44:48",
            "last_seen_utc": "2026-08-31 07:45:03",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,HypeAgent",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1883201": [
        {
            "ioc_value": "104.168.70.163:7080",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.hype_agent",
            "malware_alias": null,
            "malware_printable": "HypeAgent",
            "first_seen_utc": "2026-08-20 16:43:12",
            "last_seen_utc": "2026-08-31 07:43:13",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,HypeAgent",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1883189": [
        {
            "ioc_value": "178.156.181.26:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-08-20 16:05:05",
            "last_seen_utc": "2026-08-31 07:44:33",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "mythic",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1883153": [
        {
            "ioc_value": "143.246.216.114:38990",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.pink",
            "malware_alias": null,
            "malware_printable": "Pink",
            "first_seen_utc": "2026-08-20 14:10:36",
            "last_seen_utc": "2026-08-31 08:10:31",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "Pink",
            "anonymous": 0,
            "reporter": "Bitsight"
        }
    ],
    "1883148": [
        {
            "ioc_value": "80.190.77.86:2222",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-08-20 14:05:06",
            "last_seen_utc": "2026-08-31 07:47:44",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "asyncrat",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1883118": [
        {
            "ioc_value": "http://178.16.52.8/",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.stealc",
            "malware_alias": null,
            "malware_printable": "Stealc",
            "first_seen_utc": "2026-08-20 13:14:57",
            "last_seen_utc": "2026-08-31 07:32:02",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "c2,loader,StealC,stealer,test_2",
            "anonymous": 0,
            "reporter": "Bitsight"
        }
    ],
    "1883107": [
        {
            "ioc_value": "80.190.77.86:2000",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-08-20 12:05:05",
            "last_seen_utc": "2026-08-31 07:47:43",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "asyncrat",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1883105": [
        {
            "ioc_value": "185.92.190.174:8896",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-08-20 11:47:46",
            "last_seen_utc": "2026-08-31 07:48:41",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1883090": [
        {
            "ioc_value": "82.197.65.206:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-08-20 09:46:42",
            "last_seen_utc": "2026-08-31 07:47:48",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1883088": [
        {
            "ioc_value": "80.190.77.86:1000",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-08-20 09:46:39",
            "last_seen_utc": "2026-08-31 07:47:43",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1883089": [
        {
            "ioc_value": "80.190.77.86:8008",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-08-20 09:46:39",
            "last_seen_utc": "2026-08-31 07:47:44",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1883087": [
        {
            "ioc_value": "4.193.136.143:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.havoc",
            "malware_alias": "Havokiz",
            "malware_printable": "Havoc",
            "first_seen_utc": "2026-08-20 09:46:04",
            "last_seen_utc": "2026-08-31 07:47:00",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Havoc",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1883086": [
        {
            "ioc_value": "109.227.40.60:4433",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.danabot",
            "malware_alias": "DanaTools",
            "malware_printable": "DanaBot",
            "first_seen_utc": "2026-08-20 09:43:19",
            "last_seen_utc": "2026-08-31 07:43:27",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DanBot,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1883085": [
        {
            "ioc_value": "104.243.248.63:84",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-08-20 09:43:12",
            "last_seen_utc": "2026-08-31 07:43:17",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1883069": [
        {
            "ioc_value": "ses.sm188daftar.mom",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-08-20 09:28:44",
            "last_seen_utc": "2026-08-30 18:46:33",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "Vidar",
            "anonymous": 0,
            "reporter": "crep1x"
        }
    ],
    "1883070": [
        {
            "ioc_value": "nhg.sm188daftar.mom",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-08-20 09:28:44",
            "last_seen_utc": "2026-08-30 18:46:33",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "Vidar",
            "anonymous": 0,
            "reporter": "crep1x"
        }
    ],
    "1883071": [
        {
            "ioc_value": "ges.sm188daftar.mom",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-08-20 09:28:44",
            "last_seen_utc": "2026-08-30 18:46:34",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "Vidar",
            "anonymous": 0,
            "reporter": "crep1x"
        }
    ],
    "1883072": [
        {
            "ioc_value": "kra.sm188daftar.mom",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-08-20 09:28:44",
            "last_seen_utc": "2026-08-30 18:46:33",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "Vidar",
            "anonymous": 0,
            "reporter": "crep1x"
        }
    ],
    "1883073": [
        {
            "ioc_value": "brr.sm188daftar.mom",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-08-20 09:28:44",
            "last_seen_utc": "2026-08-30 18:46:34",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "Vidar",
            "anonymous": 0,
            "reporter": "crep1x"
        }
    ],
    "1883074": [
        {
            "ioc_value": "sto.sm188daftar.mom",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-08-20 09:28:44",
            "last_seen_utc": "2026-08-30 18:46:33",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "Vidar",
            "anonymous": 0,
            "reporter": "crep1x"
        }
    ],
    "1883075": [
        {
            "ioc_value": "rex.sm188daftar.mom",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-08-20 09:28:44",
            "last_seen_utc": "2026-08-30 18:46:33",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "Vidar",
            "anonymous": 0,
            "reporter": "crep1x"
        }
    ],
    "1883076": [
        {
            "ioc_value": "bib.sm188daftar.mom",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-08-20 09:28:44",
            "last_seen_utc": "2026-08-30 18:46:34",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "Vidar",
            "anonymous": 0,
            "reporter": "crep1x"
        }
    ],
    "1883057": [
        {
            "ioc_value": "https://2.29.7.186/",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-08-20 09:28:25",
            "last_seen_utc": "2026-08-31 08:13:07",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "Vidar",
            "anonymous": 0,
            "reporter": "crep1x"
        }
    ],
    "1883050": [
        {
            "ioc_value": "43.134.42.247:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.havoc",
            "malware_alias": "Havokiz",
            "malware_printable": "Havoc",
            "first_seen_utc": "2026-08-20 09:05:06",
            "last_seen_utc": "2026-08-31 07:47:03",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "havoc",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1883026": [
        {
            "ioc_value": "217.60.102.8:2269",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-08-20 08:23:29",
            "last_seen_utc": "2026-08-31 04:00:17",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://bazaar.abuse.ch/sample/c5103eaa70a4a80176440a0e0dc75136a0e7bcfd9a68d7c8440a4d0edea72011/",
            "tags": "RAT,RemcosRAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1883020": [
        {
            "ioc_value": "46.151.182.93:9090",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-08-20 08:06:40",
            "last_seen_utc": "2026-08-31 03:58:27",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://bazaar.abuse.ch/sample/f6117413027a3ddba78e3dcc7e975a626bf0e8f9ffe1dc5dd2387237b40f378f/",
            "tags": "remcos",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1883010": [
        {
            "ioc_value": "4.193.136.143:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.havoc",
            "malware_alias": "Havokiz",
            "malware_printable": "Havoc",
            "first_seen_utc": "2026-08-20 08:05:08",
            "last_seen_utc": "2026-08-31 07:47:00",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "havoc",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1883008": [
        {
            "ioc_value": "103.185.249.199:8081",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-08-20 08:05:06",
            "last_seen_utc": "2026-08-31 07:48:23",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "cobaltstrike",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1882919": [
        {
            "ioc_value": "185.130.45.240:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.havoc",
            "malware_alias": "Havokiz",
            "malware_printable": "Havoc",
            "first_seen_utc": "2026-08-20 05:44:41",
            "last_seen_utc": "2026-08-31 07:44:41",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": "https://www.shodan.io/host/185.130.45.240#80",
            "tags": "c2,havoc,shodan",
            "anonymous": 0,
            "reporter": "juroots"
        }
    ],
    "1882826": [
        {
            "ioc_value": "176.98.182.217:8080",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.aisuru",
            "malware_alias": null,
            "malware_printable": "Aisuru",
            "first_seen_utc": "2026-08-20 05:11:59",
            "last_seen_utc": "2026-08-31 06:12:57",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "Aisuru,c2",
            "anonymous": 0,
            "reporter": "Bitsight"
        }
    ],
    "1882677": [
        {
            "ioc_value": "95.133.166.10:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.havoc",
            "malware_alias": "Havokiz",
            "malware_printable": "Havoc",
            "first_seen_utc": "2026-08-19 19:46:59",
            "last_seen_utc": "2026-08-31 07:48:10",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Havoc",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1882676": [
        {
            "ioc_value": "91.202.233.120:8848",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.dcrat",
            "malware_alias": "DarkCrystal RAT",
            "malware_printable": "DCRat",
            "first_seen_utc": "2026-08-19 19:46:51",
            "last_seen_utc": "2026-08-31 07:47:57",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DCRat,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1882675": [
        {
            "ioc_value": "38.247.165.127:8015",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-08-19 19:46:01",
            "last_seen_utc": "2026-08-31 07:46:58",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1882674": [
        {
            "ioc_value": "34.186.150.169:6932",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-08-19 19:45:55",
            "last_seen_utc": "2026-08-31 07:46:51",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1882673": [
        {
            "ioc_value": "27.124.36.136:56003",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-19 19:45:50",
            "last_seen_utc": "2026-08-31 07:46:43",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1882672": [
        {
            "ioc_value": "209.99.188.193:43222",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-08-19 19:44:57",
            "last_seen_utc": "2026-08-31 07:45:48",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1882671": [
        {
            "ioc_value": "194.56.225.150:56002",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-19 19:44:40",
            "last_seen_utc": "2026-08-31 07:45:17",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1882670": [
        {
            "ioc_value": "189.249.193.210:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-08-19 19:44:33",
            "last_seen_utc": "2026-08-31 07:45:00",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1882669": [
        {
            "ioc_value": "185.34.147.35:2204",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-08-19 19:44:31",
            "last_seen_utc": "2026-08-31 07:44:56",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1882668": [
        {
            "ioc_value": "185.34.147.34:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-08-19 19:44:30",
            "last_seen_utc": "2026-08-31 07:44:55",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1882667": [
        {
            "ioc_value": "185.34.147.33:2204",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-08-19 19:44:29",
            "last_seen_utc": "2026-08-31 07:44:53",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1882665": [
        {
            "ioc_value": "185.34.147.31:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-08-19 19:44:28",
            "last_seen_utc": "2026-08-31 07:44:51",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1882666": [
        {
            "ioc_value": "185.34.147.32:2204",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-08-19 19:44:28",
            "last_seen_utc": "2026-08-31 07:44:52",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1882664": [
        {
            "ioc_value": "185.129.85.77:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-08-19 19:44:20",
            "last_seen_utc": "2026-08-31 07:44:41",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "Covenant,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1882663": [
        {
            "ioc_value": "176.96.138.71:56002",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-19 19:44:12",
            "last_seen_utc": "2026-08-31 07:44:32",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1882662": [
        {
            "ioc_value": "172.111.136.159:3000",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-19 19:44:04",
            "last_seen_utc": "2026-08-31 07:44:20",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1882661": [
        {
            "ioc_value": "164.90.205.13:8080",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-08-19 19:43:59",
            "last_seen_utc": "2026-08-31 07:44:14",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1882660": [
        {
            "ioc_value": "155.2.192.251:56002",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-19 19:43:48",
            "last_seen_utc": "2026-08-31 07:44:01",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1882659": [
        {
            "ioc_value": "128.90.63.100:4444",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-08-19 19:43:27",
            "last_seen_utc": "2026-08-31 07:43:38",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1882658": [
        {
            "ioc_value": "118.107.5.200:56003",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-19 19:43:24",
            "last_seen_utc": "2026-08-31 07:43:34",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1882657": [
        {
            "ioc_value": "109.248.160.184:7070",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.havoc",
            "malware_alias": "Havokiz",
            "malware_printable": "Havoc",
            "first_seen_utc": "2026-08-19 19:43:19",
            "last_seen_utc": "2026-08-31 07:43:28",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Havoc",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1882656": [
        {
            "ioc_value": "107.174.33.36:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-08-19 19:43:16",
            "last_seen_utc": "2026-08-31 07:43:23",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1882655": [
        {
            "ioc_value": "104.243.248.63:301",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-08-19 19:43:12",
            "last_seen_utc": "2026-08-31 07:43:16",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1882654": [
        {
            "ioc_value": "103.43.11.40:4443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-19 19:43:08",
            "last_seen_utc": "2026-08-31 07:43:10",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1882653": [
        {
            "ioc_value": "102.117.164.97:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-08-19 19:43:04",
            "last_seen_utc": "2026-08-31 07:43:04",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1882652": [
        {
            "ioc_value": "1.69.202.103:9003",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-08-19 19:43:02",
            "last_seen_utc": "2026-08-31 07:43:03",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1882376": [
        {
            "ioc_value": "134.209.112.52:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-08-19 15:05:06",
            "last_seen_utc": "2026-08-31 07:43:43",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "mythic",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1882265": [
        {
            "ioc_value": "2.57.241.129:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-08-19 11:48:03",
            "last_seen_utc": "2026-08-31 07:48:43",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1882253": [
        {
            "ioc_value": "185.91.126.107:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-08-19 11:46:03",
            "last_seen_utc": "2026-08-30 18:15:08",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": "",
            "tags": "c2,remcos",
            "anonymous": 0,
            "reporter": "juroots"
        }
    ],
    "1881965": [
        {
            "ioc_value": "185.34.147.35:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-08-19 10:05:07",
            "last_seen_utc": "2026-08-31 07:44:56",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "asyncrat",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1881964": [
        {
            "ioc_value": "185.34.147.33:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-08-19 10:05:06",
            "last_seen_utc": "2026-08-31 07:44:54",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "asyncrat",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1881949": [
        {
            "ioc_value": "94.26.3.52:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-19 09:46:55",
            "last_seen_utc": "2026-08-31 07:48:10",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1881950": [
        {
            "ioc_value": "95.133.229.218:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-19 09:46:55",
            "last_seen_utc": "2026-08-31 07:48:11",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1881948": [
        {
            "ioc_value": "94.20.141.82:8443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.evilginx",
            "malware_alias": null,
            "malware_printable": "Evilginx",
            "first_seen_utc": "2026-08-19 09:46:53",
            "last_seen_utc": "2026-08-31 07:48:08",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Evilginx,EvilGoPhish",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1881947": [
        {
            "ioc_value": "31.77.228.179:4321",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-08-19 09:45:53",
            "last_seen_utc": "2026-08-31 07:46:50",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1881942": [
        {
            "ioc_value": "209.99.186.201:55009",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-19 09:44:57",
            "last_seen_utc": "2026-08-31 07:45:48",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1881929": [
        {
            "ioc_value": "185.212.129.129:9000",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.evilginx",
            "malware_alias": null,
            "malware_printable": "Evilginx",
            "first_seen_utc": "2026-08-19 09:44:24",
            "last_seen_utc": "2026-08-31 07:44:47",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Evilginx,EvilGoPhish",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1881928": [
        {
            "ioc_value": "169.239.128.90:8080",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.chaos",
            "malware_alias": "FakeRyuk,RyukJoke,Yashma",
            "malware_printable": "Chaos",
            "first_seen_utc": "2026-08-19 09:44:02",
            "last_seen_utc": "2026-08-31 07:44:18",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CHAOS,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1881927": [
        {
            "ioc_value": "159.203.69.210:12262",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-08-19 09:43:54",
            "last_seen_utc": "2026-08-31 07:44:08",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1881926": [
        {
            "ioc_value": "118.107.23.86:4321",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-08-19 09:43:22",
            "last_seen_utc": "2026-08-31 07:43:32",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1881852": [
        {
            "ioc_value": "194.56.225.150:56001",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-19 09:29:13",
            "last_seen_utc": "2026-08-31 07:45:17",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "",
            "tags": "PureRAT",
            "anonymous": 0,
            "reporter": "whoamix302"
        }
    ],
    "1881802": [
        {
            "ioc_value": "154.13.7.199:9999",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-19 08:54:11",
            "last_seen_utc": "2026-08-31 07:43:56",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "",
            "tags": "PureHVNC,PureRAT,ResolverRAT",
            "anonymous": 0,
            "reporter": "whoamix302"
        }
    ],
    "1881803": [
        {
            "ioc_value": "209.99.186.201:55006",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-19 08:54:11",
            "last_seen_utc": "2026-08-31 07:45:47",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "",
            "tags": "PureHVNC,PureRAT,ResolverRAT",
            "anonymous": 0,
            "reporter": "whoamix302"
        }
    ],
    "1881801": [
        {
            "ioc_value": "41.100.227.210:3030",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-08-19 08:53:12",
            "last_seen_utc": "2026-08-31 07:47:00",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "",
            "tags": "AsyncRAT",
            "anonymous": 0,
            "reporter": "whoamix302"
        }
    ],
    "1881784": [
        {
            "ioc_value": "121.200.216.84:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-08-19 08:05:06",
            "last_seen_utc": "2026-08-31 07:43:34",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "asyncrat",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1881777": [
        {
            "ioc_value": "188.245.219.133:8137",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remus",
            "malware_alias": null,
            "malware_printable": "Remus",
            "first_seen_utc": "2026-08-19 07:50:12",
            "last_seen_utc": "2026-08-30 23:25:19",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "RemusStealer",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1881764": [
        {
            "ioc_value": "192.169.176.54:449",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.havoc",
            "malware_alias": "Havokiz",
            "malware_printable": "Havoc",
            "first_seen_utc": "2026-08-19 07:11:04",
            "last_seen_utc": "2026-08-31 07:45:06",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": "https://www.shodan.io/host/192.169.176.54#449",
            "tags": "c2,havoc,shodan",
            "anonymous": 0,
            "reporter": "juroots"
        }
    ],
    "1881352": [
        {
            "ioc_value": "23.106.253.199:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.hype_agent",
            "malware_alias": null,
            "malware_printable": "HypeAgent",
            "first_seen_utc": "2026-08-19 06:06:14",
            "last_seen_utc": "2026-08-31 07:46:39",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://infosec.exchange/@RecklessPush38671/117118098460752628",
            "tags": "C2,Censys,HypeAgent",
            "anonymous": 0,
            "reporter": "Overkill1984zzz"
        }
    ],
    "1881353": [
        {
            "ioc_value": "23.106.253.199:7080",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.hype_agent",
            "malware_alias": null,
            "malware_printable": "HypeAgent",
            "first_seen_utc": "2026-08-19 06:06:14",
            "last_seen_utc": "2026-08-31 07:46:39",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://infosec.exchange/@RecklessPush38671/117118098460752628",
            "tags": "C2,Censys,HypeAgent",
            "anonymous": 0,
            "reporter": "Overkill1984zzz"
        }
    ],
    "1881354": [
        {
            "ioc_value": "31.40.204.178:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.hype_agent",
            "malware_alias": null,
            "malware_printable": "HypeAgent",
            "first_seen_utc": "2026-08-19 06:06:14",
            "last_seen_utc": "2026-08-31 07:46:46",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://infosec.exchange/@RecklessPush38671/117118098460752628",
            "tags": "C2,Censys,HypeAgent",
            "anonymous": 0,
            "reporter": "Overkill1984zzz"
        }
    ],
    "1881357": [
        {
            "ioc_value": "31.77.138.156:7080",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.hype_agent",
            "malware_alias": null,
            "malware_printable": "HypeAgent",
            "first_seen_utc": "2026-08-19 06:06:12",
            "last_seen_utc": "2026-08-31 07:46:50",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://infosec.exchange/@RecklessPush38671/117118098460752628",
            "tags": "C2,Censys,HypeAgent",
            "anonymous": 0,
            "reporter": "Overkill1984zzz"
        }
    ],
    "1881358": [
        {
            "ioc_value": "31.77.168.191:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.hype_agent",
            "malware_alias": null,
            "malware_printable": "HypeAgent",
            "first_seen_utc": "2026-08-19 06:06:12",
            "last_seen_utc": "2026-08-31 07:46:50",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://infosec.exchange/@RecklessPush38671/117118098460752628",
            "tags": "C2,Censys,HypeAgent",
            "anonymous": 0,
            "reporter": "Overkill1984zzz"
        }
    ],
    "1881359": [
        {
            "ioc_value": "31.77.168.191:7080",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.hype_agent",
            "malware_alias": null,
            "malware_printable": "HypeAgent",
            "first_seen_utc": "2026-08-19 06:06:11",
            "last_seen_utc": "2026-08-31 07:46:50",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://infosec.exchange/@RecklessPush38671/117118098460752628",
            "tags": "C2,Censys,HypeAgent",
            "anonymous": 0,
            "reporter": "Overkill1984zzz"
        }
    ],
    "1881360": [
        {
            "ioc_value": "31.207.7.126:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.hype_agent",
            "malware_alias": null,
            "malware_printable": "HypeAgent",
            "first_seen_utc": "2026-08-19 06:06:11",
            "last_seen_utc": "2026-08-31 07:46:45",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://infosec.exchange/@RecklessPush38671/117118098460752628",
            "tags": "C2,Censys,HypeAgent",
            "anonymous": 0,
            "reporter": "Overkill1984zzz"
        }
    ],
    "1881361": [
        {
            "ioc_value": "31.207.7.126:7080",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.hype_agent",
            "malware_alias": null,
            "malware_printable": "HypeAgent",
            "first_seen_utc": "2026-08-19 06:06:10",
            "last_seen_utc": "2026-08-31 07:46:45",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://infosec.exchange/@RecklessPush38671/117118098460752628",
            "tags": "C2,Censys,HypeAgent",
            "anonymous": 0,
            "reporter": "Overkill1984zzz"
        }
    ],
    "1881362": [
        {
            "ioc_value": "46.151.182.30:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.hype_agent",
            "malware_alias": null,
            "malware_printable": "HypeAgent",
            "first_seen_utc": "2026-08-19 06:06:10",
            "last_seen_utc": "2026-08-31 07:47:21",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://infosec.exchange/@RecklessPush38671/117118098460752628",
            "tags": "C2,Censys,HypeAgent",
            "anonymous": 0,
            "reporter": "Overkill1984zzz"
        }
    ],
    "1881363": [
        {
            "ioc_value": "46.151.182.30:7080",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.hype_agent",
            "malware_alias": null,
            "malware_printable": "HypeAgent",
            "first_seen_utc": "2026-08-19 06:06:09",
            "last_seen_utc": "2026-08-31 07:47:21",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://infosec.exchange/@RecklessPush38671/117118098460752628",
            "tags": "C2,Censys,HypeAgent",
            "anonymous": 0,
            "reporter": "Overkill1984zzz"
        }
    ],
    "1881364": [
        {
            "ioc_value": "64.224.17.66:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.hype_agent",
            "malware_alias": null,
            "malware_printable": "HypeAgent",
            "first_seen_utc": "2026-08-19 06:06:09",
            "last_seen_utc": "2026-08-31 07:47:35",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://infosec.exchange/@RecklessPush38671/117118098460752628",
            "tags": "C2,Censys,HypeAgent",
            "anonymous": 0,
            "reporter": "Overkill1984zzz"
        }
    ],
    "1881365": [
        {
            "ioc_value": "64.224.17.66:7080",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.hype_agent",
            "malware_alias": null,
            "malware_printable": "HypeAgent",
            "first_seen_utc": "2026-08-19 06:06:09",
            "last_seen_utc": "2026-08-31 07:47:34",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://infosec.exchange/@RecklessPush38671/117118098460752628",
            "tags": "C2,Censys,HypeAgent",
            "anonymous": 0,
            "reporter": "Overkill1984zzz"
        }
    ],
    "1881366": [
        {
            "ioc_value": "78.40.209.239:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.hype_agent",
            "malware_alias": null,
            "malware_printable": "HypeAgent",
            "first_seen_utc": "2026-08-19 06:06:08",
            "last_seen_utc": "2026-08-31 07:47:42",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://infosec.exchange/@RecklessPush38671/117118098460752628",
            "tags": "C2,Censys,HypeAgent",
            "anonymous": 0,
            "reporter": "Overkill1984zzz"
        }
    ],
    "1881367": [
        {
            "ioc_value": "78.40.209.239:7080",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.hype_agent",
            "malware_alias": null,
            "malware_printable": "HypeAgent",
            "first_seen_utc": "2026-08-19 06:06:08",
            "last_seen_utc": "2026-08-31 07:47:42",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://infosec.exchange/@RecklessPush38671/117118098460752628",
            "tags": "C2,Censys,HypeAgent",
            "anonymous": 0,
            "reporter": "Overkill1984zzz"
        }
    ],
    "1881369": [
        {
            "ioc_value": "84.38.129.111:7080",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.hype_agent",
            "malware_alias": null,
            "malware_printable": "HypeAgent",
            "first_seen_utc": "2026-08-19 06:06:07",
            "last_seen_utc": "2026-08-31 07:47:49",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://infosec.exchange/@RecklessPush38671/117118098460752628",
            "tags": "C2,Censys,HypeAgent",
            "anonymous": 0,
            "reporter": "Overkill1984zzz"
        }
    ],
    "1881370": [
        {
            "ioc_value": "89.106.83.159:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.hype_agent",
            "malware_alias": null,
            "malware_printable": "HypeAgent",
            "first_seen_utc": "2026-08-19 06:06:06",
            "last_seen_utc": "2026-08-31 07:47:54",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://infosec.exchange/@RecklessPush38671/117118098460752628",
            "tags": "C2,Censys,HypeAgent",
            "anonymous": 0,
            "reporter": "Overkill1984zzz"
        }
    ],
    "1881371": [
        {
            "ioc_value": "89.106.83.159:7080",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.hype_agent",
            "malware_alias": null,
            "malware_printable": "HypeAgent",
            "first_seen_utc": "2026-08-19 06:06:06",
            "last_seen_utc": "2026-08-31 07:47:53",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://infosec.exchange/@RecklessPush38671/117118098460752628",
            "tags": "C2,Censys,HypeAgent",
            "anonymous": 0,
            "reporter": "Overkill1984zzz"
        }
    ],
    "1881372": [
        {
            "ioc_value": "91.92.47.111:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.hype_agent",
            "malware_alias": null,
            "malware_printable": "HypeAgent",
            "first_seen_utc": "2026-08-19 06:06:06",
            "last_seen_utc": "2026-08-31 07:48:02",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://infosec.exchange/@RecklessPush38671/117118098460752628",
            "tags": "C2,Censys,HypeAgent",
            "anonymous": 0,
            "reporter": "Overkill1984zzz"
        }
    ],
    "1881373": [
        {
            "ioc_value": "91.92.47.111:7080",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.hype_agent",
            "malware_alias": null,
            "malware_printable": "HypeAgent",
            "first_seen_utc": "2026-08-19 06:06:04",
            "last_seen_utc": "2026-08-31 07:48:02",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://infosec.exchange/@RecklessPush38671/117118098460752628",
            "tags": "C2,Censys,HypeAgent",
            "anonymous": 0,
            "reporter": "Overkill1984zzz"
        }
    ],
    "1881374": [
        {
            "ioc_value": "91.92.120.61:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.hype_agent",
            "malware_alias": null,
            "malware_printable": "HypeAgent",
            "first_seen_utc": "2026-08-19 06:06:04",
            "last_seen_utc": "2026-08-31 07:47:58",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://infosec.exchange/@RecklessPush38671/117118098460752628",
            "tags": "C2,Censys,HypeAgent",
            "anonymous": 0,
            "reporter": "Overkill1984zzz"
        }
    ],
    "1881375": [
        {
            "ioc_value": "91.92.120.61:7080",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.hype_agent",
            "malware_alias": null,
            "malware_printable": "HypeAgent",
            "first_seen_utc": "2026-08-19 06:06:03",
            "last_seen_utc": "2026-08-31 07:47:58",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://infosec.exchange/@RecklessPush38671/117118098460752628",
            "tags": "C2,Censys,HypeAgent",
            "anonymous": 0,
            "reporter": "Overkill1984zzz"
        }
    ],
    "1881377": [
        {
            "ioc_value": "94.26.3.211:7080",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.hype_agent",
            "malware_alias": null,
            "malware_printable": "HypeAgent",
            "first_seen_utc": "2026-08-19 06:06:01",
            "last_seen_utc": "2026-08-31 07:48:10",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://infosec.exchange/@RecklessPush38671/117118098460752628",
            "tags": "C2,Censys,HypeAgent",
            "anonymous": 0,
            "reporter": "Overkill1984zzz"
        }
    ],
    "1881378": [
        {
            "ioc_value": "94.154.32.73:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.hype_agent",
            "malware_alias": null,
            "malware_printable": "HypeAgent",
            "first_seen_utc": "2026-08-19 06:06:01",
            "last_seen_utc": "2026-08-31 07:48:07",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://infosec.exchange/@RecklessPush38671/117118098460752628",
            "tags": "C2,Censys,HypeAgent",
            "anonymous": 0,
            "reporter": "Overkill1984zzz"
        }
    ],
    "1881379": [
        {
            "ioc_value": "103.141.235.248:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.hype_agent",
            "malware_alias": null,
            "malware_printable": "HypeAgent",
            "first_seen_utc": "2026-08-19 06:06:01",
            "last_seen_utc": "2026-08-31 07:43:06",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://infosec.exchange/@RecklessPush38671/117118098460752628",
            "tags": "C2,Censys,HypeAgent",
            "anonymous": 0,
            "reporter": "Overkill1984zzz"
        }
    ],
    "1881380": [
        {
            "ioc_value": "103.141.235.248:7080",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.hype_agent",
            "malware_alias": null,
            "malware_printable": "HypeAgent",
            "first_seen_utc": "2026-08-19 06:06:00",
            "last_seen_utc": "2026-08-31 07:43:06",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://infosec.exchange/@RecklessPush38671/117118098460752628",
            "tags": "C2,Censys,HypeAgent",
            "anonymous": 0,
            "reporter": "Overkill1984zzz"
        }
    ],
    "1881381": [
        {
            "ioc_value": "104.168.70.163:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.hype_agent",
            "malware_alias": null,
            "malware_printable": "HypeAgent",
            "first_seen_utc": "2026-08-19 06:06:00",
            "last_seen_utc": "2026-08-31 07:43:13",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://infosec.exchange/@RecklessPush38671/117118098460752628",
            "tags": "C2,Censys,HypeAgent",
            "anonymous": 0,
            "reporter": "Overkill1984zzz"
        }
    ],
    "1881382": [
        {
            "ioc_value": "107.174.146.6:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.hype_agent",
            "malware_alias": null,
            "malware_printable": "HypeAgent",
            "first_seen_utc": "2026-08-19 06:05:59",
            "last_seen_utc": "2026-08-31 07:43:23",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://infosec.exchange/@RecklessPush38671/117118098460752628",
            "tags": "C2,Censys,HypeAgent",
            "anonymous": 0,
            "reporter": "Overkill1984zzz"
        }
    ],
    "1881383": [
        {
            "ioc_value": "107.174.146.6:7080",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.hype_agent",
            "malware_alias": null,
            "malware_printable": "HypeAgent",
            "first_seen_utc": "2026-08-19 06:05:59",
            "last_seen_utc": "2026-08-31 07:43:23",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://infosec.exchange/@RecklessPush38671/117118098460752628",
            "tags": "C2,Censys,HypeAgent",
            "anonymous": 0,
            "reporter": "Overkill1984zzz"
        }
    ],
    "1881385": [
        {
            "ioc_value": "151.242.63.24:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.hype_agent",
            "malware_alias": null,
            "malware_printable": "HypeAgent",
            "first_seen_utc": "2026-08-19 06:05:58",
            "last_seen_utc": "2026-08-31 07:43:55",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://infosec.exchange/@RecklessPush38671/117118098460752628",
            "tags": "C2,Censys,HypeAgent",
            "anonymous": 0,
            "reporter": "Overkill1984zzz"
        }
    ],
    "1881386": [
        {
            "ioc_value": "151.242.63.24:7080",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.hype_agent",
            "malware_alias": null,
            "malware_printable": "HypeAgent",
            "first_seen_utc": "2026-08-19 06:05:58",
            "last_seen_utc": "2026-08-31 07:43:55",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://infosec.exchange/@RecklessPush38671/117118098460752628",
            "tags": "C2,Censys,HypeAgent",
            "anonymous": 0,
            "reporter": "Overkill1984zzz"
        }
    ],
    "1881387": [
        {
            "ioc_value": "151.242.63.165:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.hype_agent",
            "malware_alias": null,
            "malware_printable": "HypeAgent",
            "first_seen_utc": "2026-08-19 06:05:58",
            "last_seen_utc": "2026-08-31 07:43:55",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://infosec.exchange/@RecklessPush38671/117118098460752628",
            "tags": "C2,Censys,HypeAgent",
            "anonymous": 0,
            "reporter": "Overkill1984zzz"
        }
    ],
    "1881388": [
        {
            "ioc_value": "151.242.63.165:7080",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.hype_agent",
            "malware_alias": null,
            "malware_printable": "HypeAgent",
            "first_seen_utc": "2026-08-19 06:05:57",
            "last_seen_utc": "2026-08-31 07:43:54",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://infosec.exchange/@RecklessPush38671/117118098460752628",
            "tags": "C2,Censys,HypeAgent",
            "anonymous": 0,
            "reporter": "Overkill1984zzz"
        }
    ],
    "1881389": [
        {
            "ioc_value": "151.242.63.215:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.hype_agent",
            "malware_alias": null,
            "malware_printable": "HypeAgent",
            "first_seen_utc": "2026-08-19 06:05:57",
            "last_seen_utc": "2026-08-31 07:43:55",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://infosec.exchange/@RecklessPush38671/117118098460752628",
            "tags": "C2,Censys,HypeAgent",
            "anonymous": 0,
            "reporter": "Overkill1984zzz"
        }
    ],
    "1881390": [
        {
            "ioc_value": "151.242.63.215:7080",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.hype_agent",
            "malware_alias": null,
            "malware_printable": "HypeAgent",
            "first_seen_utc": "2026-08-19 06:05:56",
            "last_seen_utc": "2026-08-31 07:43:55",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://infosec.exchange/@RecklessPush38671/117118098460752628",
            "tags": "C2,Censys,HypeAgent",
            "anonymous": 0,
            "reporter": "Overkill1984zzz"
        }
    ],
    "1881391": [
        {
            "ioc_value": "195.177.94.60:7080",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.hype_agent",
            "malware_alias": null,
            "malware_printable": "HypeAgent",
            "first_seen_utc": "2026-08-19 06:05:56",
            "last_seen_utc": "2026-08-31 07:45:26",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://infosec.exchange/@RecklessPush38671/117118098460752628",
            "tags": "C2,Censys,HypeAgent",
            "anonymous": 0,
            "reporter": "Overkill1984zzz"
        }
    ],
    "1881393": [
        {
            "ioc_value": "209.54.103.173:7080",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.hype_agent",
            "malware_alias": null,
            "malware_printable": "HypeAgent",
            "first_seen_utc": "2026-08-19 06:05:55",
            "last_seen_utc": "2026-08-31 07:45:47",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://infosec.exchange/@RecklessPush38671/117118098460752628",
            "tags": "C2,Censys,HypeAgent",
            "anonymous": 0,
            "reporter": "Overkill1984zzz"
        }
    ],
    "1881417": [
        {
            "ioc_value": "43.128.113.133:9035",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.aisuru",
            "malware_alias": null,
            "malware_printable": "Aisuru",
            "first_seen_utc": "2026-08-19 06:05:25",
            "last_seen_utc": "2026-08-31 04:00:59",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "Aisuru,c2",
            "anonymous": 0,
            "reporter": "Bitsight"
        }
    ],
    "1881423": [
        {
            "ioc_value": "150.109.93.78:8080",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.aisuru",
            "malware_alias": null,
            "malware_printable": "Aisuru",
            "first_seen_utc": "2026-08-19 06:05:24",
            "last_seen_utc": "2026-08-31 07:48:27",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "Aisuru,c2",
            "anonymous": 0,
            "reporter": "Bitsight"
        }
    ],
    "1881442": [
        {
            "ioc_value": "150.109.93.78:34567",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.aisuru",
            "malware_alias": null,
            "malware_printable": "Aisuru",
            "first_seen_utc": "2026-08-19 06:05:24",
            "last_seen_utc": "2026-08-30 20:52:34",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "Aisuru,c2",
            "anonymous": 0,
            "reporter": "Bitsight"
        }
    ],
    "1881491": [
        {
            "ioc_value": "43.128.113.133:12345",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.aisuru",
            "malware_alias": null,
            "malware_printable": "Aisuru",
            "first_seen_utc": "2026-08-19 06:05:10",
            "last_seen_utc": "2026-08-30 14:49:02",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "Aisuru,c2",
            "anonymous": 0,
            "reporter": "Bitsight"
        }
    ],
    "1881540": [
        {
            "ioc_value": "43.134.49.218:9034",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.aisuru",
            "malware_alias": null,
            "malware_printable": "Aisuru",
            "first_seen_utc": "2026-08-19 06:05:09",
            "last_seen_utc": "2026-08-31 05:38:02",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "Aisuru,c2",
            "anonymous": 0,
            "reporter": "Bitsight"
        }
    ],
    "1881309": [
        {
            "ioc_value": "176.96.138.73:7000",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-19 06:04:57",
            "last_seen_utc": "2026-08-31 07:44:32",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "",
            "tags": "PureHVNC,PureRAT,ResolverRAT",
            "anonymous": 0,
            "reporter": "whoamix302"
        }
    ],
    "1881311": [
        {
            "ioc_value": "85.209.129.102:56003",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-19 06:04:57",
            "last_seen_utc": "2026-08-31 07:47:50",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "",
            "tags": "PureHVNC,PureRAT,ResolverRAT",
            "anonymous": 0,
            "reporter": "whoamix302"
        }
    ],
    "1881310": [
        {
            "ioc_value": "213.111.148.180:56003",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-19 06:04:56",
            "last_seen_utc": "2026-08-31 07:45:50",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "",
            "tags": "PureHVNC,PureRAT,ResolverRAT",
            "anonymous": 0,
            "reporter": "whoamix302"
        }
    ],
    "1881323": [
        {
            "ioc_value": "43.134.49.218:12345",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.aisuru",
            "malware_alias": null,
            "malware_printable": "Aisuru",
            "first_seen_utc": "2026-08-19 06:04:54",
            "last_seen_utc": "2026-08-29 21:52:39",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "Aisuru,c2",
            "anonymous": 0,
            "reporter": "Bitsight"
        }
    ],
    "1881609": [
        {
            "ioc_value": "47.108.86.120:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-08-19 04:05:04",
            "last_seen_utc": "2026-08-31 07:48:51",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "cobaltstrike",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1881520": [
        {
            "ioc_value": "hutchs.ca",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.iclickfix",
            "malware_alias": null,
            "malware_printable": "IClickFix",
            "first_seen_utc": "2026-08-18 23:57:10",
            "last_seen_utc": "2026-08-29 11:28:19",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": "",
            "tags": "ClickFix,etherhiding,nochain",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1881456": [
        {
            "ioc_value": "109.248.160.184:8080",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.havoc",
            "malware_alias": "Havokiz",
            "malware_printable": "Havoc",
            "first_seen_utc": "2026-08-18 22:05:04",
            "last_seen_utc": "2026-08-31 07:43:28",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "havoc",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1881411": [
        {
            "ioc_value": "92.63.180.96:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-08-18 19:46:56",
            "last_seen_utc": "2026-08-31 07:48:04",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1881410": [
        {
            "ioc_value": "91.92.42.94:4851",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-08-18 19:46:55",
            "last_seen_utc": "2026-08-31 07:48:00",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1881409": [
        {
            "ioc_value": "91.92.243.36:56002",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-18 19:46:53",
            "last_seen_utc": "2026-08-31 07:47:59",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1881408": [
        {
            "ioc_value": "46.63.0.187:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.havoc",
            "malware_alias": "Havokiz",
            "malware_printable": "Havoc",
            "first_seen_utc": "2026-08-18 19:46:23",
            "last_seen_utc": "2026-08-31 07:47:23",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Havoc",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1881407": [
        {
            "ioc_value": "45.59.120.82:7001",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.dcrat",
            "malware_alias": "DarkCrystal RAT",
            "malware_printable": "DCRat",
            "first_seen_utc": "2026-08-18 19:46:16",
            "last_seen_utc": "2026-08-31 07:47:15",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DCRat,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1881406": [
        {
            "ioc_value": "23.175.48.7:6606",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-08-18 19:45:44",
            "last_seen_utc": "2026-08-31 07:46:39",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1881405": [
        {
            "ioc_value": "195.177.94.19:56003",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-18 19:44:42",
            "last_seen_utc": "2026-08-31 07:45:25",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1881404": [
        {
            "ioc_value": "185.199.197.93:1488",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-08-18 19:44:23",
            "last_seen_utc": "2026-08-31 07:44:44",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1881403": [
        {
            "ioc_value": "178.211.155.154:56003",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-18 19:44:16",
            "last_seen_utc": "2026-08-31 07:44:35",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1881402": [
        {
            "ioc_value": "176.96.138.71:56003",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-18 19:44:13",
            "last_seen_utc": "2026-08-31 07:44:32",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1881401": [
        {
            "ioc_value": "172.252.172.33:56003",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-18 19:44:08",
            "last_seen_utc": "2026-08-31 07:44:26",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1881400": [
        {
            "ioc_value": "172.252.172.31:56003",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-18 19:44:07",
            "last_seen_utc": "2026-08-31 07:44:25",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1881399": [
        {
            "ioc_value": "154.222.16.160:9098",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.mirai",
            "malware_alias": "Katana",
            "malware_printable": "Mirai",
            "first_seen_utc": "2026-08-18 19:43:45",
            "last_seen_utc": "2026-08-31 07:43:58",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mirai",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1881398": [
        {
            "ioc_value": "124.198.131.129:8808",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-08-18 19:43:25",
            "last_seen_utc": "2026-08-31 07:43:35",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1881397": [
        {
            "ioc_value": "102.117.161.35:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-08-18 19:43:03",
            "last_seen_utc": "2026-08-31 07:43:04",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1880844": [
        {
            "ioc_value": "64.227.187.82:8443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.aisuru",
            "malware_alias": null,
            "malware_printable": "Aisuru",
            "first_seen_utc": "2026-08-18 14:03:09",
            "last_seen_utc": "2026-08-29 08:40:20",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "Aisuru,c2",
            "anonymous": 0,
            "reporter": "Bitsight"
        }
    ],
    "1880798": [
        {
            "ioc_value": "216.128.179.190:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-08-18 12:08:13",
            "last_seen_utc": "2026-08-31 07:46:32",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": "https://www.shodan.io/host/216.128.179.190#7443",
            "tags": "c2,mythic,shodan",
            "anonymous": 0,
            "reporter": "juroots"
        }
    ],
    "1880756": [
        {
            "ioc_value": "149.202.227.107:4321",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-08-18 12:03:39",
            "last_seen_utc": "2026-08-31 07:43:52",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": "https://www.shodan.io/host/149.202.227.107#4321",
            "tags": "adaptixc2,c2,shodan",
            "anonymous": 0,
            "reporter": "juroots"
        }
    ],
    "1880291": [
        {
            "ioc_value": "23.148.212.123:2053",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-08-18 11:48:07",
            "last_seen_utc": "2026-08-31 07:48:45",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1880290": [
        {
            "ioc_value": "ossb6.oss-cn-beijing.aliyuncs.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-08-18 11:47:40",
            "last_seen_utc": "2026-08-31 07:48:19",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1880267": [
        {
            "ioc_value": "94.26.3.211:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.hype_agent",
            "malware_alias": null,
            "malware_printable": "HypeAgent",
            "first_seen_utc": "2026-08-18 10:56:26",
            "last_seen_utc": "2026-08-31 07:48:10",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "",
            "tags": "HypeAgent",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1880269": [
        {
            "ioc_value": "195.177.94.60:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.hype_agent",
            "malware_alias": null,
            "malware_printable": "HypeAgent",
            "first_seen_utc": "2026-08-18 10:56:26",
            "last_seen_utc": "2026-08-31 07:45:26",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "",
            "tags": "HypeAgent",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1880270": [
        {
            "ioc_value": "107.175.148.122:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.hype_agent",
            "malware_alias": null,
            "malware_printable": "HypeAgent",
            "first_seen_utc": "2026-08-18 10:56:26",
            "last_seen_utc": "2026-08-31 07:43:23",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "",
            "tags": "HypeAgent",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1880271": [
        {
            "ioc_value": "209.54.103.173:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.hype_agent",
            "malware_alias": null,
            "malware_printable": "HypeAgent",
            "first_seen_utc": "2026-08-18 10:56:26",
            "last_seen_utc": "2026-08-31 07:45:47",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "",
            "tags": "HypeAgent",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1880248": [
        {
            "ioc_value": "95.216.220.204:8000",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.chaos",
            "malware_alias": "FakeRyuk,RyukJoke,Yashma",
            "malware_printable": "Chaos",
            "first_seen_utc": "2026-08-18 09:47:49",
            "last_seen_utc": "2026-08-31 07:48:12",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CHAOS,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1880246": [
        {
            "ioc_value": "68.178.202.150:4321",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-08-18 09:47:23",
            "last_seen_utc": "2026-08-31 07:47:39",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1880247": [
        {
            "ioc_value": "68.178.205.17:4321",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-08-18 09:47:23",
            "last_seen_utc": "2026-08-31 07:47:39",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1880244": [
        {
            "ioc_value": "45.11.181.85:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-18 09:46:48",
            "last_seen_utc": "2026-08-31 07:47:06",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1880245": [
        {
            "ioc_value": "45.11.181.85:56001",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-18 09:46:48",
            "last_seen_utc": "2026-08-31 07:47:06",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1880243": [
        {
            "ioc_value": "36.248.232.166:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-08-18 09:46:37",
            "last_seen_utc": "2026-08-31 07:46:53",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1880242": [
        {
            "ioc_value": "31.56.209.245:5088",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.chaos",
            "malware_alias": "FakeRyuk,RyukJoke,Yashma",
            "malware_printable": "Chaos",
            "first_seen_utc": "2026-08-18 09:46:30",
            "last_seen_utc": "2026-08-31 07:46:46",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CHAOS,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1880241": [
        {
            "ioc_value": "213.199.53.152:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-08-18 09:45:34",
            "last_seen_utc": "2026-08-31 07:45:51",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1880240": [
        {
            "ioc_value": "20.51.121.37:4321",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-08-18 09:45:20",
            "last_seen_utc": "2026-08-31 07:45:39",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1880239": [
        {
            "ioc_value": "198.23.185.98:8888",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-08-18 09:45:13",
            "last_seen_utc": "2026-08-31 07:45:31",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1880238": [
        {
            "ioc_value": "198.135.54.91:2030",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.evilginx",
            "malware_alias": null,
            "malware_printable": "Evilginx",
            "first_seen_utc": "2026-08-18 09:45:11",
            "last_seen_utc": "2026-08-31 07:45:29",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Evilginx,EvilGoPhish",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1880237": [
        {
            "ioc_value": "195.242.119.228:4321",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-08-18 09:45:09",
            "last_seen_utc": "2026-08-31 07:45:27",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1880236": [
        {
            "ioc_value": "192.169.176.54:4321",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-08-18 09:44:53",
            "last_seen_utc": "2026-08-31 07:45:06",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1880235": [
        {
            "ioc_value": "187.194.216.103:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-08-18 09:44:49",
            "last_seen_utc": "2026-08-31 07:44:59",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1880234": [
        {
            "ioc_value": "186.169.88.130:5011",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-08-18 09:44:48",
            "last_seen_utc": "2026-08-31 07:44:57",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1880232": [
        {
            "ioc_value": "185.254.99.153:56002",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-18 09:44:44",
            "last_seen_utc": "2026-08-31 07:44:50",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1880233": [
        {
            "ioc_value": "185.254.99.153:56003",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-18 09:44:44",
            "last_seen_utc": "2026-08-31 07:44:50",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1880231": [
        {
            "ioc_value": "185.212.128.51:9000",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.evilginx",
            "malware_alias": null,
            "malware_printable": "Evilginx",
            "first_seen_utc": "2026-08-18 09:44:40",
            "last_seen_utc": "2026-08-31 07:44:45",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Evilginx,EvilGoPhish",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1880230": [
        {
            "ioc_value": "185.193.127.4:13370",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-08-18 09:44:38",
            "last_seen_utc": "2026-08-31 07:44:44",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1880229": [
        {
            "ioc_value": "178.211.155.154:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-18 09:44:30",
            "last_seen_utc": "2026-08-31 07:44:35",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1880228": [
        {
            "ioc_value": "176.96.138.71:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-18 09:44:25",
            "last_seen_utc": "2026-08-31 07:44:32",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1880225": [
        {
            "ioc_value": "172.252.172.30:56001",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-18 09:44:18",
            "last_seen_utc": "2026-08-31 07:44:24",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1880226": [
        {
            "ioc_value": "172.252.172.30:56002",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-18 09:44:18",
            "last_seen_utc": "2026-08-31 07:44:25",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1880227": [
        {
            "ioc_value": "172.252.172.30:56003",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-18 09:44:18",
            "last_seen_utc": "2026-08-31 07:44:25",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1880224": [
        {
            "ioc_value": "154.248.45.157:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-18 09:43:52",
            "last_seen_utc": "2026-08-31 07:43:59",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1880223": [
        {
            "ioc_value": "137.175.30.119:56003",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-18 09:43:37",
            "last_seen_utc": "2026-08-31 07:43:44",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1880222": [
        {
            "ioc_value": "128.90.112.33:2486",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.dcrat",
            "malware_alias": "DarkCrystal RAT",
            "malware_printable": "DCRat",
            "first_seen_utc": "2026-08-18 09:43:30",
            "last_seen_utc": "2026-08-31 07:43:38",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DCRat,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1880221": [
        {
            "ioc_value": "104.243.248.63:408",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-08-18 09:43:14",
            "last_seen_utc": "2026-08-31 07:43:17",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1880192": [
        {
            "ioc_value": "43.128.113.133:34567",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.aisuru",
            "malware_alias": null,
            "malware_printable": "Aisuru",
            "first_seen_utc": "2026-08-18 09:15:11",
            "last_seen_utc": "2026-08-30 15:24:41",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "Aisuru,c2",
            "anonymous": 0,
            "reporter": "Bitsight"
        }
    ],
    "1880191": [
        {
            "ioc_value": "43.134.49.218:34567",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.aisuru",
            "malware_alias": null,
            "malware_printable": "Aisuru",
            "first_seen_utc": "2026-08-18 09:15:10",
            "last_seen_utc": "2026-08-31 01:15:29",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "Aisuru,c2",
            "anonymous": 0,
            "reporter": "Bitsight"
        }
    ],
    "1880040": [
        {
            "ioc_value": "tunisie-connect.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "unknown_loader",
            "malware_alias": null,
            "malware_printable": "Unknown Loader",
            "first_seen_utc": "2026-08-18 07:28:28",
            "last_seen_utc": "2026-08-29 18:51:58",
            "confidence_level": 75,
            "is_compromised": true,
            "reference": "",
            "tags": "etherhiding",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1878822": [
        {
            "ioc_value": "38.76.183.197:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-08-18 07:05:10",
            "last_seen_utc": "2026-08-31 07:48:46",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "cobaltstrike",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1878059": [
        {
            "ioc_value": "167.99.67.141:8811",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remus",
            "malware_alias": null,
            "malware_printable": "Remus",
            "first_seen_utc": "2026-08-18 05:28:19",
            "last_seen_utc": "2026-08-31 05:06:03",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "974b6b4ed30ddaa4b6f4ec27976e52d8,c2,remus",
            "anonymous": 0,
            "reporter": "Bitsight"
        }
    ],
    "1878062": [
        {
            "ioc_value": "176.98.182.177:8080",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.aisuru",
            "malware_alias": null,
            "malware_printable": "Aisuru",
            "first_seen_utc": "2026-08-18 05:28:17",
            "last_seen_utc": "2026-08-31 07:49:34",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "Aisuru,c2",
            "anonymous": 0,
            "reporter": "Bitsight"
        }
    ],
    "1878496": [
        {
            "ioc_value": "168.144.188.31:8001",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.aisuru",
            "malware_alias": null,
            "malware_printable": "Aisuru",
            "first_seen_utc": "2026-08-18 05:25:12",
            "last_seen_utc": "2026-08-29 09:47:34",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "Aisuru,c2",
            "anonymous": 0,
            "reporter": "Bitsight"
        }
    ],
    "1878497": [
        {
            "ioc_value": "201.79.5.223:8001",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.aisuru",
            "malware_alias": null,
            "malware_printable": "Aisuru",
            "first_seen_utc": "2026-08-18 05:25:11",
            "last_seen_utc": "2026-08-29 09:48:28",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "Aisuru,c2",
            "anonymous": 0,
            "reporter": "Bitsight"
        }
    ],
    "1878498": [
        {
            "ioc_value": "161.35.74.220:8001",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.aisuru",
            "malware_alias": null,
            "malware_printable": "Aisuru",
            "first_seen_utc": "2026-08-18 05:25:11",
            "last_seen_utc": "2026-08-29 09:48:16",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "Aisuru,c2",
            "anonymous": 0,
            "reporter": "Bitsight"
        }
    ],
    "1878499": [
        {
            "ioc_value": "64.227.187.82:8001",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.aisuru",
            "malware_alias": null,
            "malware_printable": "Aisuru",
            "first_seen_utc": "2026-08-18 05:25:10",
            "last_seen_utc": "2026-08-29 09:49:11",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "Aisuru,c2",
            "anonymous": 0,
            "reporter": "Bitsight"
        }
    ],
    "1878500": [
        {
            "ioc_value": "138.197.15.223:8001",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.aisuru",
            "malware_alias": null,
            "malware_printable": "Aisuru",
            "first_seen_utc": "2026-08-18 05:25:09",
            "last_seen_utc": "2026-08-29 09:48:03",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "Aisuru,c2",
            "anonymous": 0,
            "reporter": "Bitsight"
        }
    ],
    "1878510": [
        {
            "ioc_value": "142.93.205.111:8001",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.aisuru",
            "malware_alias": null,
            "malware_printable": "Aisuru",
            "first_seen_utc": "2026-08-18 05:25:08",
            "last_seen_utc": "2026-08-29 09:47:48",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "Aisuru,c2",
            "anonymous": 0,
            "reporter": "Bitsight"
        }
    ],
    "1878511": [
        {
            "ioc_value": "159.89.193.17:8001",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.aisuru",
            "malware_alias": null,
            "malware_printable": "Aisuru",
            "first_seen_utc": "2026-08-18 05:25:07",
            "last_seen_utc": "2026-08-29 09:48:56",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "Aisuru,c2",
            "anonymous": 0,
            "reporter": "Bitsight"
        }
    ],
    "1878515": [
        {
            "ioc_value": "143.198.84.165:8001",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.aisuru",
            "malware_alias": null,
            "malware_printable": "Aisuru",
            "first_seen_utc": "2026-08-18 05:25:04",
            "last_seen_utc": "2026-08-29 09:48:41",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "Aisuru,c2",
            "anonymous": 0,
            "reporter": "Bitsight"
        }
    ],
    "1878646": [
        {
            "ioc_value": "43.134.49.218:8080",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.aisuru",
            "malware_alias": null,
            "malware_printable": "Aisuru",
            "first_seen_utc": "2026-08-18 05:24:56",
            "last_seen_utc": "2026-08-31 06:44:52",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "Aisuru,c2",
            "anonymous": 0,
            "reporter": "Bitsight"
        }
    ],
    "1878751": [
        {
            "ioc_value": "43.128.113.133:9034",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.aisuru",
            "malware_alias": null,
            "malware_printable": "Aisuru",
            "first_seen_utc": "2026-08-18 05:24:25",
            "last_seen_utc": "2026-08-30 23:39:22",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "Aisuru,c2",
            "anonymous": 0,
            "reporter": "Bitsight"
        }
    ],
    "1878778": [
        {
            "ioc_value": "150.109.93.78:9034",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.aisuru",
            "malware_alias": null,
            "malware_printable": "Aisuru",
            "first_seen_utc": "2026-08-18 05:24:22",
            "last_seen_utc": "2026-08-30 20:20:28",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "Aisuru,c2",
            "anonymous": 0,
            "reporter": "Bitsight"
        }
    ],
    "1878626": [
        {
            "ioc_value": "94.143.231.61:56001",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-17 19:46:54",
            "last_seen_utc": "2026-08-31 07:48:06",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1878625": [
        {
            "ioc_value": "83.229.120.106:45231",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-08-17 19:46:42",
            "last_seen_utc": "2026-08-31 07:47:48",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1878624": [
        {
            "ioc_value": "64.89.160.127:8088",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-08-17 19:46:32",
            "last_seen_utc": "2026-08-31 07:47:35",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1878622": [
        {
            "ioc_value": "46.246.6.16:2703",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-08-17 19:46:21",
            "last_seen_utc": "2026-08-31 07:47:22",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1878623": [
        {
            "ioc_value": "46.246.6.16:7049",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-08-17 19:46:21",
            "last_seen_utc": "2026-08-31 07:47:22",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1878621": [
        {
            "ioc_value": "45.61.114.254:56003",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-17 19:46:15",
            "last_seen_utc": "2026-08-31 07:47:15",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1878620": [
        {
            "ioc_value": "38.240.47.77:8088",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-08-17 19:45:59",
            "last_seen_utc": "2026-08-31 07:46:57",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1878618": [
        {
            "ioc_value": "217.60.195.226:56001",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-17 19:45:42",
            "last_seen_utc": "2026-08-31 07:46:35",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1878619": [
        {
            "ioc_value": "217.60.195.226:56002",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-17 19:45:42",
            "last_seen_utc": "2026-08-31 07:46:35",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1878617": [
        {
            "ioc_value": "207.89.17.21:7070",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.dcrat",
            "malware_alias": "DarkCrystal RAT",
            "malware_printable": "DCRat",
            "first_seen_utc": "2026-08-17 19:44:57",
            "last_seen_utc": "2026-08-31 07:45:46",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DCRat,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1878616": [
        {
            "ioc_value": "2.27.63.240:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-08-17 19:44:49",
            "last_seen_utc": "2026-08-31 07:45:35",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1878615": [
        {
            "ioc_value": "194.59.30.183:56003",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-17 19:44:41",
            "last_seen_utc": "2026-08-31 07:45:19",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1878614": [
        {
            "ioc_value": "194.110.247.114:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-08-17 19:44:40",
            "last_seen_utc": "2026-08-31 07:45:16",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1878613": [
        {
            "ioc_value": "179.61.227.148:6606",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-08-17 19:44:19",
            "last_seen_utc": "2026-08-31 07:44:37",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1878612": [
        {
            "ioc_value": "178.16.52.100:8848",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.dcrat",
            "malware_alias": "DarkCrystal RAT",
            "malware_printable": "DCRat",
            "first_seen_utc": "2026-08-17 19:44:16",
            "last_seen_utc": "2026-08-31 07:44:33",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DCRat,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1878611": [
        {
            "ioc_value": "172.98.22.177:56002",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-17 19:44:12",
            "last_seen_utc": "2026-08-31 07:44:29",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1878610": [
        {
            "ioc_value": "164.160.187.69:8080",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-08-17 19:44:00",
            "last_seen_utc": "2026-08-31 07:44:14",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1878609": [
        {
            "ioc_value": "159.223.145.166:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.poshc2",
            "malware_alias": null,
            "malware_printable": "PoshC2",
            "first_seen_utc": "2026-08-17 19:43:56",
            "last_seen_utc": "2026-08-31 07:44:09",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PoshC2",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1878608": [
        {
            "ioc_value": "155.138.175.126:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-08-17 19:43:48",
            "last_seen_utc": "2026-08-31 07:44:00",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1878606": [
        {
            "ioc_value": "154.222.16.226:9098",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.mirai",
            "malware_alias": "Katana",
            "malware_printable": "Mirai",
            "first_seen_utc": "2026-08-17 19:43:47",
            "last_seen_utc": "2026-08-31 07:43:58",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mirai",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1878607": [
        {
            "ioc_value": "154.222.16.250:9098",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.mirai",
            "malware_alias": "Katana",
            "malware_printable": "Mirai",
            "first_seen_utc": "2026-08-17 19:43:47",
            "last_seen_utc": "2026-08-31 07:43:58",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mirai",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1878604": [
        {
            "ioc_value": "154.205.145.162:48443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.bianlian",
            "malware_alias": null,
            "malware_printable": "BianLian",
            "first_seen_utc": "2026-08-17 19:43:46",
            "last_seen_utc": "2026-08-31 07:43:58",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "Bianlian,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1878605": [
        {
            "ioc_value": "154.222.16.141:9098",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.mirai",
            "malware_alias": "Katana",
            "malware_printable": "Mirai",
            "first_seen_utc": "2026-08-17 19:43:46",
            "last_seen_utc": "2026-08-31 07:43:58",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mirai",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1878602": [
        {
            "ioc_value": "151.242.170.219:56001",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-17 19:43:44",
            "last_seen_utc": "2026-08-31 07:43:54",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1878603": [
        {
            "ioc_value": "151.242.170.219:56002",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-17 19:43:44",
            "last_seen_utc": "2026-08-31 07:43:54",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1878600": [
        {
            "ioc_value": "124.198.131.110:56001",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-17 19:43:25",
            "last_seen_utc": "2026-08-31 07:43:35",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1878601": [
        {
            "ioc_value": "124.198.131.110:56002",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-17 19:43:25",
            "last_seen_utc": "2026-08-31 07:43:35",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1878598": [
        {
            "ioc_value": "118.107.5.200:56001",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-17 19:43:23",
            "last_seen_utc": "2026-08-31 07:43:33",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1878599": [
        {
            "ioc_value": "118.107.5.200:56002",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-17 19:43:23",
            "last_seen_utc": "2026-08-31 07:43:33",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1878597": [
        {
            "ioc_value": "104.243.248.63:401",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-08-17 19:43:12",
            "last_seen_utc": "2026-08-31 07:43:17",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1878057": [
        {
            "ioc_value": "huber-holzbau.ch",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-08-17 15:05:26",
            "last_seen_utc": "2026-08-29 12:31:37",
            "confidence_level": 90,
            "is_compromised": true,
            "reference": null,
            "tags": "compromised,ErrTraffic",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1878053": [
        {
            "ioc_value": "43.128.113.133:8443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.aisuru",
            "malware_alias": null,
            "malware_printable": "Aisuru",
            "first_seen_utc": "2026-08-17 15:00:38",
            "last_seen_utc": "2026-08-31 05:07:04",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "Aisuru,c2",
            "anonymous": 0,
            "reporter": "Bitsight"
        }
    ],
    "1878054": [
        {
            "ioc_value": "43.129.180.120:8080",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.aisuru",
            "malware_alias": null,
            "malware_printable": "Aisuru",
            "first_seen_utc": "2026-08-17 15:00:38",
            "last_seen_utc": "2026-08-31 04:33:23",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "Aisuru,c2",
            "anonymous": 0,
            "reporter": "Bitsight"
        }
    ],
    "1878047": [
        {
            "ioc_value": "189.128.189.249:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-08-17 14:05:05",
            "last_seen_utc": "2026-08-31 07:45:00",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "mythic",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1877899": [
        {
            "ioc_value": "c2.apamm.kdns.fr",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-08-17 11:47:55",
            "last_seen_utc": "2026-08-31 07:48:14",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1877763": [
        {
            "ioc_value": "https://svhost-update-service.casa/",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.stealc",
            "malware_alias": null,
            "malware_printable": "Stealc",
            "first_seen_utc": "2026-08-17 10:05:22",
            "last_seen_utc": "2026-08-31 08:15:02",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "c2,loader,PG,StealC,stealer",
            "anonymous": 0,
            "reporter": "Bitsight"
        }
    ],
    "1877751": [
        {
            "ioc_value": "95.133.229.173:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-17 09:47:53",
            "last_seen_utc": "2026-08-31 07:48:11",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1877750": [
        {
            "ioc_value": "94.250.190.137:4433",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.danabot",
            "malware_alias": "DanaTools",
            "malware_printable": "DanaBot",
            "first_seen_utc": "2026-08-17 09:47:52",
            "last_seen_utc": "2026-08-31 07:48:08",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DanBot,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1877749": [
        {
            "ioc_value": "86.48.16.94:3200",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-08-17 09:47:39",
            "last_seen_utc": "2026-08-31 07:47:52",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1877748": [
        {
            "ioc_value": "83.136.211.230:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-17 09:47:35",
            "last_seen_utc": "2026-08-31 07:47:48",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1877747": [
        {
            "ioc_value": "82.158.90.134:50555",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "apk.hook",
            "malware_alias": null,
            "malware_printable": "Hook",
            "first_seen_utc": "2026-08-17 09:47:34",
            "last_seen_utc": "2026-08-31 07:47:47",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Hook",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1877745": [
        {
            "ioc_value": "82.158.90.131:50555",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "apk.hook",
            "malware_alias": null,
            "malware_printable": "Hook",
            "first_seen_utc": "2026-08-17 09:47:33",
            "last_seen_utc": "2026-08-31 07:47:46",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Hook",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1877746": [
        {
            "ioc_value": "82.158.90.133:50555",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "apk.hook",
            "malware_alias": null,
            "malware_printable": "Hook",
            "first_seen_utc": "2026-08-17 09:47:33",
            "last_seen_utc": "2026-08-31 07:47:46",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Hook",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1877744": [
        {
            "ioc_value": "217.60.195.226:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-17 09:46:26",
            "last_seen_utc": "2026-08-31 07:46:35",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1877743": [
        {
            "ioc_value": "204.13.234.19:3333",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.evilginx",
            "malware_alias": null,
            "malware_printable": "Evilginx",
            "first_seen_utc": "2026-08-17 09:45:33",
            "last_seen_utc": "2026-08-31 07:45:42",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Evilginx,EvilGoPhish",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1877742": [
        {
            "ioc_value": "193.32.162.108:4432",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-08-17 09:45:13",
            "last_seen_utc": "2026-08-31 07:45:15",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1877741": [
        {
            "ioc_value": "186.112.73.78:8443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.deimos_c2",
            "malware_alias": null,
            "malware_printable": "DeimosC2",
            "first_seen_utc": "2026-08-17 09:44:57",
            "last_seen_utc": "2026-08-31 07:44:57",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "Deimos,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1877740": [
        {
            "ioc_value": "178.128.14.67:4443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.havoc",
            "malware_alias": "Havokiz",
            "malware_printable": "Havoc",
            "first_seen_utc": "2026-08-17 09:44:35",
            "last_seen_utc": "2026-08-31 07:44:33",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Havoc",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1877739": [
        {
            "ioc_value": "169.58.180.142:30400",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-08-17 09:44:22",
            "last_seen_utc": "2026-08-31 07:44:18",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1877738": [
        {
            "ioc_value": "145.63.130.104:4444",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-08-17 09:43:51",
            "last_seen_utc": "2026-08-31 07:43:50",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1877737": [
        {
            "ioc_value": "107.173.160.185:4321",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-08-17 09:43:20",
            "last_seen_utc": "2026-08-31 07:43:22",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1877688": [
        {
            "ioc_value": "http://158.94.210.108/",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.stealc",
            "malware_alias": null,
            "malware_printable": "Stealc",
            "first_seen_utc": "2026-08-17 08:00:26",
            "last_seen_utc": "2026-08-30 22:47:12",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "c2,loader,StealC,stealer,userr",
            "anonymous": 0,
            "reporter": "Bitsight"
        }
    ],
    "1877665": [
        {
            "ioc_value": "185.34.147.32:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-08-17 06:05:06",
            "last_seen_utc": "2026-08-31 07:44:53",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "asyncrat",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1877664": [
        {
            "ioc_value": "34.150.91.139:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-08-17 06:05:05",
            "last_seen_utc": "2026-08-31 07:46:51",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "mythic",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1877531": [
        {
            "ioc_value": "23.148.212.86:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-08-16 23:47:35",
            "last_seen_utc": "2026-08-31 07:48:45",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1877532": [
        {
            "ioc_value": "38.190.196.19:8080",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-08-16 23:47:35",
            "last_seen_utc": "2026-08-31 07:48:46",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1877530": [
        {
            "ioc_value": "154.91.85.44:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-08-16 23:47:26",
            "last_seen_utc": "2026-08-31 07:48:36",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1877529": [
        {
            "ioc_value": "cdn.winservers-network.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-08-16 23:47:06",
            "last_seen_utc": "2026-08-31 07:48:15",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1877422": [
        {
            "ioc_value": "2.27.4.236:5552",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-08-16 21:06:08",
            "last_seen_utc": "2026-08-31 07:45:35",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://bazaar.abuse.ch/sample/85cd6c3229f9ab547cc54f2cbdcf6ef2937987c0181e5ffa3c4205105df8e8fe/",
            "tags": "asyncrat",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1877334": [
        {
            "ioc_value": "94.250.182.47:4433",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.danabot",
            "malware_alias": "DanaTools",
            "malware_printable": "DanaBot",
            "first_seen_utc": "2026-08-16 19:46:47",
            "last_seen_utc": "2026-08-31 07:48:08",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DanBot,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1877335": [
        {
            "ioc_value": "94.26.0.7:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "js.tsundere",
            "malware_alias": "DinDoor",
            "malware_printable": "Tsundere",
            "first_seen_utc": "2026-08-16 19:46:47",
            "last_seen_utc": "2026-08-31 07:48:09",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DinDoor,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1877333": [
        {
            "ioc_value": "85.120.217.247:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-08-16 19:46:34",
            "last_seen_utc": "2026-08-31 07:47:50",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1877332": [
        {
            "ioc_value": "68.183.248.32:4443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.havoc",
            "malware_alias": "Havokiz",
            "malware_printable": "Havoc",
            "first_seen_utc": "2026-08-16 19:46:27",
            "last_seen_utc": "2026-08-31 07:47:39",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Havoc",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1877331": [
        {
            "ioc_value": "51.79.169.74:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-16 19:46:17",
            "last_seen_utc": "2026-08-31 07:47:27",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1877329": [
        {
            "ioc_value": "45.145.41.185:56002",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-16 19:46:03",
            "last_seen_utc": "2026-08-31 07:47:09",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1877330": [
        {
            "ioc_value": "45.145.41.185:56003",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-16 19:46:03",
            "last_seen_utc": "2026-08-31 07:47:09",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1877328": [
        {
            "ioc_value": "217.60.195.110:56003",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-16 19:45:35",
            "last_seen_utc": "2026-08-31 07:46:34",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1877327": [
        {
            "ioc_value": "195.177.94.41:56002",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-16 19:44:40",
            "last_seen_utc": "2026-08-31 07:45:25",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1877326": [
        {
            "ioc_value": "187.154.215.53:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-08-16 19:44:30",
            "last_seen_utc": "2026-08-31 07:44:59",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1877325": [
        {
            "ioc_value": "178.172.173.84:3333",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.evilginx",
            "malware_alias": null,
            "malware_printable": "Evilginx",
            "first_seen_utc": "2026-08-16 19:44:15",
            "last_seen_utc": "2026-08-31 07:44:35",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Evilginx,EvilGoPhish",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1877324": [
        {
            "ioc_value": "172.94.18.103:77",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-08-16 19:44:09",
            "last_seen_utc": "2026-08-31 07:44:28",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1877323": [
        {
            "ioc_value": "153.52.182.78:7777",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-08-16 19:43:44",
            "last_seen_utc": "2026-08-31 07:43:56",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1877322": [
        {
            "ioc_value": "148.163.101.169:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-16 19:43:41",
            "last_seen_utc": "2026-08-31 07:43:52",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1877321": [
        {
            "ioc_value": "124.198.131.110:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-16 19:43:25",
            "last_seen_utc": "2026-08-31 07:43:35",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1877320": [
        {
            "ioc_value": "109.248.160.184:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.havoc",
            "malware_alias": "Havokiz",
            "malware_printable": "Havoc",
            "first_seen_utc": "2026-08-16 19:43:19",
            "last_seen_utc": "2026-08-31 07:43:28",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Havoc",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1877319": [
        {
            "ioc_value": "104.243.248.63:1002",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-08-16 19:43:12",
            "last_seen_utc": "2026-08-31 07:43:15",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1877301": [
        {
            "ioc_value": "108.174.153.97:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-08-16 19:05:07",
            "last_seen_utc": "2026-08-31 07:43:24",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "mythic",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1877129": [
        {
            "ioc_value": "185.34.147.34:21",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-08-16 13:05:07",
            "last_seen_utc": "2026-08-31 07:44:55",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "asyncrat",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1876883": [
        {
            "ioc_value": "217.60.195.110:56002",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-16 13:04:44",
            "last_seen_utc": "2026-08-31 07:46:33",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "",
            "tags": "PureHVNC,PureRAT,ResolverRAT",
            "anonymous": 0,
            "reporter": "whoamix302"
        }
    ],
    "1876882": [
        {
            "ioc_value": "217.60.195.110:56001",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-16 13:04:43",
            "last_seen_utc": "2026-08-31 07:46:33",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "",
            "tags": "PureHVNC,PureRAT,ResolverRAT",
            "anonymous": 0,
            "reporter": "whoamix302"
        }
    ],
    "1876897": [
        {
            "ioc_value": "150.109.93.78:8443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.aisuru",
            "malware_alias": null,
            "malware_printable": "Aisuru",
            "first_seen_utc": "2026-08-16 13:03:50",
            "last_seen_utc": "2026-08-31 06:43:24",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "Aisuru,c2",
            "anonymous": 0,
            "reporter": "Bitsight"
        }
    ],
    "1876984": [
        {
            "ioc_value": "43.128.113.133:8080",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.aisuru",
            "malware_alias": null,
            "malware_printable": "Aisuru",
            "first_seen_utc": "2026-08-16 13:03:33",
            "last_seen_utc": "2026-08-31 04:34:50",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "Aisuru,c2",
            "anonymous": 0,
            "reporter": "Bitsight"
        }
    ],
    "1877037": [
        {
            "ioc_value": "176.98.182.216:8080",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.aisuru",
            "malware_alias": null,
            "malware_printable": "Aisuru",
            "first_seen_utc": "2026-08-16 13:03:28",
            "last_seen_utc": "2026-08-30 13:10:17",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "Aisuru,c2",
            "anonymous": 0,
            "reporter": "Bitsight"
        }
    ],
    "1877040": [
        {
            "ioc_value": "45.145.41.185:56001",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-16 13:03:28",
            "last_seen_utc": "2026-08-31 07:47:09",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "",
            "tags": "PureHVNC,PureRAT,ResolverRAT",
            "anonymous": 0,
            "reporter": "whoamix302"
        }
    ],
    "1877041": [
        {
            "ioc_value": "172.98.22.177:56001",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-16 13:03:28",
            "last_seen_utc": "2026-08-31 07:44:29",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "",
            "tags": "PureHVNC,PureRAT,ResolverRAT",
            "anonymous": 0,
            "reporter": "whoamix302"
        }
    ],
    "1877051": [
        {
            "ioc_value": "150.109.93.78:9035",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.aisuru",
            "malware_alias": null,
            "malware_printable": "Aisuru",
            "first_seen_utc": "2026-08-16 13:03:26",
            "last_seen_utc": "2026-08-30 14:52:43",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "Aisuru,c2",
            "anonymous": 0,
            "reporter": "Bitsight"
        }
    ],
    "1876556": [
        {
            "ioc_value": "http://158.94.209.112/",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.stealc",
            "malware_alias": null,
            "malware_printable": "Stealc",
            "first_seen_utc": "2026-08-16 13:03:09",
            "last_seen_utc": "2026-08-31 07:55:43",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "c2,loader,StealC,stealer,V1",
            "anonymous": 0,
            "reporter": "Bitsight"
        }
    ],
    "1876789": [
        {
            "ioc_value": "43.129.180.120:8443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.aisuru",
            "malware_alias": null,
            "malware_printable": "Aisuru",
            "first_seen_utc": "2026-08-16 13:03:07",
            "last_seen_utc": "2026-08-31 01:50:46",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "Aisuru,c2",
            "anonymous": 0,
            "reporter": "Bitsight"
        }
    ],
    "1877094": [
        {
            "ioc_value": "47.242.248.156:30001",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-08-16 11:47:14",
            "last_seen_utc": "2026-08-31 07:48:53",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1877059": [
        {
            "ioc_value": "45.156.87.224:8443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-08-16 09:45:53",
            "last_seen_utc": "2026-08-31 07:47:10",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1877058": [
        {
            "ioc_value": "31.59.137.24:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-16 09:45:38",
            "last_seen_utc": "2026-08-31 07:46:48",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1877057": [
        {
            "ioc_value": "217.60.195.195:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-16 09:45:26",
            "last_seen_utc": "2026-08-31 07:46:34",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1877056": [
        {
            "ioc_value": "217.60.195.110:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-16 09:45:25",
            "last_seen_utc": "2026-08-31 07:46:33",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1877055": [
        {
            "ioc_value": "194.59.31.11:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-16 09:44:29",
            "last_seen_utc": "2026-08-31 07:45:20",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1877054": [
        {
            "ioc_value": "193.161.193.99:35711",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-08-16 09:44:26",
            "last_seen_utc": "2026-08-31 07:45:13",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1877053": [
        {
            "ioc_value": "192.162.199.185:38492",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-08-16 09:44:24",
            "last_seen_utc": "2026-08-31 07:45:06",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1877052": [
        {
            "ioc_value": "135.136.147.86:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-16 09:43:30",
            "last_seen_utc": "2026-08-31 07:43:43",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1877003": [
        {
            "ioc_value": "2.27.63.244:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-08-16 05:05:05",
            "last_seen_utc": "2026-08-31 07:45:35",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "mythic",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1876997": [
        {
            "ioc_value": "155.117.155.237:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-08-16 04:05:05",
            "last_seen_utc": "2026-08-31 07:44:00",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "mythic",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1876969": [
        {
            "ioc_value": "149.88.66.234:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-08-16 01:05:07",
            "last_seen_utc": "2026-08-31 07:48:34",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "cobaltstrike",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1876960": [
        {
            "ioc_value": "149.88.66.234:2020",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-08-15 23:46:23",
            "last_seen_utc": "2026-08-31 07:48:34",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1876823": [
        {
            "ioc_value": "91.236.230.143:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-08-15 19:46:52",
            "last_seen_utc": "2026-08-31 07:47:58",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1876822": [
        {
            "ioc_value": "89.37.100.205:56003",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-15 19:46:50",
            "last_seen_utc": "2026-08-31 07:47:55",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1876817": [
        {
            "ioc_value": "64.176.199.134:8443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.havoc",
            "malware_alias": "Havokiz",
            "malware_printable": "Havoc",
            "first_seen_utc": "2026-08-15 19:46:32",
            "last_seen_utc": "2026-08-31 07:47:33",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Havoc",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1876816": [
        {
            "ioc_value": "62.171.166.237:44300",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.havoc",
            "malware_alias": "Havokiz",
            "malware_printable": "Havoc",
            "first_seen_utc": "2026-08-15 19:46:31",
            "last_seen_utc": "2026-08-31 07:47:32",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Havoc",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1876814": [
        {
            "ioc_value": "45.154.98.207:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.evilginx",
            "malware_alias": null,
            "malware_printable": "Evilginx",
            "first_seen_utc": "2026-08-15 19:46:12",
            "last_seen_utc": "2026-08-31 07:47:10",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Evilginx,EvilGoPhish",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1876813": [
        {
            "ioc_value": "38.60.253.24:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.dcrat",
            "malware_alias": "DarkCrystal RAT",
            "malware_printable": "DCRat",
            "first_seen_utc": "2026-08-15 19:46:05",
            "last_seen_utc": "2026-08-31 07:47:00",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DCRat,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1876812": [
        {
            "ioc_value": "31.59.137.24:56003",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-15 19:45:56",
            "last_seen_utc": "2026-08-31 07:46:49",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1876811": [
        {
            "ioc_value": "31.59.137.166:56001",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-15 19:45:55",
            "last_seen_utc": "2026-08-31 07:46:48",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1876809": [
        {
            "ioc_value": "217.60.195.40:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-15 19:45:43",
            "last_seen_utc": "2026-08-31 07:46:36",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1876810": [
        {
            "ioc_value": "217.60.195.40:56003",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-15 19:45:43",
            "last_seen_utc": "2026-08-31 07:46:36",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1876808": [
        {
            "ioc_value": "217.60.195.197:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-15 19:45:42",
            "last_seen_utc": "2026-08-31 07:46:35",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1876806": [
        {
            "ioc_value": "195.177.94.19:56001",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-15 19:44:44",
            "last_seen_utc": "2026-08-31 07:45:24",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1876807": [
        {
            "ioc_value": "195.177.94.19:56002",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-15 19:44:44",
            "last_seen_utc": "2026-08-31 07:45:24",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1876805": [
        {
            "ioc_value": "185.34.147.35:6606",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-08-15 19:44:33",
            "last_seen_utc": "2026-08-31 07:44:56",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1876803": [
        {
            "ioc_value": "185.34.147.33:6606",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-08-15 19:44:32",
            "last_seen_utc": "2026-08-31 07:44:54",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1876804": [
        {
            "ioc_value": "185.34.147.34:6606",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-08-15 19:44:32",
            "last_seen_utc": "2026-08-31 07:44:55",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1876802": [
        {
            "ioc_value": "185.34.147.32:6606",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-08-15 19:44:31",
            "last_seen_utc": "2026-08-31 07:44:53",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1876801": [
        {
            "ioc_value": "185.34.147.31:6606",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-08-15 19:44:30",
            "last_seen_utc": "2026-08-31 07:44:52",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1876800": [
        {
            "ioc_value": "172.86.77.50:5656",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.dcrat",
            "malware_alias": "DarkCrystal RAT",
            "malware_printable": "DCRat",
            "first_seen_utc": "2026-08-15 19:44:11",
            "last_seen_utc": "2026-08-31 07:44:27",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DCRat,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1876799": [
        {
            "ioc_value": "153.52.176.60:56003",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-15 19:43:46",
            "last_seen_utc": "2026-08-31 07:43:56",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1876797": [
        {
            "ioc_value": "153.52.176.60:56001",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-15 19:43:45",
            "last_seen_utc": "2026-08-31 07:43:56",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1876798": [
        {
            "ioc_value": "153.52.176.60:56002",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-15 19:43:45",
            "last_seen_utc": "2026-08-31 07:43:56",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1876796": [
        {
            "ioc_value": "143.110.197.12:65000",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-08-15 19:43:38",
            "last_seen_utc": "2026-08-31 07:43:48",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1876795": [
        {
            "ioc_value": "124.198.131.110:56003",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-15 19:43:25",
            "last_seen_utc": "2026-08-31 07:43:35",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1876794": [
        {
            "ioc_value": "109.227.57.186:4433",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.danabot",
            "malware_alias": "DanaTools",
            "malware_printable": "DanaBot",
            "first_seen_utc": "2026-08-15 19:43:20",
            "last_seen_utc": "2026-08-31 07:43:27",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DanBot,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1876793": [
        {
            "ioc_value": "107.173.177.168:56003",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-15 19:43:16",
            "last_seen_utc": "2026-08-31 07:43:23",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1876791": [
        {
            "ioc_value": "102.117.167.183:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-08-15 19:05:05",
            "last_seen_utc": "2026-08-31 07:43:05",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "mythic",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1875029": [
        {
            "ioc_value": "176.98.182.218:8443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.aisuru",
            "malware_alias": null,
            "malware_printable": "Aisuru",
            "first_seen_utc": "2026-08-15 15:42:48",
            "last_seen_utc": "2026-08-31 03:28:56",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "Aisuru,c2",
            "anonymous": 0,
            "reporter": "Bitsight"
        }
    ],
    "1875086": [
        {
            "ioc_value": "150.109.93.78:8001",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.aisuru",
            "malware_alias": null,
            "malware_printable": "Aisuru",
            "first_seen_utc": "2026-08-15 15:42:44",
            "last_seen_utc": "2026-08-31 07:16:57",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "Aisuru,c2",
            "anonymous": 0,
            "reporter": "Bitsight"
        }
    ],
    "1875087": [
        {
            "ioc_value": "43.128.113.133:8001",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.aisuru",
            "malware_alias": null,
            "malware_printable": "Aisuru",
            "first_seen_utc": "2026-08-15 15:42:44",
            "last_seen_utc": "2026-08-31 07:51:29",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "Aisuru,c2",
            "anonymous": 0,
            "reporter": "Bitsight"
        }
    ],
    "1875088": [
        {
            "ioc_value": "43.129.180.120:8001",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.aisuru",
            "malware_alias": null,
            "malware_printable": "Aisuru",
            "first_seen_utc": "2026-08-15 15:42:43",
            "last_seen_utc": "2026-08-31 07:50:40",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "Aisuru,c2",
            "anonymous": 0,
            "reporter": "Bitsight"
        }
    ],
    "1875089": [
        {
            "ioc_value": "43.134.49.218:8001",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.aisuru",
            "malware_alias": null,
            "malware_printable": "Aisuru",
            "first_seen_utc": "2026-08-15 15:42:43",
            "last_seen_utc": "2026-08-31 07:51:56",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "Aisuru,c2",
            "anonymous": 0,
            "reporter": "Bitsight"
        }
    ],
    "1876044": [
        {
            "ioc_value": "176.98.182.218:8080",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.aisuru",
            "malware_alias": null,
            "malware_printable": "Aisuru",
            "first_seen_utc": "2026-08-15 15:42:34",
            "last_seen_utc": "2026-08-30 11:01:57",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "Aisuru,c2",
            "anonymous": 0,
            "reporter": "Bitsight"
        }
    ],
    "1876137": [
        {
            "ioc_value": "176.98.182.177:8443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.aisuru",
            "malware_alias": null,
            "malware_printable": "Aisuru",
            "first_seen_utc": "2026-08-15 15:42:27",
            "last_seen_utc": "2026-08-31 07:16:02",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "Aisuru,c2",
            "anonymous": 0,
            "reporter": "Bitsight"
        }
    ],
    "1876160": [
        {
            "ioc_value": "176.98.182.216:8443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.aisuru",
            "malware_alias": null,
            "malware_printable": "Aisuru",
            "first_seen_utc": "2026-08-15 15:42:24",
            "last_seen_utc": "2026-08-31 03:27:21",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "Aisuru,c2",
            "anonymous": 0,
            "reporter": "Bitsight"
        }
    ],
    "1876188": [
        {
            "ioc_value": "43.134.49.218:8443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.aisuru",
            "malware_alias": null,
            "malware_printable": "Aisuru",
            "first_seen_utc": "2026-08-15 15:42:23",
            "last_seen_utc": "2026-08-31 07:16:27",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "Aisuru,c2",
            "anonymous": 0,
            "reporter": "Bitsight"
        }
    ],
    "1876365": [
        {
            "ioc_value": "http://160.20.109.90/",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.stealc",
            "malware_alias": null,
            "malware_printable": "Stealc",
            "first_seen_utc": "2026-08-15 15:41:43",
            "last_seen_utc": "2026-08-31 07:56:42",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "c2,loader,newbuild,StealC,stealer",
            "anonymous": 0,
            "reporter": "Bitsight"
        }
    ],
    "1876375": [
        {
            "ioc_value": "209.38.82.72:9048",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remus",
            "malware_alias": null,
            "malware_printable": "Remus",
            "first_seen_utc": "2026-08-15 15:41:38",
            "last_seen_utc": "2026-08-31 07:31:18",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "0f81469cc7638ba7c82eaddbd6b3c20a,c2,remus",
            "anonymous": 0,
            "reporter": "Bitsight"
        }
    ],
    "1876366": [
        {
            "ioc_value": "31.171.131.250:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-08-15 12:05:06",
            "last_seen_utc": "2026-08-31 07:46:45",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "mythic",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1876320": [
        {
            "ioc_value": "91.92.243.114:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-15 09:46:30",
            "last_seen_utc": "2026-08-31 07:47:59",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1876319": [
        {
            "ioc_value": "64.94.84.119:4321",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-08-15 09:46:15",
            "last_seen_utc": "2026-08-31 07:47:37",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1876318": [
        {
            "ioc_value": "62.171.166.237:8080",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.havoc",
            "malware_alias": "Havokiz",
            "malware_printable": "Havoc",
            "first_seen_utc": "2026-08-15 09:46:11",
            "last_seen_utc": "2026-08-31 07:47:33",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Havoc",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1876317": [
        {
            "ioc_value": "45.61.177.23:2030",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.evilginx",
            "malware_alias": null,
            "malware_printable": "Evilginx",
            "first_seen_utc": "2026-08-15 09:45:57",
            "last_seen_utc": "2026-08-31 07:47:16",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Evilginx,EvilGoPhish",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1876316": [
        {
            "ioc_value": "45.154.98.207:8443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.evilginx",
            "malware_alias": null,
            "malware_printable": "Evilginx",
            "first_seen_utc": "2026-08-15 09:45:51",
            "last_seen_utc": "2026-08-31 07:47:10",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Evilginx,EvilGoPhish",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1876315": [
        {
            "ioc_value": "38.147.162.163:15087",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-08-15 09:45:42",
            "last_seen_utc": "2026-08-31 07:46:56",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1876314": [
        {
            "ioc_value": "23.175.48.7:7707",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-08-15 09:45:31",
            "last_seen_utc": "2026-08-31 07:46:40",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1876313": [
        {
            "ioc_value": "194.182.87.116:4321",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-08-15 09:44:31",
            "last_seen_utc": "2026-08-31 07:45:16",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1876312": [
        {
            "ioc_value": "177.22.119.159:9001",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.danabot",
            "malware_alias": "DanaTools",
            "malware_printable": "DanaBot",
            "first_seen_utc": "2026-08-15 09:44:09",
            "last_seen_utc": "2026-08-31 07:44:33",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DanBot,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1876311": [
        {
            "ioc_value": "176.44.51.156:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.havoc",
            "malware_alias": "Havokiz",
            "malware_printable": "Havoc",
            "first_seen_utc": "2026-08-15 09:44:08",
            "last_seen_utc": "2026-08-31 07:44:30",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Havoc",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1876309": [
        {
            "ioc_value": "155.94.150.221:6745",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-08-15 09:43:45",
            "last_seen_utc": "2026-08-31 07:44:02",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1876308": [
        {
            "ioc_value": "147.45.61.65:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-15 09:43:39",
            "last_seen_utc": "2026-08-31 07:43:51",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1876307": [
        {
            "ioc_value": "144.124.234.128:49999",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-08-15 09:43:37",
            "last_seen_utc": "2026-08-31 07:43:49",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1876306": [
        {
            "ioc_value": "123.136.92.100:49999",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-08-15 09:43:24",
            "last_seen_utc": "2026-08-31 07:43:35",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1876305": [
        {
            "ioc_value": "111.228.13.59:18443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-08-15 09:43:20",
            "last_seen_utc": "2026-08-31 07:43:29",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1876304": [
        {
            "ioc_value": "104.243.248.63:306",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-08-15 09:43:13",
            "last_seen_utc": "2026-08-31 07:43:16",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1876303": [
        {
            "ioc_value": "104.194.132.192:24432",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-08-15 09:43:10",
            "last_seen_utc": "2026-08-31 07:43:13",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1876285": [
        {
            "ioc_value": "93.95.227.51:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-08-15 09:05:05",
            "last_seen_utc": "2026-08-31 07:48:06",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "mythic",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1876169": [
        {
            "ioc_value": "47.84.15.240:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-08-14 23:46:57",
            "last_seen_utc": "2026-08-31 07:48:53",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1876084": [
        {
            "ioc_value": "94.143.231.61:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-14 19:46:43",
            "last_seen_utc": "2026-08-31 07:48:06",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1876083": [
        {
            "ioc_value": "91.92.43.103:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "js.tsundere",
            "malware_alias": "DinDoor",
            "malware_printable": "Tsundere",
            "first_seen_utc": "2026-08-14 19:46:41",
            "last_seen_utc": "2026-08-31 07:48:00",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DinDoor,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1876082": [
        {
            "ioc_value": "78.17.213.180:1907",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.dcrat",
            "malware_alias": "DarkCrystal RAT",
            "malware_printable": "DCRat",
            "first_seen_utc": "2026-08-14 19:46:27",
            "last_seen_utc": "2026-08-31 07:47:42",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DCRat,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1876081": [
        {
            "ioc_value": "64.89.161.196:4444",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.dcrat",
            "malware_alias": "DarkCrystal RAT",
            "malware_printable": "DCRat",
            "first_seen_utc": "2026-08-14 19:46:22",
            "last_seen_utc": "2026-08-31 07:47:37",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DCRat,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1876080": [
        {
            "ioc_value": "64.227.74.35:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-08-14 19:46:21",
            "last_seen_utc": "2026-08-31 07:47:35",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1876079": [
        {
            "ioc_value": "46.149.68.224:8443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.bianlian",
            "malware_alias": null,
            "malware_printable": "BianLian",
            "first_seen_utc": "2026-08-14 19:46:07",
            "last_seen_utc": "2026-08-31 07:47:20",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "Bianlian,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1876078": [
        {
            "ioc_value": "45.157.233.139:7000",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-14 19:45:58",
            "last_seen_utc": "2026-08-31 07:47:11",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1876077": [
        {
            "ioc_value": "23.175.48.7:8808",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-08-14 19:45:36",
            "last_seen_utc": "2026-08-31 07:46:40",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1876076": [
        {
            "ioc_value": "212.103.26.10:55000",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.havoc",
            "malware_alias": "Havokiz",
            "malware_printable": "Havoc",
            "first_seen_utc": "2026-08-14 19:44:53",
            "last_seen_utc": "2026-08-31 07:45:50",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Havoc",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1876073": [
        {
            "ioc_value": "2.59.133.115:56001",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-14 19:44:43",
            "last_seen_utc": "2026-08-31 07:45:36",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1876074": [
        {
            "ioc_value": "2.59.133.115:56002",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-14 19:44:43",
            "last_seen_utc": "2026-08-31 07:45:36",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1876075": [
        {
            "ioc_value": "2.59.133.115:56003",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-14 19:44:43",
            "last_seen_utc": "2026-08-31 07:45:36",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1876072": [
        {
            "ioc_value": "2.27.248.16:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "js.tsundere",
            "malware_alias": "DinDoor",
            "malware_printable": "Tsundere",
            "first_seen_utc": "2026-08-14 19:44:41",
            "last_seen_utc": "2026-08-31 07:45:34",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DinDoor,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1876071": [
        {
            "ioc_value": "198.199.74.231:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-08-14 19:44:38",
            "last_seen_utc": "2026-08-31 07:45:30",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1876070": [
        {
            "ioc_value": "195.177.94.41:56003",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-14 19:44:36",
            "last_seen_utc": "2026-08-31 07:45:26",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1876067": [
        {
            "ioc_value": "185.112.147.233:31337",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.sliver",
            "malware_alias": null,
            "malware_printable": "Sliver",
            "first_seen_utc": "2026-08-14 19:44:16",
            "last_seen_utc": "2026-08-31 07:44:40",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Sliver",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1876068": [
        {
            "ioc_value": "185.112.147.233:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.sliver",
            "malware_alias": null,
            "malware_printable": "Sliver",
            "first_seen_utc": "2026-08-14 19:44:16",
            "last_seen_utc": "2026-08-31 07:44:41",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Sliver",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1876066": [
        {
            "ioc_value": "178.16.52.136:3009",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-08-14 19:44:10",
            "last_seen_utc": "2026-08-31 07:44:33",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1876065": [
        {
            "ioc_value": "176.65.139.232:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.mirai",
            "malware_alias": "Katana",
            "malware_printable": "Mirai",
            "first_seen_utc": "2026-08-14 19:44:08",
            "last_seen_utc": "2026-08-31 07:44:31",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mirai",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1876064": [
        {
            "ioc_value": "172.236.157.30:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-14 19:44:01",
            "last_seen_utc": "2026-08-31 07:44:22",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1876063": [
        {
            "ioc_value": "147.45.61.65:56001",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-14 19:43:39",
            "last_seen_utc": "2026-08-31 07:43:51",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1876062": [
        {
            "ioc_value": "147.124.223.225:56003",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-14 19:43:38",
            "last_seen_utc": "2026-08-31 07:43:51",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1876061": [
        {
            "ioc_value": "128.90.63.117:4444",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-08-14 19:43:26",
            "last_seen_utc": "2026-08-31 07:43:38",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1876059": [
        {
            "ioc_value": "108.187.7.173:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-14 19:43:18",
            "last_seen_utc": "2026-08-31 07:43:26",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1876060": [
        {
            "ioc_value": "108.187.7.180:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-14 19:43:18",
            "last_seen_utc": "2026-08-31 07:43:27",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1876058": [
        {
            "ioc_value": "104.164.46.182:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-14 19:43:10",
            "last_seen_utc": "2026-08-31 07:43:13",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1876057": [
        {
            "ioc_value": "102.117.165.168:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-08-14 19:43:04",
            "last_seen_utc": "2026-08-31 07:43:04",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1876046": [
        {
            "ioc_value": "45.66.248.156:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-08-14 19:05:07",
            "last_seen_utc": "2026-08-31 07:47:17",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "mythic",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1874713": [
        {
            "ioc_value": "117.72.159.96:9998",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-08-14 11:47:34",
            "last_seen_utc": "2026-08-31 07:48:28",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1874678": [
        {
            "ioc_value": "63.141.237.101:7707",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-08-14 09:46:18",
            "last_seen_utc": "2026-08-31 07:47:33",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1874677": [
        {
            "ioc_value": "45.74.6.146:8848",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.dcrat",
            "malware_alias": "DarkCrystal RAT",
            "malware_printable": "DCRat",
            "first_seen_utc": "2026-08-14 09:45:58",
            "last_seen_utc": "2026-08-31 07:47:17",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DCRat,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1874676": [
        {
            "ioc_value": "23.111.14.80:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-14 09:45:27",
            "last_seen_utc": "2026-08-31 07:46:39",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1874675": [
        {
            "ioc_value": "217.60.241.247:7707",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-08-14 09:45:24",
            "last_seen_utc": "2026-08-31 07:46:36",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1874672": [
        {
            "ioc_value": "207.56.26.118:4321",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-08-14 09:44:42",
            "last_seen_utc": "2026-08-31 07:45:45",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1874673": [
        {
            "ioc_value": "207.56.26.121:4321",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-08-14 09:44:42",
            "last_seen_utc": "2026-08-31 07:45:45",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1874671": [
        {
            "ioc_value": "198.23.185.238:30305",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-08-14 09:44:32",
            "last_seen_utc": "2026-08-31 07:45:30",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1874670": [
        {
            "ioc_value": "128.90.108.184:8848",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.dcrat",
            "malware_alias": "DarkCrystal RAT",
            "malware_printable": "DCRat",
            "first_seen_utc": "2026-08-14 09:43:24",
            "last_seen_utc": "2026-08-31 07:43:37",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DCRat,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1874669": [
        {
            "ioc_value": "117.24.4.112:3333",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-08-14 09:43:21",
            "last_seen_utc": "2026-08-31 07:43:32",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1874668": [
        {
            "ioc_value": "104.251.180.164:55009",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-14 09:43:13",
            "last_seen_utc": "2026-08-31 07:43:19",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1874667": [
        {
            "ioc_value": "103.51.145.75:4321",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-08-14 09:43:07",
            "last_seen_utc": "2026-08-31 07:43:10",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1874661": [
        {
            "ioc_value": "172.188.0.134:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.havoc",
            "malware_alias": "Havokiz",
            "malware_printable": "Havoc",
            "first_seen_utc": "2026-08-14 09:05:09",
            "last_seen_utc": "2026-08-31 07:44:22",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "havoc",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1873910": [
        {
            "ioc_value": "176.98.182.217:8001",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.aisuru",
            "malware_alias": null,
            "malware_printable": "Aisuru",
            "first_seen_utc": "2026-08-14 06:20:07",
            "last_seen_utc": "2026-08-31 07:48:59",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "Aisuru,c2",
            "anonymous": 0,
            "reporter": "Bitsight"
        }
    ],
    "1873911": [
        {
            "ioc_value": "176.98.182.177:8001",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.aisuru",
            "malware_alias": null,
            "malware_printable": "Aisuru",
            "first_seen_utc": "2026-08-14 06:20:06",
            "last_seen_utc": "2026-08-31 06:45:07",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "Aisuru,c2",
            "anonymous": 0,
            "reporter": "Bitsight"
        }
    ],
    "1873912": [
        {
            "ioc_value": "176.98.182.218:8001",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.aisuru",
            "malware_alias": null,
            "malware_printable": "Aisuru",
            "first_seen_utc": "2026-08-14 06:20:06",
            "last_seen_utc": "2026-08-31 07:51:43",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "Aisuru,c2",
            "anonymous": 0,
            "reporter": "Bitsight"
        }
    ],
    "1873913": [
        {
            "ioc_value": "176.98.182.216:8001",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.aisuru",
            "malware_alias": null,
            "malware_printable": "Aisuru",
            "first_seen_utc": "2026-08-14 06:20:06",
            "last_seen_utc": "2026-08-31 07:47:35",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "Aisuru,c2",
            "anonymous": 0,
            "reporter": "Bitsight"
        }
    ],
    "1874176": [
        {
            "ioc_value": "176.98.182.217:8443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.aisuru",
            "malware_alias": null,
            "malware_printable": "Aisuru",
            "first_seen_utc": "2026-08-14 06:18:51",
            "last_seen_utc": "2026-08-31 07:17:32",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "Aisuru,c2",
            "anonymous": 0,
            "reporter": "Bitsight"
        }
    ],
    "1874208": [
        {
            "ioc_value": "20.187.120.42:8080",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-08-14 06:05:07",
            "last_seen_utc": "2026-08-31 07:48:43",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "cobaltstrike",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1874171": [
        {
            "ioc_value": "169.58.31.140:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-08-14 04:05:06",
            "last_seen_utc": "2026-08-31 07:44:18",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "mythic",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1874136": [
        {
            "ioc_value": "169.58.31.140:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-08-14 03:05:04",
            "last_seen_utc": "2026-08-31 07:44:19",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "mythic",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1873953": [
        {
            "ioc_value": "145.223.93.74:7748",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remus",
            "malware_alias": null,
            "malware_printable": "Remus",
            "first_seen_utc": "2026-08-14 00:05:43",
            "last_seen_utc": "2026-08-31 08:08:58",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://bazaar.abuse.ch/sample/949d52a103ea1b3c8752abf5cdcdfe58363b157d031cb78c99f1e45029bfbcb5/",
            "tags": "remus",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1873917": [
        {
            "ioc_value": "185.92.190.175:8896",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-08-13 23:46:59",
            "last_seen_utc": "2026-08-31 07:48:41",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1873916": [
        {
            "ioc_value": "113.52.135.27:19666",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-08-13 23:46:48",
            "last_seen_utc": "2026-08-31 07:48:26",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1873849": [
        {
            "ioc_value": "85.208.69.45:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.bianlian",
            "malware_alias": null,
            "malware_printable": "BianLian",
            "first_seen_utc": "2026-08-13 19:46:44",
            "last_seen_utc": "2026-08-31 07:47:50",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "Bianlian,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1873847": [
        {
            "ioc_value": "64.89.161.181:56001",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-13 19:46:34",
            "last_seen_utc": "2026-08-31 07:47:36",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1873848": [
        {
            "ioc_value": "64.89.161.181:56002",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-13 19:46:34",
            "last_seen_utc": "2026-08-31 07:47:36",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1873846": [
        {
            "ioc_value": "63.141.237.101:8808",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-08-13 19:46:32",
            "last_seen_utc": "2026-08-31 07:47:33",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1873845": [
        {
            "ioc_value": "63.141.237.101:6606",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-08-13 19:46:31",
            "last_seen_utc": "2026-08-31 07:47:33",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1873844": [
        {
            "ioc_value": "46.246.4.16:7049",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-08-13 19:46:22",
            "last_seen_utc": "2026-08-31 07:47:22",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1873843": [
        {
            "ioc_value": "45.88.91.74:7580",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-08-13 19:46:19",
            "last_seen_utc": "2026-08-31 07:47:19",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1873841": [
        {
            "ioc_value": "217.60.195.226:56003",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-13 19:45:43",
            "last_seen_utc": "2026-08-31 07:46:35",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1873842": [
        {
            "ioc_value": "217.60.241.247:6606",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-08-13 19:45:43",
            "last_seen_utc": "2026-08-31 07:46:36",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1873839": [
        {
            "ioc_value": "216.118.235.66:4321",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-08-13 19:45:40",
            "last_seen_utc": "2026-08-31 07:46:31",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1873840": [
        {
            "ioc_value": "216.118.235.69:4321",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-08-13 19:45:40",
            "last_seen_utc": "2026-08-31 07:46:31",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1873838": [
        {
            "ioc_value": "177.22.117.81:9001",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.danabot",
            "malware_alias": "DanaTools",
            "malware_printable": "DanaBot",
            "first_seen_utc": "2026-08-13 19:44:16",
            "last_seen_utc": "2026-08-31 07:44:32",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DanBot,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1873837": [
        {
            "ioc_value": "172.86.72.75:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-08-13 19:44:12",
            "last_seen_utc": "2026-08-31 07:44:27",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1873836": [
        {
            "ioc_value": "147.45.61.65:56003",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-13 19:43:43",
            "last_seen_utc": "2026-08-31 07:43:52",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1873831": [
        {
            "ioc_value": "128.90.112.237:6666",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.dcrat",
            "malware_alias": "DarkCrystal RAT",
            "malware_printable": "DCRat",
            "first_seen_utc": "2026-08-13 19:43:29",
            "last_seen_utc": "2026-08-31 07:43:37",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DCRat,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1873830": [
        {
            "ioc_value": "128.90.105.154:8624",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.dcrat",
            "malware_alias": "DarkCrystal RAT",
            "malware_printable": "DCRat",
            "first_seen_utc": "2026-08-13 19:43:28",
            "last_seen_utc": "2026-08-31 07:43:37",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DCRat,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1873826": [
        {
            "ioc_value": "108.187.43.137:56001",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-13 19:43:20",
            "last_seen_utc": "2026-08-31 07:43:26",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1873827": [
        {
            "ioc_value": "108.187.43.137:56002",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-13 19:43:20",
            "last_seen_utc": "2026-08-31 07:43:26",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1873828": [
        {
            "ioc_value": "108.187.43.144:56001",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-13 19:43:20",
            "last_seen_utc": "2026-08-31 07:43:26",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1873829": [
        {
            "ioc_value": "108.187.43.144:56002",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-13 19:43:20",
            "last_seen_utc": "2026-08-31 07:43:26",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1873825": [
        {
            "ioc_value": "104.251.180.164:55006",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-13 19:43:15",
            "last_seen_utc": "2026-08-31 07:43:18",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1873824": [
        {
            "ioc_value": "104.239.66.245:56003",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-13 19:43:13",
            "last_seen_utc": "2026-08-31 07:43:15",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1873823": [
        {
            "ioc_value": "102.117.162.167:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-08-13 19:43:04",
            "last_seen_utc": "2026-08-31 07:43:04",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1873797": [
        {
            "ioc_value": "31.40.204.178:7080",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.hype_agent",
            "malware_alias": null,
            "malware_printable": "HypeAgent",
            "first_seen_utc": "2026-08-13 16:50:12",
            "last_seen_utc": "2026-08-31 07:46:46",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://bazaar.abuse.ch/sample/797f2a8984090b782a158c170edeb51285a57d42df02aaf35e65e082f88e77e0/",
            "tags": "HypeAgent",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1873757": [
        {
            "ioc_value": "4.232.64.244:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-08-13 15:05:05",
            "last_seen_utc": "2026-08-31 07:47:00",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "mythic",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1873640": [
        {
            "ioc_value": "91.92.42.118:13019",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-08-13 11:47:22",
            "last_seen_utc": "2026-08-31 07:48:58",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1873639": [
        {
            "ioc_value": "118.31.18.77:2301",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-08-13 11:46:56",
            "last_seen_utc": "2026-08-31 07:48:29",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1873575": [
        {
            "ioc_value": "91.242.163.227:5174",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-08-13 09:47:21",
            "last_seen_utc": "2026-08-31 07:47:58",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1873574": [
        {
            "ioc_value": "86.124.168.48:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "js.fakeupdates",
            "malware_alias": "FakeUpdate,GhoLoader,SocGholish",
            "malware_printable": "FAKEUPDATES",
            "first_seen_utc": "2026-08-13 09:47:14",
            "last_seen_utc": "2026-08-31 07:47:51",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,SocGholish",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1873573": [
        {
            "ioc_value": "54.54.27.128:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-08-13 09:46:54",
            "last_seen_utc": "2026-08-31 07:47:30",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1873571": [
        {
            "ioc_value": "38.240.57.198:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-13 09:46:22",
            "last_seen_utc": "2026-08-31 07:46:57",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1873570": [
        {
            "ioc_value": "217.60.241.247:7722",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-08-13 09:46:03",
            "last_seen_utc": "2026-08-31 07:46:36",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1873568": [
        {
            "ioc_value": "203.161.55.41:7691",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-08-13 09:45:09",
            "last_seen_utc": "2026-08-31 07:45:41",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1873567": [
        {
            "ioc_value": "202.73.4.82:44321",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-08-13 09:45:08",
            "last_seen_utc": "2026-08-31 07:45:40",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1873566": [
        {
            "ioc_value": "194.76.226.90:4321",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-08-13 09:44:52",
            "last_seen_utc": "2026-08-31 07:45:21",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1873563": [
        {
            "ioc_value": "193.138.195.29:56001",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-13 09:44:48",
            "last_seen_utc": "2026-08-31 07:45:12",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1873564": [
        {
            "ioc_value": "193.138.195.29:56002",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-13 09:44:48",
            "last_seen_utc": "2026-08-31 07:45:12",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1873565": [
        {
            "ioc_value": "193.138.195.29:56003",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-13 09:44:48",
            "last_seen_utc": "2026-08-31 07:45:12",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1873561": [
        {
            "ioc_value": "185.34.147.34:8080",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-08-13 09:44:40",
            "last_seen_utc": "2026-08-31 07:44:56",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1873562": [
        {
            "ioc_value": "185.34.147.35:8080",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-08-13 09:44:40",
            "last_seen_utc": "2026-08-31 07:44:57",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1873559": [
        {
            "ioc_value": "185.34.147.31:8080",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-08-13 09:44:39",
            "last_seen_utc": "2026-08-31 07:44:52",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1873560": [
        {
            "ioc_value": "185.34.147.32:8080",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-08-13 09:44:39",
            "last_seen_utc": "2026-08-31 07:44:53",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1873558": [
        {
            "ioc_value": "185.199.197.93:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-08-13 09:44:32",
            "last_seen_utc": "2026-08-31 07:44:44",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "Covenant,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1873557": [
        {
            "ioc_value": "172.111.134.94:56013",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-13 09:44:13",
            "last_seen_utc": "2026-08-31 07:44:20",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1873556": [
        {
            "ioc_value": "154.36.188.233:8080",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.havoc",
            "malware_alias": "Havokiz",
            "malware_printable": "Havoc",
            "first_seen_utc": "2026-08-13 09:43:51",
            "last_seen_utc": "2026-08-31 07:43:59",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Havoc",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1873555": [
        {
            "ioc_value": "139.180.136.200:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-08-13 09:43:39",
            "last_seen_utc": "2026-08-31 07:43:46",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1873554": [
        {
            "ioc_value": "130.12.182.39:2500",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-08-13 09:43:32",
            "last_seen_utc": "2026-08-31 07:43:40",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1873553": [
        {
            "ioc_value": "103.54.153.49:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-13 09:43:10",
            "last_seen_utc": "2026-08-31 07:43:10",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1873552": [
        {
            "ioc_value": "103.182.16.169:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.dcrat",
            "malware_alias": "DarkCrystal RAT",
            "malware_printable": "DCRat",
            "first_seen_utc": "2026-08-13 09:43:08",
            "last_seen_utc": "2026-08-31 07:43:08",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DCRat,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1873504": [
        {
            "ioc_value": "http://91.92.34.11/",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.stealc",
            "malware_alias": null,
            "malware_printable": "Stealc",
            "first_seen_utc": "2026-08-13 08:30:34",
            "last_seen_utc": "2026-08-31 08:07:02",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "c2,flka,loader,StealC,stealer",
            "anonymous": 0,
            "reporter": "Bitsight"
        }
    ],
    "1873444": [
        {
            "ioc_value": "198.199.86.166:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-08-13 06:05:05",
            "last_seen_utc": "2026-08-31 07:45:30",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "mythic",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1873415": [
        {
            "ioc_value": "http://91.202.233.163/",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.stealc",
            "malware_alias": null,
            "malware_printable": "Stealc",
            "first_seen_utc": "2026-08-13 05:53:05",
            "last_seen_utc": "2026-08-31 08:09:21",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "321LL,c2,loader,StealC,stealer",
            "anonymous": 0,
            "reporter": "Bitsight"
        }
    ],
    "1873416": [
        {
            "ioc_value": "https://fbdfsgfwrgerwefew.top/",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.stealc",
            "malware_alias": null,
            "malware_printable": "Stealc",
            "first_seen_utc": "2026-08-13 05:53:04",
            "last_seen_utc": "2026-08-31 07:35:39",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "c2,kard,loader,StealC,stealer",
            "anonymous": 0,
            "reporter": "Bitsight"
        }
    ],
    "1873335": [
        {
            "ioc_value": "120.55.93.58:10092",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-08-12 23:46:54",
            "last_seen_utc": "2026-08-31 07:48:31",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1873334": [
        {
            "ioc_value": "119.45.231.164:4433",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-08-12 23:46:53",
            "last_seen_utc": "2026-08-31 07:48:31",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1873316": [
        {
            "ioc_value": "130.94.30.59:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-08-12 23:05:10",
            "last_seen_utc": "2026-08-31 07:43:42",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "mythic",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1873315": [
        {
            "ioc_value": "185.34.147.33:8080",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-08-12 23:05:05",
            "last_seen_utc": "2026-08-31 07:44:54",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "asyncrat",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1873272": [
        {
            "ioc_value": "89.110.91.35:4321",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-08-12 19:46:45",
            "last_seen_utc": "2026-08-31 07:47:54",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1873270": [
        {
            "ioc_value": "87.58.201.47:56001",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-12 19:46:44",
            "last_seen_utc": "2026-08-31 07:47:53",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1873271": [
        {
            "ioc_value": "87.58.201.47:56002",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-12 19:46:44",
            "last_seen_utc": "2026-08-31 07:47:53",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1873269": [
        {
            "ioc_value": "87.199.206.169:4321",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-08-12 19:46:43",
            "last_seen_utc": "2026-08-31 07:47:52",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1873268": [
        {
            "ioc_value": "80.76.49.54:2244",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-08-12 19:46:38",
            "last_seen_utc": "2026-08-31 07:47:45",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1873267": [
        {
            "ioc_value": "65.21.102.4:4321",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-08-12 19:46:32",
            "last_seen_utc": "2026-08-31 07:47:38",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1873266": [
        {
            "ioc_value": "54.54.33.23:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-08-12 19:46:26",
            "last_seen_utc": "2026-08-31 07:47:31",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1873265": [
        {
            "ioc_value": "46.246.14.7:7049",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-08-12 19:46:19",
            "last_seen_utc": "2026-08-31 07:47:22",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1873264": [
        {
            "ioc_value": "46.246.14.7:2703",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-08-12 19:46:18",
            "last_seen_utc": "2026-08-31 07:47:22",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1873263": [
        {
            "ioc_value": "45.221.97.68:56003",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-12 19:46:09",
            "last_seen_utc": "2026-08-31 07:47:13",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1873261": [
        {
            "ioc_value": "44.251.4.9:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-08-12 19:46:03",
            "last_seen_utc": "2026-08-31 07:47:06",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1873259": [
        {
            "ioc_value": "38.240.57.198:56001",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-12 19:45:56",
            "last_seen_utc": "2026-08-31 07:46:57",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1873260": [
        {
            "ioc_value": "38.240.57.198:56002",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-12 19:45:56",
            "last_seen_utc": "2026-08-31 07:46:58",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1873258": [
        {
            "ioc_value": "3.39.249.68:8443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.havoc",
            "malware_alias": "Havokiz",
            "malware_printable": "Havoc",
            "first_seen_utc": "2026-08-12 19:45:47",
            "last_seen_utc": "2026-08-31 07:46:45",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Havoc",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1873257": [
        {
            "ioc_value": "3.122.223.106:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-08-12 19:45:46",
            "last_seen_utc": "2026-08-31 07:46:45",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1873255": [
        {
            "ioc_value": "23.95.103.215:6606",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-08-12 19:45:44",
            "last_seen_utc": "2026-08-31 07:46:42",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1873256": [
        {
            "ioc_value": "27.124.17.46:442",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-12 19:45:44",
            "last_seen_utc": "2026-08-31 07:46:42",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1873254": [
        {
            "ioc_value": "23.148.228.253:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-08-12 19:45:40",
            "last_seen_utc": "2026-08-31 07:46:39",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1873253": [
        {
            "ioc_value": "217.60.241.247:8808",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-08-12 19:45:37",
            "last_seen_utc": "2026-08-31 07:46:37",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1873249": [
        {
            "ioc_value": "194.59.30.170:1009",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-08-12 19:44:38",
            "last_seen_utc": "2026-08-31 07:45:18",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1873250": [
        {
            "ioc_value": "194.59.30.170:60",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-08-12 19:44:38",
            "last_seen_utc": "2026-08-31 07:45:18",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1873251": [
        {
            "ioc_value": "194.59.30.170:7777",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-08-12 19:44:38",
            "last_seen_utc": "2026-08-31 07:45:18",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1873243": [
        {
            "ioc_value": "185.34.147.32:3306",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-08-12 19:44:28",
            "last_seen_utc": "2026-08-31 07:44:52",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1873244": [
        {
            "ioc_value": "185.34.147.33:21",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-08-12 19:44:28",
            "last_seen_utc": "2026-08-31 07:44:53",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1873245": [
        {
            "ioc_value": "185.34.147.33:3306",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-08-12 19:44:28",
            "last_seen_utc": "2026-08-31 07:44:54",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1873246": [
        {
            "ioc_value": "185.34.147.34:3306",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-08-12 19:44:28",
            "last_seen_utc": "2026-08-31 07:44:55",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1873247": [
        {
            "ioc_value": "185.34.147.35:21",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-08-12 19:44:28",
            "last_seen_utc": "2026-08-31 07:44:56",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1873248": [
        {
            "ioc_value": "185.34.147.35:3306",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-08-12 19:44:28",
            "last_seen_utc": "2026-08-31 07:44:56",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1873240": [
        {
            "ioc_value": "185.34.147.31:21",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-08-12 19:44:27",
            "last_seen_utc": "2026-08-31 07:44:51",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1873241": [
        {
            "ioc_value": "185.34.147.31:3306",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-08-12 19:44:27",
            "last_seen_utc": "2026-08-31 07:44:51",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1873242": [
        {
            "ioc_value": "185.34.147.32:21",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-08-12 19:44:27",
            "last_seen_utc": "2026-08-31 07:44:52",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1873237": [
        {
            "ioc_value": "183.90.187.196:56001",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-12 19:44:18",
            "last_seen_utc": "2026-08-31 07:44:39",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1873238": [
        {
            "ioc_value": "183.90.187.196:56002",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-12 19:44:18",
            "last_seen_utc": "2026-08-31 07:44:39",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1873239": [
        {
            "ioc_value": "183.90.187.196:56003",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-12 19:44:18",
            "last_seen_utc": "2026-08-31 07:44:39",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1873236": [
        {
            "ioc_value": "182.16.29.36:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-12 19:44:17",
            "last_seen_utc": "2026-08-31 07:44:38",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1873235": [
        {
            "ioc_value": "168.222.251.83:56013",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-12 19:44:01",
            "last_seen_utc": "2026-08-31 07:44:17",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1873234": [
        {
            "ioc_value": "158.94.208.101:666",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-08-12 19:43:53",
            "last_seen_utc": "2026-08-31 07:44:07",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1873233": [
        {
            "ioc_value": "149.28.121.179:1337",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.evilginx",
            "malware_alias": null,
            "malware_printable": "Evilginx",
            "first_seen_utc": "2026-08-12 19:43:41",
            "last_seen_utc": "2026-08-31 07:43:52",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Evilginx,EvilGoPhish",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1873232": [
        {
            "ioc_value": "143.92.61.47:4321",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-08-12 19:43:37",
            "last_seen_utc": "2026-08-31 07:43:49",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1873231": [
        {
            "ioc_value": "128.90.59.81:7070",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-08-12 19:43:26",
            "last_seen_utc": "2026-08-31 07:43:38",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1873230": [
        {
            "ioc_value": "117.50.214.216:8000",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-08-12 19:43:23",
            "last_seen_utc": "2026-08-31 07:43:32",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1873229": [
        {
            "ioc_value": "103.149.91.182:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-08-12 19:43:06",
            "last_seen_utc": "2026-08-31 07:43:08",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1873227": [
        {
            "ioc_value": "103.117.149.104:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-08-12 19:43:04",
            "last_seen_utc": "2026-08-31 07:43:06",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1873228": [
        {
            "ioc_value": "103.118.199.85:50555",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "apk.hook",
            "malware_alias": null,
            "malware_printable": "Hook",
            "first_seen_utc": "2026-08-12 19:43:04",
            "last_seen_utc": "2026-08-31 07:43:06",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Hook",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1873148": [
        {
            "ioc_value": "http://95.135.181.73/",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.stealc",
            "malware_alias": null,
            "malware_printable": "Stealc",
            "first_seen_utc": "2026-08-12 17:32:12",
            "last_seen_utc": "2026-08-31 07:48:55",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "c2,loader,Mewwski,StealC,stealer",
            "anonymous": 0,
            "reporter": "Bitsight"
        }
    ],
    "1873032": [
        {
            "ioc_value": "185.100.87.42:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-08-12 13:05:08",
            "last_seen_utc": "2026-08-31 07:44:40",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "asyncrat",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1873018": [
        {
            "ioc_value": "185.100.87.43:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-08-12 12:05:06",
            "last_seen_utc": "2026-08-31 07:44:40",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "asyncrat",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1872712": [
        {
            "ioc_value": "23.95.103.215:7707",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-08-12 09:46:07",
            "last_seen_utc": "2026-08-31 07:46:42",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1872713": [
        {
            "ioc_value": "23.95.103.215:8808",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-08-12 09:46:07",
            "last_seen_utc": "2026-08-31 07:46:42",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1872710": [
        {
            "ioc_value": "209.99.184.151:55006",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-12 09:45:15",
            "last_seen_utc": "2026-08-31 07:45:47",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1872711": [
        {
            "ioc_value": "209.99.184.151:55009",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-12 09:45:15",
            "last_seen_utc": "2026-08-31 07:45:47",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1872709": [
        {
            "ioc_value": "192.229.115.162:56002",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-12 09:44:45",
            "last_seen_utc": "2026-08-31 07:45:08",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1872708": [
        {
            "ioc_value": "192.229.115.154:56002",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-12 09:44:44",
            "last_seen_utc": "2026-08-31 07:45:07",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1872706": [
        {
            "ioc_value": "178.211.155.64:56001",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-12 09:44:25",
            "last_seen_utc": "2026-08-31 07:44:36",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1872705": [
        {
            "ioc_value": "177.22.118.236:9001",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.danabot",
            "malware_alias": "DanaTools",
            "malware_printable": "DanaBot",
            "first_seen_utc": "2026-08-12 09:44:22",
            "last_seen_utc": "2026-08-31 07:44:32",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DanBot,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1872704": [
        {
            "ioc_value": "175.43.223.196:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-08-12 09:44:20",
            "last_seen_utc": "2026-08-31 07:44:30",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1872701": [
        {
            "ioc_value": "172.245.23.153:56001",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-12 09:44:15",
            "last_seen_utc": "2026-08-31 07:44:24",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1872702": [
        {
            "ioc_value": "172.245.23.153:56002",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-12 09:44:15",
            "last_seen_utc": "2026-08-31 07:44:24",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1872703": [
        {
            "ioc_value": "172.245.23.153:56003",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-12 09:44:15",
            "last_seen_utc": "2026-08-31 07:44:24",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1872700": [
        {
            "ioc_value": "158.94.208.101:963",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-08-12 09:44:03",
            "last_seen_utc": "2026-08-31 07:44:07",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1872698": [
        {
            "ioc_value": "158.94.208.101:7707",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-08-12 09:44:01",
            "last_seen_utc": "2026-08-31 07:44:07",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1872699": [
        {
            "ioc_value": "158.94.208.101:777",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-08-12 09:44:01",
            "last_seen_utc": "2026-08-31 07:44:07",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1872696": [
        {
            "ioc_value": "13.236.153.60:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.poshc2",
            "malware_alias": null,
            "malware_printable": "PoshC2",
            "first_seen_utc": "2026-08-12 09:43:32",
            "last_seen_utc": "2026-08-31 07:43:39",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PoshC2",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1872695": [
        {
            "ioc_value": "128.90.105.228:6666",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.dcrat",
            "malware_alias": "DarkCrystal RAT",
            "malware_printable": "DCRat",
            "first_seen_utc": "2026-08-12 09:43:30",
            "last_seen_utc": "2026-08-31 07:43:37",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DCRat,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1872694": [
        {
            "ioc_value": "107.22.41.214:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-08-12 09:43:20",
            "last_seen_utc": "2026-08-31 07:43:24",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1872692": [
        {
            "ioc_value": "107.172.72.178:31337",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.sliver",
            "malware_alias": null,
            "malware_printable": "Sliver",
            "first_seen_utc": "2026-08-12 09:43:19",
            "last_seen_utc": "2026-08-31 07:43:22",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Sliver",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1872693": [
        {
            "ioc_value": "107.172.72.178:54398",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.sliver",
            "malware_alias": null,
            "malware_printable": "Sliver",
            "first_seen_utc": "2026-08-12 09:43:19",
            "last_seen_utc": "2026-08-31 07:43:22",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Sliver",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1872691": [
        {
            "ioc_value": "104.243.248.63:410",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-08-12 09:43:16",
            "last_seen_utc": "2026-08-31 07:43:17",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1872690": [
        {
            "ioc_value": "103.146.231.107:4321",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-08-12 09:43:06",
            "last_seen_utc": "2026-08-31 07:43:07",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1872689": [
        {
            "ioc_value": "103.140.154.7:32333",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-08-12 09:43:05",
            "last_seen_utc": "2026-08-31 07:43:06",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1872624": [
        {
            "ioc_value": "169.58.121.189:4443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-08-12 07:32:50",
            "last_seen_utc": "2026-08-31 07:48:38",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-987654321",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1872592": [
        {
            "ioc_value": "140.82.46.246:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-08-12 06:05:09",
            "last_seen_utc": "2026-08-31 07:43:47",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "mythic",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1872568": [
        {
            "ioc_value": "93.152.223.39:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.havoc",
            "malware_alias": "Havokiz",
            "malware_printable": "Havoc",
            "first_seen_utc": "2026-08-12 05:05:06",
            "last_seen_utc": "2026-08-31 07:48:05",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "havoc",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1872489": [
        {
            "ioc_value": "89.127.233.194:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-08-12 00:05:05",
            "last_seen_utc": "2026-08-31 07:47:54",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "mythic",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1872484": [
        {
            "ioc_value": "159.75.123.199:1111",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-08-11 23:47:15",
            "last_seen_utc": "2026-08-31 07:48:37",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1872483": [
        {
            "ioc_value": "114.67.98.107:54325",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-08-11 23:47:05",
            "last_seen_utc": "2026-08-31 07:48:26",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1872473": [
        {
            "ioc_value": "185.139.214.67:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-08-11 23:05:07",
            "last_seen_utc": "2026-08-31 07:44:41",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "mythic",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1872465": [
        {
            "ioc_value": "188.49.80.159:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.havoc",
            "malware_alias": "Havokiz",
            "malware_printable": "Havoc",
            "first_seen_utc": "2026-08-11 22:05:06",
            "last_seen_utc": "2026-08-31 07:45:00",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "havoc",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1872428": [
        {
            "ioc_value": "91.92.243.36:56003",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-11 19:46:42",
            "last_seen_utc": "2026-08-31 07:47:59",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1872426": [
        {
            "ioc_value": "89.37.100.205:56001",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-11 19:46:40",
            "last_seen_utc": "2026-08-31 07:47:55",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1872427": [
        {
            "ioc_value": "89.37.100.205:56002",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-11 19:46:40",
            "last_seen_utc": "2026-08-31 07:47:55",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1872425": [
        {
            "ioc_value": "87.76.146.221:7771",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-08-11 19:46:37",
            "last_seen_utc": "2026-08-31 07:47:53",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1872424": [
        {
            "ioc_value": "85.137.249.185:25729",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-08-11 19:46:34",
            "last_seen_utc": "2026-08-31 07:47:50",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1872423": [
        {
            "ioc_value": "64.188.69.73:7273",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.netsupportmanager_rat",
            "malware_alias": "NetSupport",
            "malware_printable": "NetSupportManager RAT",
            "first_seen_utc": "2026-08-11 19:46:23",
            "last_seen_utc": "2026-08-31 07:47:34",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,NetSupport,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1872422": [
        {
            "ioc_value": "54.171.35.227:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-08-11 19:46:18",
            "last_seen_utc": "2026-08-31 07:47:29",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1872421": [
        {
            "ioc_value": "45.88.91.103:2244",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-08-11 19:46:09",
            "last_seen_utc": "2026-08-31 07:47:18",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1872420": [
        {
            "ioc_value": "220.154.140.4:9443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-08-11 19:45:34",
            "last_seen_utc": "2026-08-31 07:46:38",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1872419": [
        {
            "ioc_value": "217.60.241.19:8808",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-08-11 19:45:32",
            "last_seen_utc": "2026-08-31 07:46:36",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1872418": [
        {
            "ioc_value": "209.99.184.151:55005",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-11 19:44:49",
            "last_seen_utc": "2026-08-31 07:45:47",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1872417": [
        {
            "ioc_value": "193.221.201.164:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-08-11 19:44:30",
            "last_seen_utc": "2026-08-31 07:45:13",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "Covenant,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1872415": [
        {
            "ioc_value": "182.16.29.35:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-11 19:44:15",
            "last_seen_utc": "2026-08-31 07:44:38",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1872416": [
        {
            "ioc_value": "182.16.29.37:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-11 19:44:15",
            "last_seen_utc": "2026-08-31 07:44:39",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1872414": [
        {
            "ioc_value": "18.171.60.199:9999",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-08-11 19:44:13",
            "last_seen_utc": "2026-08-31 07:44:38",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1872412": [
        {
            "ioc_value": "168.222.251.83:56011",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-11 19:43:59",
            "last_seen_utc": "2026-08-31 07:44:17",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1872411": [
        {
            "ioc_value": "154.40.62.125:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pupy",
            "malware_alias": "Patpoopy",
            "malware_printable": "pupy",
            "first_seen_utc": "2026-08-11 19:43:44",
            "last_seen_utc": "2026-08-31 07:43:59",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PupyRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1872410": [
        {
            "ioc_value": "153.80.249.203:56003",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-11 19:43:42",
            "last_seen_utc": "2026-08-31 07:43:56",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1872409": [
        {
            "ioc_value": "130.12.182.39:5444",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-08-11 19:43:27",
            "last_seen_utc": "2026-08-31 07:43:40",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1872408": [
        {
            "ioc_value": "124.198.131.169:56003",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-11 19:43:25",
            "last_seen_utc": "2026-08-31 07:43:36",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1872406": [
        {
            "ioc_value": "124.198.131.169:56001",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-11 19:43:24",
            "last_seen_utc": "2026-08-31 07:43:36",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1872407": [
        {
            "ioc_value": "124.198.131.169:56002",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-11 19:43:24",
            "last_seen_utc": "2026-08-31 07:43:36",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1872330": [
        {
            "ioc_value": "146.56.227.227:9443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-08-11 15:47:04",
            "last_seen_utc": "2026-08-31 07:48:34",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1872329": [
        {
            "ioc_value": "cf.lala1.lat",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-08-11 15:46:46",
            "last_seen_utc": "2026-08-31 07:48:15",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1872210": [
        {
            "ioc_value": "47.94.224.229:1111",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-08-11 11:48:37",
            "last_seen_utc": "2026-08-31 07:48:54",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1872208": [
        {
            "ioc_value": "36.140.162.173:6666",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-08-11 11:48:28",
            "last_seen_utc": "2026-08-31 07:48:46",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1872161": [
        {
            "ioc_value": "98.156.49.133:2021",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.dcrat",
            "malware_alias": "DarkCrystal RAT",
            "malware_printable": "DCRat",
            "first_seen_utc": "2026-08-11 09:47:24",
            "last_seen_utc": "2026-08-31 07:48:12",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DCRat,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1872159": [
        {
            "ioc_value": "57.181.120.61:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.brute_ratel_c4",
            "malware_alias": "BOLDBADGER,BruteRatel",
            "malware_printable": "Brute Ratel C4",
            "first_seen_utc": "2026-08-11 09:46:52",
            "last_seen_utc": "2026-08-31 07:47:32",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "BruteRatel,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1872158": [
        {
            "ioc_value": "54.54.33.23:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-08-11 09:46:51",
            "last_seen_utc": "2026-08-31 07:47:30",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1872157": [
        {
            "ioc_value": "23.94.252.16:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "js.tsundere",
            "malware_alias": "DinDoor",
            "malware_printable": "Tsundere",
            "first_seen_utc": "2026-08-11 09:46:08",
            "last_seen_utc": "2026-08-31 07:46:41",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DinDoor,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1872153": [
        {
            "ioc_value": "192.229.115.156:56001",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-11 09:44:46",
            "last_seen_utc": "2026-08-31 07:45:07",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1872154": [
        {
            "ioc_value": "192.229.115.156:56002",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-11 09:44:46",
            "last_seen_utc": "2026-08-31 07:45:08",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1872155": [
        {
            "ioc_value": "192.229.115.156:56003",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-11 09:44:46",
            "last_seen_utc": "2026-08-31 07:45:08",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1872156": [
        {
            "ioc_value": "192.229.115.162:56001",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-11 09:44:46",
            "last_seen_utc": "2026-08-31 07:45:08",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1872151": [
        {
            "ioc_value": "192.229.115.154:56001",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-11 09:44:45",
            "last_seen_utc": "2026-08-31 07:45:07",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1872152": [
        {
            "ioc_value": "192.229.115.154:56003",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-11 09:44:45",
            "last_seen_utc": "2026-08-31 07:45:07",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1872150": [
        {
            "ioc_value": "185.174.101.235:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-11 09:44:32",
            "last_seen_utc": "2026-08-31 07:44:42",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1872148": [
        {
            "ioc_value": "178.16.52.136:7707",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-08-11 09:44:26",
            "last_seen_utc": "2026-08-31 07:44:33",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1872146": [
        {
            "ioc_value": "128.90.102.72:8888",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.dcrat",
            "malware_alias": "DarkCrystal RAT",
            "malware_printable": "DCRat",
            "first_seen_utc": "2026-08-11 09:43:32",
            "last_seen_utc": "2026-08-31 07:43:37",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DCRat,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1872145": [
        {
            "ioc_value": "104.251.181.111:3333",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.dcrat",
            "malware_alias": "DarkCrystal RAT",
            "malware_printable": "DCRat",
            "first_seen_utc": "2026-08-11 09:43:18",
            "last_seen_utc": "2026-08-31 07:43:19",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DCRat,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1872144": [
        {
            "ioc_value": "104.243.248.63:300",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-08-11 09:43:17",
            "last_seen_utc": "2026-08-31 07:43:16",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1872079": [
        {
            "ioc_value": "155.103.70.232:14554",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-08-11 06:58:27",
            "last_seen_utc": "2026-08-31 03:57:13",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://bazaar.abuse.ch/sample/d6fd0e658ec1560ce283754920373825805e7e57176f371e6bc8b9270055bab0/",
            "tags": "RAT,RemcosRAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1872041": [
        {
            "ioc_value": "107.182.173.199:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.havoc",
            "malware_alias": "Havokiz",
            "malware_printable": "Havoc",
            "first_seen_utc": "2026-08-11 06:05:05",
            "last_seen_utc": "2026-08-31 07:43:24",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "havoc",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1871924": [
        {
            "ioc_value": "43.254.166.41:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-08-10 23:46:52",
            "last_seen_utc": "2026-08-31 07:48:49",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1871923": [
        {
            "ioc_value": "update.qzkgpqn.kdns.fr",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-08-10 23:46:29",
            "last_seen_utc": "2026-08-31 07:48:20",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1871881": [
        {
            "ioc_value": "192.252.185.78:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-08-10 20:05:05",
            "last_seen_utc": "2026-08-31 07:48:42",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "cobaltstrike",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1871878": [
        {
            "ioc_value": "91.92.42.22:6767",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-10 19:46:44",
            "last_seen_utc": "2026-08-31 07:48:00",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1871877": [
        {
            "ioc_value": "85.137.252.216:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-10 19:46:36",
            "last_seen_utc": "2026-08-31 07:47:50",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1871876": [
        {
            "ioc_value": "64.89.160.127:8808",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-08-10 19:46:25",
            "last_seen_utc": "2026-08-31 07:47:35",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1871875": [
        {
            "ioc_value": "5.133.102.33:4321",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-08-10 19:46:16",
            "last_seen_utc": "2026-08-31 07:47:25",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1871874": [
        {
            "ioc_value": "46.151.182.113:8848",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.dcrat",
            "malware_alias": "DarkCrystal RAT",
            "malware_printable": "DCRat",
            "first_seen_utc": "2026-08-10 19:46:12",
            "last_seen_utc": "2026-08-31 07:47:20",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DCRat,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1871873": [
        {
            "ioc_value": "45.88.91.145:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-10 19:46:10",
            "last_seen_utc": "2026-08-31 07:47:18",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1871872": [
        {
            "ioc_value": "38.54.45.183:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.bianlian",
            "malware_alias": null,
            "malware_printable": "BianLian",
            "first_seen_utc": "2026-08-10 19:45:52",
            "last_seen_utc": "2026-08-31 07:46:58",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "Bianlian,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1871871": [
        {
            "ioc_value": "37.244.251.138:4433",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.danabot",
            "malware_alias": "DanaTools",
            "malware_printable": "DanaBot",
            "first_seen_utc": "2026-08-10 19:45:48",
            "last_seen_utc": "2026-08-31 07:46:54",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DanBot,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1871870": [
        {
            "ioc_value": "31.76.125.2:56003",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-10 19:45:45",
            "last_seen_utc": "2026-08-31 07:46:49",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1871869": [
        {
            "ioc_value": "216.250.254.245:8808",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-08-10 19:45:31",
            "last_seen_utc": "2026-08-31 07:46:32",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1871868": [
        {
            "ioc_value": "186.168.97.172:8443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.deimos_c2",
            "malware_alias": null,
            "malware_printable": "DeimosC2",
            "first_seen_utc": "2026-08-10 19:44:23",
            "last_seen_utc": "2026-08-31 07:44:57",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "Deimos,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1871867": [
        {
            "ioc_value": "181.215.49.119:56003",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-10 19:44:14",
            "last_seen_utc": "2026-08-31 07:44:38",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1871865": [
        {
            "ioc_value": "172.81.132.75:56001",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-10 19:44:05",
            "last_seen_utc": "2026-08-31 07:44:26",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1871866": [
        {
            "ioc_value": "172.81.132.75:56002",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-10 19:44:05",
            "last_seen_utc": "2026-08-31 07:44:26",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1871864": [
        {
            "ioc_value": "151.241.99.168:1447",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-08-10 19:43:40",
            "last_seen_utc": "2026-08-31 07:43:54",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1871863": [
        {
            "ioc_value": "118.99.88.240:10549",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-08-10 19:43:22",
            "last_seen_utc": "2026-08-31 07:43:34",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1871862": [
        {
            "ioc_value": "104.249.10.87:56001",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-10 19:43:13",
            "last_seen_utc": "2026-08-31 07:43:18",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1871861": [
        {
            "ioc_value": "103.213.248.61:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-08-10 19:43:06",
            "last_seen_utc": "2026-08-31 07:43:09",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1871806": [
        {
            "ioc_value": "38.97.63.243:9999",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "apk.vo1d",
            "malware_alias": null,
            "malware_printable": "vo1d",
            "first_seen_utc": "2026-08-10 19:31:02",
            "last_seen_utc": "2026-08-31 03:15:07",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "loader,Vo1d",
            "anonymous": 0,
            "reporter": "Bitsight"
        }
    ],
    "1871851": [
        {
            "ioc_value": "192.252.179.24:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-08-10 19:05:07",
            "last_seen_utc": "2026-08-31 07:48:42",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "cobaltstrike",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1871717": [
        {
            "ioc_value": "38.97.63.242:9999",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "apk.vo1d",
            "malware_alias": null,
            "malware_printable": "vo1d",
            "first_seen_utc": "2026-08-10 14:24:09",
            "last_seen_utc": "2026-08-31 04:48:45",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "loader,Vo1d",
            "anonymous": 0,
            "reporter": "Bitsight"
        }
    ],
    "1871659": [
        {
            "ioc_value": "123.207.203.20:55501",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-08-10 11:47:37",
            "last_seen_utc": "2026-08-31 07:48:32",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1871658": [
        {
            "ioc_value": "117.24.4.112:4521",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-08-10 11:47:33",
            "last_seen_utc": "2026-08-31 07:48:27",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1871626": [
        {
            "ioc_value": "98.191.191.44:8080",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.deimos_c2",
            "malware_alias": null,
            "malware_printable": "DeimosC2",
            "first_seen_utc": "2026-08-10 09:46:58",
            "last_seen_utc": "2026-08-31 07:48:12",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "Deimos,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1871625": [
        {
            "ioc_value": "91.92.42.22:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-10 09:46:52",
            "last_seen_utc": "2026-08-31 07:48:00",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1871624": [
        {
            "ioc_value": "91.92.34.73:43283",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-08-10 09:46:51",
            "last_seen_utc": "2026-08-31 07:47:59",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1871623": [
        {
            "ioc_value": "77.237.97.58:4433",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.danabot",
            "malware_alias": "DanaTools",
            "malware_printable": "DanaBot",
            "first_seen_utc": "2026-08-10 09:46:36",
            "last_seen_utc": "2026-08-31 07:47:41",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DanBot,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1871622": [
        {
            "ioc_value": "31.77.195.32:4321",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-08-10 09:45:53",
            "last_seen_utc": "2026-08-31 07:46:50",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1871621": [
        {
            "ioc_value": "209.99.190.23:56014",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-10 09:44:52",
            "last_seen_utc": "2026-08-31 07:45:49",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1871620": [
        {
            "ioc_value": "167.233.161.42:3287",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.chaos",
            "malware_alias": "FakeRyuk,RyukJoke,Yashma",
            "malware_printable": "Chaos",
            "first_seen_utc": "2026-08-10 09:43:58",
            "last_seen_utc": "2026-08-31 07:44:16",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CHAOS,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1871619": [
        {
            "ioc_value": "159.203.69.210:8401",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-08-10 09:43:52",
            "last_seen_utc": "2026-08-31 07:44:09",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1871618": [
        {
            "ioc_value": "149.28.121.179:5000",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.evilginx",
            "malware_alias": null,
            "malware_printable": "Evilginx",
            "first_seen_utc": "2026-08-10 09:43:38",
            "last_seen_utc": "2026-08-31 07:43:52",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Evilginx,EvilGoPhish",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1871617": [
        {
            "ioc_value": "104.239.66.245:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-10 09:43:10",
            "last_seen_utc": "2026-08-31 07:43:14",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1871573": [
        {
            "ioc_value": "xox.slotmacau188bd.top",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-08-10 08:19:49",
            "last_seen_utc": "2026-08-30 18:46:32",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "Vidar",
            "anonymous": 0,
            "reporter": "crep1x"
        }
    ],
    "1871555": [
        {
            "ioc_value": "https://78.47.230.34/",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-08-10 08:19:14",
            "last_seen_utc": "2026-08-31 00:19:51",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "Vidar",
            "anonymous": 0,
            "reporter": "crep1x"
        }
    ],
    "1871475": [
        {
            "ioc_value": "102.117.174.217:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-08-10 07:05:05",
            "last_seen_utc": "2026-08-31 07:43:05",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "mythic",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1871452": [
        {
            "ioc_value": "169.58.150.130:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-08-10 03:05:06",
            "last_seen_utc": "2026-08-31 07:44:18",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "mythic",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1871395": [
        {
            "ioc_value": "91.202.233.151:8443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.sliver",
            "malware_alias": null,
            "malware_printable": "Sliver",
            "first_seen_utc": "2026-08-09 19:46:19",
            "last_seen_utc": "2026-08-31 07:47:57",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Sliver",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1871394": [
        {
            "ioc_value": "91.202.233.151:31337",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.sliver",
            "malware_alias": null,
            "malware_printable": "Sliver",
            "first_seen_utc": "2026-08-09 19:46:18",
            "last_seen_utc": "2026-08-31 07:47:57",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Sliver",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1871393": [
        {
            "ioc_value": "85.209.87.84:56003",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-09 19:46:13",
            "last_seen_utc": "2026-08-31 07:47:51",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1871392": [
        {
            "ioc_value": "49.235.153.53:3333",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.evilginx",
            "malware_alias": null,
            "malware_printable": "Evilginx",
            "first_seen_utc": "2026-08-09 19:45:52",
            "last_seen_utc": "2026-08-31 07:47:25",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Evilginx,EvilGoPhish",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1871390": [
        {
            "ioc_value": "45.140.204.12:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pupy",
            "malware_alias": "Patpoopy",
            "malware_printable": "pupy",
            "first_seen_utc": "2026-08-09 19:45:38",
            "last_seen_utc": "2026-08-31 07:47:08",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PupyRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1871391": [
        {
            "ioc_value": "45.140.204.12:9000",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pupy",
            "malware_alias": "Patpoopy",
            "malware_printable": "pupy",
            "first_seen_utc": "2026-08-09 19:45:38",
            "last_seen_utc": "2026-08-31 07:47:08",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PupyRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1871389": [
        {
            "ioc_value": "217.60.77.60:4782",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-09 19:45:16",
            "last_seen_utc": "2026-08-31 07:46:37",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1871388": [
        {
            "ioc_value": "2.50.170.49:7707",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-08-09 19:44:29",
            "last_seen_utc": "2026-08-31 07:45:36",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1871387": [
        {
            "ioc_value": "128.90.59.58:1110",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-08-09 19:43:21",
            "last_seen_utc": "2026-08-31 07:43:38",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1871386": [
        {
            "ioc_value": "107.172.133.190:56002",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-08-09 19:43:12",
            "last_seen_utc": "2026-08-31 07:43:21",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1871385": [
        {
            "ioc_value": "104.164.46.182:52203",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-09 19:43:08",
            "last_seen_utc": "2026-08-31 07:43:13",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1871285": [
        {
            "ioc_value": "72.14.136.55:56001",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-09 09:46:40",
            "last_seen_utc": "2026-08-31 07:47:40",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1871286": [
        {
            "ioc_value": "72.14.136.55:56002",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-09 09:46:40",
            "last_seen_utc": "2026-08-31 07:47:40",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1871287": [
        {
            "ioc_value": "72.14.136.55:56003",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-09 09:46:40",
            "last_seen_utc": "2026-08-31 07:47:40",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1871284": [
        {
            "ioc_value": "69.164.245.180:4000",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.evilginx",
            "malware_alias": null,
            "malware_printable": "Evilginx",
            "first_seen_utc": "2026-08-09 09:46:39",
            "last_seen_utc": "2026-08-31 07:47:40",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Evilginx,EvilGoPhish",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1871282": [
        {
            "ioc_value": "43.134.169.103:31337",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.sliver",
            "malware_alias": null,
            "malware_printable": "Sliver",
            "first_seen_utc": "2026-08-09 09:46:06",
            "last_seen_utc": "2026-08-31 07:47:03",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Sliver",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1871283": [
        {
            "ioc_value": "43.134.169.103:40056",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.sliver",
            "malware_alias": null,
            "malware_printable": "Sliver",
            "first_seen_utc": "2026-08-09 09:46:06",
            "last_seen_utc": "2026-08-31 07:47:03",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Sliver",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1871281": [
        {
            "ioc_value": "212.103.26.10:54321",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.havoc",
            "malware_alias": "Havokiz",
            "malware_printable": "Havoc",
            "first_seen_utc": "2026-08-09 09:44:59",
            "last_seen_utc": "2026-08-31 07:45:50",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Havoc",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1871280": [
        {
            "ioc_value": "209.99.190.23:55010",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-09 09:44:57",
            "last_seen_utc": "2026-08-31 07:45:48",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1871279": [
        {
            "ioc_value": "20.243.82.8:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-08-09 09:44:49",
            "last_seen_utc": "2026-08-31 07:45:38",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1871278": [
        {
            "ioc_value": "198.37.105.30:7777",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-08-09 09:44:43",
            "last_seen_utc": "2026-08-31 07:45:31",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1871277": [
        {
            "ioc_value": "185.247.208.91:55555",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-09 09:44:28",
            "last_seen_utc": "2026-08-31 07:44:50",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1871275": [
        {
            "ioc_value": "172.252.172.33:56001",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-09 09:44:10",
            "last_seen_utc": "2026-08-31 07:44:25",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1871276": [
        {
            "ioc_value": "172.252.172.33:56002",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-09 09:44:10",
            "last_seen_utc": "2026-08-31 07:44:26",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1871272": [
        {
            "ioc_value": "172.252.172.29:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-09 09:44:09",
            "last_seen_utc": "2026-08-31 07:44:24",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1871273": [
        {
            "ioc_value": "172.252.172.30:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-09 09:44:09",
            "last_seen_utc": "2026-08-31 07:44:24",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1871274": [
        {
            "ioc_value": "172.252.172.31:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-09 09:44:09",
            "last_seen_utc": "2026-08-31 07:44:25",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1871269": [
        {
            "ioc_value": "172.245.136.99:56001",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-09 09:44:08",
            "last_seen_utc": "2026-08-31 07:44:23",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1871270": [
        {
            "ioc_value": "172.245.136.99:56002",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-09 09:44:08",
            "last_seen_utc": "2026-08-31 07:44:23",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1871271": [
        {
            "ioc_value": "172.245.136.99:56003",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-09 09:44:08",
            "last_seen_utc": "2026-08-31 07:44:23",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1871268": [
        {
            "ioc_value": "168.222.251.83:56012",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-09 09:44:04",
            "last_seen_utc": "2026-08-31 07:44:17",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1871264": [
        {
            "ioc_value": "138.2.87.233:25745",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.sliver",
            "malware_alias": null,
            "malware_printable": "Sliver",
            "first_seen_utc": "2026-08-09 09:43:33",
            "last_seen_utc": "2026-08-31 07:43:45",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Sliver",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1871265": [
        {
            "ioc_value": "138.2.87.233:30462",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.sliver",
            "malware_alias": null,
            "malware_printable": "Sliver",
            "first_seen_utc": "2026-08-09 09:43:33",
            "last_seen_utc": "2026-08-31 07:43:45",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Sliver",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1871266": [
        {
            "ioc_value": "138.2.87.233:31337",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.sliver",
            "malware_alias": null,
            "malware_printable": "Sliver",
            "first_seen_utc": "2026-08-09 09:43:33",
            "last_seen_utc": "2026-08-31 07:43:46",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Sliver",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1871267": [
        {
            "ioc_value": "139.162.113.221:64321",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-08-09 09:43:33",
            "last_seen_utc": "2026-08-31 07:43:46",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1871263": [
        {
            "ioc_value": "134.122.132.3:4321",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-08-09 09:43:29",
            "last_seen_utc": "2026-08-31 07:43:42",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1871262": [
        {
            "ioc_value": "130.12.182.39:2700",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-08-09 09:43:26",
            "last_seen_utc": "2026-08-31 07:43:40",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1871261": [
        {
            "ioc_value": "124.221.215.82:9090",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-08-09 09:43:24",
            "last_seen_utc": "2026-08-31 07:43:36",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1871260": [
        {
            "ioc_value": "105.108.109.255:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-09 09:43:14",
            "last_seen_utc": "2026-08-31 07:43:20",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1871243": [
        {
            "ioc_value": "45.61.136.78:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-08-09 08:05:08",
            "last_seen_utc": "2026-08-31 07:47:15",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "mythic",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1871240": [
        {
            "ioc_value": "207.189.23.189:8808",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-08-09 08:05:05",
            "last_seen_utc": "2026-08-31 07:45:44",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "asyncrat",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1871218": [
        {
            "ioc_value": "202.60.232.182:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-08-09 06:05:06",
            "last_seen_utc": "2026-08-31 07:45:40",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "mythic",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1871217": [
        {
            "ioc_value": "34.26.129.189:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-08-09 06:05:05",
            "last_seen_utc": "2026-08-31 07:46:51",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "mythic",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1871165": [
        {
            "ioc_value": "68.64.183.64:9088",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-08-08 23:47:03",
            "last_seen_utc": "2026-08-31 07:48:55",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1871140": [
        {
            "ioc_value": "http://193.148.56.206/",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.stealc",
            "malware_alias": null,
            "malware_printable": "Stealc",
            "first_seen_utc": "2026-08-08 20:36:26",
            "last_seen_utc": "2026-08-31 07:42:20",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://bazaar.abuse.ch/sample/d490ac7dc0854bea4728b0a4497727fdf74a8b1a4a9dc10d040c71b1814586bd/",
            "tags": "Stealc",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1871134": [
        {
            "ioc_value": "91.92.40.5:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.mirai",
            "malware_alias": "Katana",
            "malware_printable": "Mirai",
            "first_seen_utc": "2026-08-08 19:46:26",
            "last_seen_utc": "2026-08-31 07:48:00",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mirai",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1871133": [
        {
            "ioc_value": "57.182.128.31:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.brute_ratel_c4",
            "malware_alias": "BOLDBADGER,BruteRatel",
            "malware_printable": "Brute Ratel C4",
            "first_seen_utc": "2026-08-08 19:46:05",
            "last_seen_utc": "2026-08-31 07:47:32",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "BruteRatel,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1871131": [
        {
            "ioc_value": "52.128.231.157:4321",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-08-08 19:46:03",
            "last_seen_utc": "2026-08-31 07:47:28",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1871132": [
        {
            "ioc_value": "52.128.231.158:4321",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-08-08 19:46:03",
            "last_seen_utc": "2026-08-31 07:47:28",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1871129": [
        {
            "ioc_value": "52.128.231.155:4321",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-08-08 19:46:02",
            "last_seen_utc": "2026-08-31 07:47:28",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1871130": [
        {
            "ioc_value": "52.128.231.156:4321",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-08-08 19:46:02",
            "last_seen_utc": "2026-08-31 07:47:28",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1871128": [
        {
            "ioc_value": "43.139.114.212:4321",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-08-08 19:45:40",
            "last_seen_utc": "2026-08-31 07:47:04",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1871127": [
        {
            "ioc_value": "34.150.91.139:19443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-08-08 19:45:33",
            "last_seen_utc": "2026-08-31 07:46:51",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1871126": [
        {
            "ioc_value": "207.189.18.213:56003",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-08 19:44:39",
            "last_seen_utc": "2026-08-31 07:45:44",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1871125": [
        {
            "ioc_value": "194.69.162.217:4321",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-08-08 19:44:25",
            "last_seen_utc": "2026-08-31 07:45:21",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1871123": [
        {
            "ioc_value": "191.111.244.175:8443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.deimos_c2",
            "malware_alias": null,
            "malware_printable": "DeimosC2",
            "first_seen_utc": "2026-08-08 19:44:19",
            "last_seen_utc": "2026-08-31 07:45:01",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "Deimos,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1871122": [
        {
            "ioc_value": "172.252.172.33:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-08 19:43:58",
            "last_seen_utc": "2026-08-31 07:44:25",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1871121": [
        {
            "ioc_value": "169.58.64.151:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-08-08 19:43:55",
            "last_seen_utc": "2026-08-31 07:44:19",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1871120": [
        {
            "ioc_value": "159.203.69.210:48202",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-08-08 19:43:49",
            "last_seen_utc": "2026-08-31 07:44:09",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1871119": [
        {
            "ioc_value": "157.10.52.2:56003",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-08 19:43:43",
            "last_seen_utc": "2026-08-31 07:44:04",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1871118": [
        {
            "ioc_value": "151.242.170.219:56003",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-08 19:43:37",
            "last_seen_utc": "2026-08-31 07:43:54",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1871116": [
        {
            "ioc_value": "125.62.77.141:56002",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-08 19:43:22",
            "last_seen_utc": "2026-08-31 07:43:36",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1871117": [
        {
            "ioc_value": "125.62.77.141:56003",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-08 19:43:22",
            "last_seen_utc": "2026-08-31 07:43:37",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1871112": [
        {
            "ioc_value": "112.121.176.3:56003",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-08 19:43:17",
            "last_seen_utc": "2026-08-31 07:43:29",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1871113": [
        {
            "ioc_value": "112.121.176.4:56003",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-08 19:43:17",
            "last_seen_utc": "2026-08-31 07:43:29",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1871114": [
        {
            "ioc_value": "112.121.176.5:56003",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-08 19:43:17",
            "last_seen_utc": "2026-08-31 07:43:30",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1871115": [
        {
            "ioc_value": "112.121.176.6:56003",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-08 19:43:17",
            "last_seen_utc": "2026-08-31 07:43:30",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1871111": [
        {
            "ioc_value": "104.239.66.95:56003",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-08 19:43:11",
            "last_seen_utc": "2026-08-31 07:43:15",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1871110": [
        {
            "ioc_value": "1.92.135.168:4321",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-08-08 19:43:01",
            "last_seen_utc": "2026-08-31 07:43:03",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1871094": [
        {
            "ioc_value": "38.60.227.165:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-08-08 18:05:08",
            "last_seen_utc": "2026-08-31 07:46:59",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "mythic",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1871093": [
        {
            "ioc_value": "37.72.168.212:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-08-08 18:05:07",
            "last_seen_utc": "2026-08-31 07:46:54",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "mythic",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1870777": [
        {
            "ioc_value": "161.248.179.92:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-08-08 14:05:06",
            "last_seen_utc": "2026-08-31 07:44:10",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "asyncrat",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1870752": [
        {
            "ioc_value": "185.92.190.177:8896",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-08-08 11:47:11",
            "last_seen_utc": "2026-08-31 07:48:41",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1870714": [
        {
            "ioc_value": "95.133.229.173:56001",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-08 09:46:41",
            "last_seen_utc": "2026-08-31 07:48:11",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1870713": [
        {
            "ioc_value": "88.129.145.223:8080",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.deimos_c2",
            "malware_alias": null,
            "malware_printable": "DeimosC2",
            "first_seen_utc": "2026-08-08 09:46:32",
            "last_seen_utc": "2026-08-31 07:47:53",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "Deimos,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1870712": [
        {
            "ioc_value": "68.178.202.150:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-08-08 09:46:21",
            "last_seen_utc": "2026-08-31 07:47:39",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1870710": [
        {
            "ioc_value": "45.56.165.197:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-08 09:45:58",
            "last_seen_utc": "2026-08-31 07:47:14",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1870711": [
        {
            "ioc_value": "45.56.165.197:56001",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-08 09:45:58",
            "last_seen_utc": "2026-08-31 07:47:14",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1870709": [
        {
            "ioc_value": "45.157.117.186:27487",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-08-08 09:45:54",
            "last_seen_utc": "2026-08-31 07:47:11",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1870708": [
        {
            "ioc_value": "34.81.234.183:8443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.evilginx",
            "malware_alias": null,
            "malware_printable": "Evilginx",
            "first_seen_utc": "2026-08-08 09:45:42",
            "last_seen_utc": "2026-08-31 07:46:52",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Evilginx,EvilGoPhish",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1870707": [
        {
            "ioc_value": "31.77.145.53:4443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-08-08 09:45:41",
            "last_seen_utc": "2026-08-31 07:46:50",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1870706": [
        {
            "ioc_value": "217.60.195.187:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.mirai",
            "malware_alias": "Katana",
            "malware_printable": "Mirai",
            "first_seen_utc": "2026-08-08 09:45:29",
            "last_seen_utc": "2026-08-31 07:46:34",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mirai",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1870705": [
        {
            "ioc_value": "209.99.190.23:55011",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-08 09:44:45",
            "last_seen_utc": "2026-08-31 07:45:48",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1870704": [
        {
            "ioc_value": "203.98.68.17:1111",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-08-08 09:44:39",
            "last_seen_utc": "2026-08-31 07:45:42",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1870703": [
        {
            "ioc_value": "2.59.133.115:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-08 09:44:36",
            "last_seen_utc": "2026-08-31 07:45:36",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1870702": [
        {
            "ioc_value": "2.26.30.62:8080",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.chaos",
            "malware_alias": "FakeRyuk,RyukJoke,Yashma",
            "malware_printable": "Chaos",
            "first_seen_utc": "2026-08-08 09:44:33",
            "last_seen_utc": "2026-08-31 07:45:33",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CHAOS,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1870701": [
        {
            "ioc_value": "195.242.119.86:9000",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.evilginx",
            "malware_alias": null,
            "malware_printable": "Evilginx",
            "first_seen_utc": "2026-08-08 09:44:30",
            "last_seen_utc": "2026-08-31 07:45:27",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Evilginx,EvilGoPhish",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1870700": [
        {
            "ioc_value": "194.59.31.175:4321",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-08-08 09:44:28",
            "last_seen_utc": "2026-08-31 07:45:20",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1870699": [
        {
            "ioc_value": "172.252.172.32:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-08 09:43:59",
            "last_seen_utc": "2026-08-31 07:44:25",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1870698": [
        {
            "ioc_value": "136.244.96.75:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-08-08 09:43:27",
            "last_seen_utc": "2026-08-31 07:43:44",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1870697": [
        {
            "ioc_value": "134.122.132.35:4321",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-08-08 09:43:26",
            "last_seen_utc": "2026-08-31 07:43:43",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1870696": [
        {
            "ioc_value": "129.146.57.192:56001",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-08 09:43:22",
            "last_seen_utc": "2026-08-31 07:43:38",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1870641": [
        {
            "ioc_value": "192.169.176.54:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-08-08 07:05:05",
            "last_seen_utc": "2026-08-31 07:45:06",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "mythic",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1870610": [
        {
            "ioc_value": "68.178.205.17:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-08-08 04:05:05",
            "last_seen_utc": "2026-08-31 07:47:39",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "mythic",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1870520": [
        {
            "ioc_value": "121.5.27.17:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-08-07 23:46:45",
            "last_seen_utc": "2026-08-31 07:48:32",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1870519": [
        {
            "ioc_value": "1302768123-l3a4w496qm.ap-shanghai.tencentscf.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-08-07 23:46:29",
            "last_seen_utc": "2026-08-31 07:48:13",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1870254": [
        {
            "ioc_value": "94.154.32.48:56001",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-07 19:46:31",
            "last_seen_utc": "2026-08-31 07:48:06",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1870253": [
        {
            "ioc_value": "87.120.196.221:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.mirai",
            "malware_alias": "Katana",
            "malware_printable": "Mirai",
            "first_seen_utc": "2026-08-07 19:46:22",
            "last_seen_utc": "2026-08-31 07:47:52",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mirai",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1870252": [
        {
            "ioc_value": "43.135.34.69:43911",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-08-07 19:45:42",
            "last_seen_utc": "2026-08-31 07:47:04",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1870251": [
        {
            "ioc_value": "38.18.229.217:56001",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-07 19:45:39",
            "last_seen_utc": "2026-08-31 07:46:56",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1870250": [
        {
            "ioc_value": "217.60.97.106:6606",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-08-07 19:45:24",
            "last_seen_utc": "2026-08-31 07:46:37",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1870249": [
        {
            "ioc_value": "207.231.104.146:1447",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-08-07 19:44:41",
            "last_seen_utc": "2026-08-31 07:45:44",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1870248": [
        {
            "ioc_value": "207.189.18.213:56002",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-07 19:44:40",
            "last_seen_utc": "2026-08-31 07:45:44",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1870247": [
        {
            "ioc_value": "186.169.88.130:9002",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.dcrat",
            "malware_alias": "DarkCrystal RAT",
            "malware_printable": "DCRat",
            "first_seen_utc": "2026-08-07 19:44:18",
            "last_seen_utc": "2026-08-31 07:44:58",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DCRat,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1870246": [
        {
            "ioc_value": "185.212.128.59:9000",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.evilginx",
            "malware_alias": null,
            "malware_printable": "Evilginx",
            "first_seen_utc": "2026-08-07 19:44:13",
            "last_seen_utc": "2026-08-31 07:44:46",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Evilginx,EvilGoPhish",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1870244": [
        {
            "ioc_value": "172.239.45.42:82",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.havoc",
            "malware_alias": "Havokiz",
            "malware_printable": "Havoc",
            "first_seen_utc": "2026-08-07 19:43:59",
            "last_seen_utc": "2026-08-31 07:44:23",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Havoc",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1870245": [
        {
            "ioc_value": "172.86.117.104:56001",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-07 19:43:59",
            "last_seen_utc": "2026-08-31 07:44:26",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1870243": [
        {
            "ioc_value": "167.172.145.141:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-08-07 19:43:55",
            "last_seen_utc": "2026-08-31 07:44:16",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "Covenant,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1870242": [
        {
            "ioc_value": "159.203.69.210:11088",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-08-07 19:43:49",
            "last_seen_utc": "2026-08-31 07:44:08",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1870241": [
        {
            "ioc_value": "124.198.131.130:1907",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.dcrat",
            "malware_alias": "DarkCrystal RAT",
            "malware_printable": "DCRat",
            "first_seen_utc": "2026-08-07 19:43:22",
            "last_seen_utc": "2026-08-31 07:43:35",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DCRat,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1870240": [
        {
            "ioc_value": "104.238.57.23:56003",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-07 19:43:11",
            "last_seen_utc": "2026-08-31 07:43:14",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1870239": [
        {
            "ioc_value": "103.158.191.249:442",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-07 19:43:06",
            "last_seen_utc": "2026-08-31 07:43:08",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1869794": [
        {
            "ioc_value": "43.139.87.203:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-08-07 10:05:08",
            "last_seen_utc": "2026-08-31 07:48:48",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "cobaltstrike",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1869781": [
        {
            "ioc_value": "85.209.87.84:56002",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-07 09:46:36",
            "last_seen_utc": "2026-08-31 07:47:51",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1869780": [
        {
            "ioc_value": "78.17.71.8:5025",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.dcrat",
            "malware_alias": "DarkCrystal RAT",
            "malware_printable": "DCRat",
            "first_seen_utc": "2026-08-07 09:46:29",
            "last_seen_utc": "2026-08-31 07:47:42",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DCRat,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1869779": [
        {
            "ioc_value": "64.89.161.196:7777",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.dcrat",
            "malware_alias": "DarkCrystal RAT",
            "malware_printable": "DCRat",
            "first_seen_utc": "2026-08-07 09:46:24",
            "last_seen_utc": "2026-08-31 07:47:37",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DCRat,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1869778": [
        {
            "ioc_value": "45.89.48.12:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-07 09:46:10",
            "last_seen_utc": "2026-08-31 07:47:19",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1869777": [
        {
            "ioc_value": "34.106.101.107:6606",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-08-07 09:45:46",
            "last_seen_utc": "2026-08-31 07:46:51",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1869776": [
        {
            "ioc_value": "3.75.210.48:7777",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.deimos_c2",
            "malware_alias": null,
            "malware_printable": "DeimosC2",
            "first_seen_utc": "2026-08-07 09:45:43",
            "last_seen_utc": "2026-08-31 07:46:45",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "Deimos,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1869775": [
        {
            "ioc_value": "207.32.217.227:21903",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-08-07 09:44:48",
            "last_seen_utc": "2026-08-31 07:45:44",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1869774": [
        {
            "ioc_value": "203.98.68.17:1009",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-08-07 09:44:45",
            "last_seen_utc": "2026-08-31 07:45:42",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1869773": [
        {
            "ioc_value": "185.212.129.152:9000",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.evilginx",
            "malware_alias": null,
            "malware_printable": "Evilginx",
            "first_seen_utc": "2026-08-07 09:44:19",
            "last_seen_utc": "2026-08-31 07:44:47",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Evilginx,EvilGoPhish",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1869772": [
        {
            "ioc_value": "185.212.128.170:9000",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.evilginx",
            "malware_alias": null,
            "malware_printable": "Evilginx",
            "first_seen_utc": "2026-08-07 09:44:18",
            "last_seen_utc": "2026-08-31 07:44:45",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Evilginx,EvilGoPhish",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1869771": [
        {
            "ioc_value": "159.203.69.210:35203",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-08-07 09:43:53",
            "last_seen_utc": "2026-08-31 07:44:09",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1869769": [
        {
            "ioc_value": "154.30.132.30:6606",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-08-07 09:43:42",
            "last_seen_utc": "2026-08-31 07:43:59",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1869770": [
        {
            "ioc_value": "154.40.62.125:9001",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pupy",
            "malware_alias": "Patpoopy",
            "malware_printable": "pupy",
            "first_seen_utc": "2026-08-07 09:43:42",
            "last_seen_utc": "2026-08-31 07:43:59",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PupyRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1869768": [
        {
            "ioc_value": "124.198.131.169:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-07 09:43:22",
            "last_seen_utc": "2026-08-31 07:43:36",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1869767": [
        {
            "ioc_value": "103.249.116.184:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-07 09:43:06",
            "last_seen_utc": "2026-08-31 07:43:09",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1869750": [
        {
            "ioc_value": "203.98.68.17:2222",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-08-07 09:05:08",
            "last_seen_utc": "2026-08-31 07:45:42",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "asyncrat",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1869692": [
        {
            "ioc_value": "159.203.69.210:8088",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-08-07 06:05:06",
            "last_seen_utc": "2026-08-31 07:44:09",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "asyncrat",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1869592": [
        {
            "ioc_value": "151.242.125.190:9527",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-08-06 23:46:46",
            "last_seen_utc": "2026-08-31 07:48:34",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1869558": [
        {
            "ioc_value": "91.92.40.56:8888",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-06 19:46:26",
            "last_seen_utc": "2026-08-31 07:48:00",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1869556": [
        {
            "ioc_value": "80.76.49.3:56001",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-06 19:46:15",
            "last_seen_utc": "2026-08-31 07:47:44",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1869557": [
        {
            "ioc_value": "80.76.49.3:56002",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-06 19:46:15",
            "last_seen_utc": "2026-08-31 07:47:45",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1869555": [
        {
            "ioc_value": "64.89.161.42:13834",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-06 19:46:09",
            "last_seen_utc": "2026-08-31 07:47:37",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1869554": [
        {
            "ioc_value": "31.59.137.166:56002",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-06 19:45:33",
            "last_seen_utc": "2026-08-31 07:46:48",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1869553": [
        {
            "ioc_value": "217.60.97.106:8808",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-08-06 19:45:21",
            "last_seen_utc": "2026-08-31 07:46:37",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1869552": [
        {
            "ioc_value": "185.212.128.232:9000",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.evilginx",
            "malware_alias": null,
            "malware_printable": "Evilginx",
            "first_seen_utc": "2026-08-06 19:44:11",
            "last_seen_utc": "2026-08-31 07:44:45",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Evilginx,EvilGoPhish",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1869551": [
        {
            "ioc_value": "156.251.16.212:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-06 19:43:43",
            "last_seen_utc": "2026-08-31 07:44:04",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1869550": [
        {
            "ioc_value": "154.37.154.36:1443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-06 19:43:38",
            "last_seen_utc": "2026-08-31 07:43:59",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1869549": [
        {
            "ioc_value": "153.75.88.67:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-06 19:43:37",
            "last_seen_utc": "2026-08-31 07:43:56",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1869453": [
        {
            "ioc_value": "103.213.248.61:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-08-06 14:05:06",
            "last_seen_utc": "2026-08-31 07:43:09",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "mythic",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1869415": [
        {
            "ioc_value": "154.221.25.38:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-08-06 13:05:05",
            "last_seen_utc": "2026-08-31 07:48:36",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "cobaltstrike",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1869383": [
        {
            "ioc_value": "8.135.68.39:2087",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-08-06 11:47:32",
            "last_seen_utc": "2026-08-31 07:48:56",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1869382": [
        {
            "ioc_value": "185.92.190.176:8896",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-08-06 11:47:16",
            "last_seen_utc": "2026-08-31 07:48:41",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1869381": [
        {
            "ioc_value": "185.92.190.173:8896",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-08-06 11:47:15",
            "last_seen_utc": "2026-08-31 07:48:40",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1869380": [
        {
            "ioc_value": "139.199.3.92:2087",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-08-06 11:47:09",
            "last_seen_utc": "2026-08-31 07:48:33",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1869339": [
        {
            "ioc_value": "94.154.32.48:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-06 09:46:43",
            "last_seen_utc": "2026-08-31 07:48:06",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1869338": [
        {
            "ioc_value": "88.214.26.49:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-06 09:46:35",
            "last_seen_utc": "2026-08-31 07:47:53",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1869337": [
        {
            "ioc_value": "80.225.83.93:4444",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.mirai",
            "malware_alias": "Katana",
            "malware_printable": "Mirai",
            "first_seen_utc": "2026-08-06 09:46:27",
            "last_seen_utc": "2026-08-31 07:47:44",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mirai",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1869336": [
        {
            "ioc_value": "57.154.16.251:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-08-06 09:46:15",
            "last_seen_utc": "2026-08-31 07:47:31",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1869335": [
        {
            "ioc_value": "31.77.145.53:4444",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-08-06 09:45:42",
            "last_seen_utc": "2026-08-31 07:46:50",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1869334": [
        {
            "ioc_value": "209.99.190.23:56013",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-06 09:44:47",
            "last_seen_utc": "2026-08-31 07:45:49",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1869333": [
        {
            "ioc_value": "207.174.0.234:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-06 09:44:43",
            "last_seen_utc": "2026-08-31 07:45:44",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1869332": [
        {
            "ioc_value": "206.123.129.171:7720",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.dcrat",
            "malware_alias": "DarkCrystal RAT",
            "malware_printable": "DCRat",
            "first_seen_utc": "2026-08-06 09:44:42",
            "last_seen_utc": "2026-08-31 07:45:43",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DCRat,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1869331": [
        {
            "ioc_value": "20.168.52.142:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-08-06 09:44:38",
            "last_seen_utc": "2026-08-31 07:45:37",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1869330": [
        {
            "ioc_value": "20.150.148.238:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-08-06 09:44:37",
            "last_seen_utc": "2026-08-31 07:45:37",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1869329": [
        {
            "ioc_value": "196.64.146.72:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-06 09:44:32",
            "last_seen_utc": "2026-08-31 07:45:29",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1869327": [
        {
            "ioc_value": "186.112.66.56:8443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.deimos_c2",
            "malware_alias": null,
            "malware_printable": "DeimosC2",
            "first_seen_utc": "2026-08-06 09:44:19",
            "last_seen_utc": "2026-08-31 07:44:57",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "Deimos,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1869328": [
        {
            "ioc_value": "186.169.88.130:9031",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.dcrat",
            "malware_alias": "DarkCrystal RAT",
            "malware_printable": "DCRat",
            "first_seen_utc": "2026-08-06 09:44:19",
            "last_seen_utc": "2026-08-31 07:44:58",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DCRat,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1869326": [
        {
            "ioc_value": "172.239.45.42:81",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.havoc",
            "malware_alias": "Havokiz",
            "malware_printable": "Havoc",
            "first_seen_utc": "2026-08-06 09:43:59",
            "last_seen_utc": "2026-08-31 07:44:23",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Havoc",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1869324": [
        {
            "ioc_value": "159.203.69.210:22555",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-08-06 09:43:50",
            "last_seen_utc": "2026-08-31 07:44:08",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1869325": [
        {
            "ioc_value": "159.203.69.210:5800",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-08-06 09:43:50",
            "last_seen_utc": "2026-08-31 07:44:09",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1869323": [
        {
            "ioc_value": "134.122.132.28:4321",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-08-06 09:43:25",
            "last_seen_utc": "2026-08-31 07:43:42",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1869312": [
        {
            "ioc_value": "217.60.195.118:2404",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-08-06 09:02:08",
            "last_seen_utc": "2026-08-30 23:11:03",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://bazaar.abuse.ch/sample/a99039b4ba0da4c05516d43a10dbccc34757b1e3c7b9de7a67d35d667b19948b/",
            "tags": "RAT,RemcosRAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1869296": [
        {
            "ioc_value": "64.89.161.65:4444",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.dcrat",
            "malware_alias": "DarkCrystal RAT",
            "malware_printable": "DCRat",
            "first_seen_utc": "2026-08-06 08:05:06",
            "last_seen_utc": "2026-08-31 07:47:37",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "dcrat",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1869284": [
        {
            "ioc_value": "154.221.25.38:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-08-06 07:24:00",
            "last_seen_utc": "2026-08-31 07:48:36",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-391144938",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1869123": [
        {
            "ioc_value": "159.65.136.5:7647",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remus",
            "malware_alias": null,
            "malware_printable": "Remus",
            "first_seen_utc": "2026-08-06 05:10:19",
            "last_seen_utc": "2026-08-31 08:11:25",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "0f81469cc7638ba7c82eaddbd6b3c20a,c2,remus",
            "anonymous": 0,
            "reporter": "Bitsight"
        }
    ],
    "1869105": [
        {
            "ioc_value": "217.154.212.25:4444",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-08-05 23:47:16",
            "last_seen_utc": "2026-08-31 07:48:44",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1869104": [
        {
            "ioc_value": "100.82.195.65:4444",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-08-05 23:46:54",
            "last_seen_utc": "2026-08-31 07:48:21",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1869103": [
        {
            "ioc_value": "hp.tailc223d4.ts.net",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-08-05 23:46:49",
            "last_seen_utc": "2026-08-31 07:48:17",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1869057": [
        {
            "ioc_value": "94.250.176.76:4433",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.danabot",
            "malware_alias": "DanaTools",
            "malware_printable": "DanaBot",
            "first_seen_utc": "2026-08-05 19:47:11",
            "last_seen_utc": "2026-08-31 07:48:08",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DanBot,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1869055": [
        {
            "ioc_value": "85.209.87.84:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-05 19:46:59",
            "last_seen_utc": "2026-08-31 07:47:51",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1869056": [
        {
            "ioc_value": "86.48.16.94:30200",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-08-05 19:46:59",
            "last_seen_utc": "2026-08-31 07:47:52",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1869054": [
        {
            "ioc_value": "72.14.136.55:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-05 19:46:50",
            "last_seen_utc": "2026-08-31 07:47:40",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1869052": [
        {
            "ioc_value": "64.95.13.164:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-08-05 19:46:47",
            "last_seen_utc": "2026-08-31 07:47:37",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1869053": [
        {
            "ioc_value": "64.95.13.164:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-08-05 19:46:47",
            "last_seen_utc": "2026-08-31 07:47:38",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1869051": [
        {
            "ioc_value": "45.59.120.82:5656",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.dcrat",
            "malware_alias": "DarkCrystal RAT",
            "malware_printable": "DCRat",
            "first_seen_utc": "2026-08-05 19:46:26",
            "last_seen_utc": "2026-08-31 07:47:15",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DCRat,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1869050": [
        {
            "ioc_value": "206.123.129.171:8081",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-08-05 19:44:59",
            "last_seen_utc": "2026-08-31 07:45:43",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1869047": [
        {
            "ioc_value": "196.251.107.131:8808",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-08-05 19:44:48",
            "last_seen_utc": "2026-08-31 07:45:28",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1869048": [
        {
            "ioc_value": "196.64.146.72:5000",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-08-05 19:44:48",
            "last_seen_utc": "2026-08-31 07:45:29",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1869049": [
        {
            "ioc_value": "196.64.146.72:5001",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-08-05 19:44:48",
            "last_seen_utc": "2026-08-31 07:45:29",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1869046": [
        {
            "ioc_value": "185.212.129.31:9000",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.evilginx",
            "malware_alias": null,
            "malware_printable": "Evilginx",
            "first_seen_utc": "2026-08-05 19:44:31",
            "last_seen_utc": "2026-08-31 07:44:47",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Evilginx,EvilGoPhish",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1869044": [
        {
            "ioc_value": "185.212.129.170:9000",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.evilginx",
            "malware_alias": null,
            "malware_printable": "Evilginx",
            "first_seen_utc": "2026-08-05 19:44:30",
            "last_seen_utc": "2026-08-31 07:44:47",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Evilginx,EvilGoPhish",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1869045": [
        {
            "ioc_value": "185.212.129.25:9000",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.evilginx",
            "malware_alias": null,
            "malware_printable": "Evilginx",
            "first_seen_utc": "2026-08-05 19:44:30",
            "last_seen_utc": "2026-08-31 07:44:47",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Evilginx,EvilGoPhish",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1869043": [
        {
            "ioc_value": "185.212.128.181:9000",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.evilginx",
            "malware_alias": null,
            "malware_printable": "Evilginx",
            "first_seen_utc": "2026-08-05 19:44:29",
            "last_seen_utc": "2026-08-31 07:44:45",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Evilginx,EvilGoPhish",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1869042": [
        {
            "ioc_value": "185.212.128.124:9000",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.evilginx",
            "malware_alias": null,
            "malware_printable": "Evilginx",
            "first_seen_utc": "2026-08-05 19:44:28",
            "last_seen_utc": "2026-08-31 07:44:44",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Evilginx,EvilGoPhish",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1869041": [
        {
            "ioc_value": "185.174.103.243:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-05 19:44:27",
            "last_seen_utc": "2026-08-31 07:44:43",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1869040": [
        {
            "ioc_value": "178.16.53.222:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-05 19:44:19",
            "last_seen_utc": "2026-08-31 07:44:34",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1869039": [
        {
            "ioc_value": "172.81.132.75:56003",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-05 19:44:13",
            "last_seen_utc": "2026-08-31 07:44:26",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1869038": [
        {
            "ioc_value": "159.203.69.210:23501",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-08-05 19:44:00",
            "last_seen_utc": "2026-08-31 07:44:08",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1869037": [
        {
            "ioc_value": "154.247.251.74:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-05 19:43:48",
            "last_seen_utc": "2026-08-31 07:43:59",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1869036": [
        {
            "ioc_value": "130.12.181.96:8848",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.dcrat",
            "malware_alias": "DarkCrystal RAT",
            "malware_printable": "DCRat",
            "first_seen_utc": "2026-08-05 19:43:28",
            "last_seen_utc": "2026-08-31 07:43:39",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DCRat,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1869030": [
        {
            "ioc_value": "158.220.100.51:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-08-05 19:05:06",
            "last_seen_utc": "2026-08-31 07:44:06",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "mythic",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1869029": [
        {
            "ioc_value": "134.209.146.147:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-08-05 19:05:05",
            "last_seen_utc": "2026-08-31 07:43:43",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "mythic",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1869000": [
        {
            "ioc_value": "8.156.69.157:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-08-05 17:05:05",
            "last_seen_utc": "2026-08-31 07:48:56",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "cobaltstrike",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1868828": [
        {
            "ioc_value": "47.83.3.103:10443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-08-05 11:47:40",
            "last_seen_utc": "2026-08-31 07:48:53",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1868827": [
        {
            "ioc_value": "45.8.159.205:8596",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-08-05 11:47:36",
            "last_seen_utc": "2026-08-31 07:48:50",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1868826": [
        {
            "ioc_value": "209.200.246.194:16556",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-08-05 11:47:30",
            "last_seen_utc": "2026-08-31 07:48:43",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1868825": [
        {
            "ioc_value": "169.58.82.229:7788",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-08-05 11:47:25",
            "last_seen_utc": "2026-08-31 07:48:39",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1868823": [
        {
            "ioc_value": "acac.hopto.org",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-08-05 11:46:59",
            "last_seen_utc": "2026-08-31 07:48:13",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1868757": [
        {
            "ioc_value": "65.1.70.222:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-05 09:46:52",
            "last_seen_utc": "2026-08-31 07:47:38",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1868756": [
        {
            "ioc_value": "64.227.159.29:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-08-05 09:46:51",
            "last_seen_utc": "2026-08-31 07:47:35",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1868755": [
        {
            "ioc_value": "64.20.61.215:5000",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.evilginx",
            "malware_alias": null,
            "malware_printable": "Evilginx",
            "first_seen_utc": "2026-08-05 09:46:50",
            "last_seen_utc": "2026-08-31 07:47:34",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Evilginx,EvilGoPhish",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1868754": [
        {
            "ioc_value": "57.154.16.246:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-08-05 09:46:46",
            "last_seen_utc": "2026-08-31 07:47:31",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1868753": [
        {
            "ioc_value": "45.38.20.38:8491",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-08-05 09:46:29",
            "last_seen_utc": "2026-08-31 07:47:14",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1868752": [
        {
            "ioc_value": "43.135.26.173:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-05 09:46:19",
            "last_seen_utc": "2026-08-31 07:47:04",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1868751": [
        {
            "ioc_value": "36.248.232.165:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-08-05 09:46:13",
            "last_seen_utc": "2026-08-31 07:46:53",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1868750": [
        {
            "ioc_value": "217.60.97.106:7707",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-08-05 09:45:56",
            "last_seen_utc": "2026-08-31 07:46:37",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1868748": [
        {
            "ioc_value": "203.98.68.17:1008",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-08-05 09:44:55",
            "last_seen_utc": "2026-08-31 07:45:42",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1868749": [
        {
            "ioc_value": "203.98.68.29:30300",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-08-05 09:44:55",
            "last_seen_utc": "2026-08-31 07:45:42",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1868747": [
        {
            "ioc_value": "196.251.107.131:7707",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-08-05 09:44:47",
            "last_seen_utc": "2026-08-31 07:45:28",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1868746": [
        {
            "ioc_value": "194.87.239.245:7682",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-08-05 09:44:44",
            "last_seen_utc": "2026-08-31 07:45:21",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1868745": [
        {
            "ioc_value": "193.149.185.215:4321",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-08-05 09:44:40",
            "last_seen_utc": "2026-08-31 07:45:12",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1868744": [
        {
            "ioc_value": "186.244.227.52:4321",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-08-05 09:44:34",
            "last_seen_utc": "2026-08-31 07:44:58",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1868740": [
        {
            "ioc_value": "186.169.88.130:5012",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-08-05 09:44:33",
            "last_seen_utc": "2026-08-31 07:44:58",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1868741": [
        {
            "ioc_value": "186.169.88.130:9140",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-08-05 09:44:33",
            "last_seen_utc": "2026-08-31 07:44:58",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1868742": [
        {
            "ioc_value": "186.244.227.104:4321",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-08-05 09:44:33",
            "last_seen_utc": "2026-08-31 07:44:58",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1868743": [
        {
            "ioc_value": "186.244.227.27:4321",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-08-05 09:44:33",
            "last_seen_utc": "2026-08-31 07:44:58",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1868736": [
        {
            "ioc_value": "185.212.129.70:9000",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.evilginx",
            "malware_alias": null,
            "malware_printable": "Evilginx",
            "first_seen_utc": "2026-08-05 09:44:29",
            "last_seen_utc": "2026-08-31 07:44:47",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Evilginx,EvilGoPhish",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1868737": [
        {
            "ioc_value": "185.212.129.89:9000",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.evilginx",
            "malware_alias": null,
            "malware_printable": "Evilginx",
            "first_seen_utc": "2026-08-05 09:44:29",
            "last_seen_utc": "2026-08-31 07:44:48",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Evilginx,EvilGoPhish",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1868738": [
        {
            "ioc_value": "185.212.131.112:9000",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.evilginx",
            "malware_alias": null,
            "malware_printable": "Evilginx",
            "first_seen_utc": "2026-08-05 09:44:29",
            "last_seen_utc": "2026-08-31 07:44:48",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Evilginx,EvilGoPhish",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1868739": [
        {
            "ioc_value": "185.212.131.113:9000",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.evilginx",
            "malware_alias": null,
            "malware_printable": "Evilginx",
            "first_seen_utc": "2026-08-05 09:44:29",
            "last_seen_utc": "2026-08-31 07:44:48",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Evilginx,EvilGoPhish",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1868735": [
        {
            "ioc_value": "185.174.102.28:55555",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-05 09:44:26",
            "last_seen_utc": "2026-08-31 07:44:43",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1868734": [
        {
            "ioc_value": "172.81.132.75:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-05 09:44:12",
            "last_seen_utc": "2026-08-31 07:44:26",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1868733": [
        {
            "ioc_value": "164.132.199.212:8089",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.havoc",
            "malware_alias": "Havokiz",
            "malware_printable": "Havoc",
            "first_seen_utc": "2026-08-05 09:44:06",
            "last_seen_utc": "2026-08-31 07:44:14",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Havoc",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1868732": [
        {
            "ioc_value": "160.20.109.52:32333",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-08-05 09:44:00",
            "last_seen_utc": "2026-08-31 07:44:10",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1868731": [
        {
            "ioc_value": "149.28.163.119:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-08-05 09:43:43",
            "last_seen_utc": "2026-08-31 07:43:52",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1868730": [
        {
            "ioc_value": "128.90.59.58:7070",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-08-05 09:43:27",
            "last_seen_utc": "2026-08-31 07:43:38",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1868729": [
        {
            "ioc_value": "122.51.212.92:39901",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.bianlian",
            "malware_alias": null,
            "malware_printable": "BianLian",
            "first_seen_utc": "2026-08-05 09:43:26",
            "last_seen_utc": "2026-08-31 07:43:35",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "Bianlian,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1868683": [
        {
            "ioc_value": "169.58.82.229:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-08-05 08:05:05",
            "last_seen_utc": "2026-08-31 07:48:39",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "cobaltstrike",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1868587": [
        {
            "ioc_value": "43.163.88.35:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-08-05 06:37:44",
            "last_seen_utc": "2026-08-31 07:48:49",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": null,
            "tags": "132203,c2,censys,cobalt strike",
            "anonymous": 0,
            "reporter": "sojubear"
        }
    ],
    "1868636": [
        {
            "ioc_value": "43.108.51.124:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-08-05 06:05:05",
            "last_seen_utc": "2026-08-31 07:48:47",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "cobaltstrike",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1868569": [
        {
            "ioc_value": "210.56.48.227:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-08-04 23:47:37",
            "last_seen_utc": "2026-08-31 07:48:44",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1868570": [
        {
            "ioc_value": "222.255.215.42:30005",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-08-04 23:47:37",
            "last_seen_utc": "2026-08-31 07:48:45",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1868505": [
        {
            "ioc_value": "93.82.26.41:8000",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.eye_pyramid",
            "malware_alias": null,
            "malware_printable": "Eye Pyramid",
            "first_seen_utc": "2026-08-04 19:46:40",
            "last_seen_utc": "2026-08-31 07:48:05",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,EyePyramid",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1868504": [
        {
            "ioc_value": "80.96.109.107:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-04 19:46:26",
            "last_seen_utc": "2026-08-31 07:47:46",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1868503": [
        {
            "ioc_value": "43.134.169.103:8080",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.havoc",
            "malware_alias": "Havokiz",
            "malware_printable": "Havoc",
            "first_seen_utc": "2026-08-04 19:45:49",
            "last_seen_utc": "2026-08-31 07:47:03",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Havoc",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1868502": [
        {
            "ioc_value": "35.202.238.13:8443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.evilginx",
            "malware_alias": null,
            "malware_printable": "Evilginx",
            "first_seen_utc": "2026-08-04 19:45:43",
            "last_seen_utc": "2026-08-31 07:46:53",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Evilginx,EvilGoPhish",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1868501": [
        {
            "ioc_value": "31.76.96.193:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "js.tsundere",
            "malware_alias": "DinDoor",
            "malware_printable": "Tsundere",
            "first_seen_utc": "2026-08-04 19:45:42",
            "last_seen_utc": "2026-08-31 07:46:49",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DinDoor,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1868500": [
        {
            "ioc_value": "3.122.223.106:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-08-04 19:45:38",
            "last_seen_utc": "2026-08-31 07:46:45",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1868499": [
        {
            "ioc_value": "207.189.25.132:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-04 19:44:44",
            "last_seen_utc": "2026-08-31 07:45:44",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1868498": [
        {
            "ioc_value": "203.98.68.17:30200",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-08-04 19:44:42",
            "last_seen_utc": "2026-08-31 07:45:42",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1868497": [
        {
            "ioc_value": "195.177.94.71:56001",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-04 19:44:33",
            "last_seen_utc": "2026-08-31 07:45:26",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1868495": [
        {
            "ioc_value": "176.97.114.8:56001",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-04 19:44:09",
            "last_seen_utc": "2026-08-31 07:44:32",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1868496": [
        {
            "ioc_value": "176.97.114.8:56002",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-04 19:44:09",
            "last_seen_utc": "2026-08-31 07:44:32",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1868494": [
        {
            "ioc_value": "172.182.216.158:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-08-04 19:44:03",
            "last_seen_utc": "2026-08-31 07:44:22",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1868492": [
        {
            "ioc_value": "161.97.154.193:56001",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-04 19:43:55",
            "last_seen_utc": "2026-08-31 07:44:11",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1868493": [
        {
            "ioc_value": "161.97.154.193:56002",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-04 19:43:55",
            "last_seen_utc": "2026-08-31 07:44:11",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1868491": [
        {
            "ioc_value": "153.75.88.67:6666",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-04 19:43:41",
            "last_seen_utc": "2026-08-31 07:43:56",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1868490": [
        {
            "ioc_value": "105.108.17.137:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-04 19:43:15",
            "last_seen_utc": "2026-08-31 07:43:20",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1868489": [
        {
            "ioc_value": "100.31.3.235:8082",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.danabot",
            "malware_alias": "DanaTools",
            "malware_printable": "DanaBot",
            "first_seen_utc": "2026-08-04 19:43:02",
            "last_seen_utc": "2026-08-31 07:43:03",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DanBot,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1868453": [
        {
            "ioc_value": "61.54.27.211:8082",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "vbs.vbrevshell",
            "malware_alias": null,
            "malware_printable": "VBREVSHELL",
            "first_seen_utc": "2026-08-04 18:00:04",
            "last_seen_utc": "2026-08-31 05:48:02",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": "https://tracker.viriback.com/index.php?q=61.54.27.211",
            "tags": "ViriBack,Vshell",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1868328": [
        {
            "ioc_value": "130.12.182.39:7001",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-08-04 14:05:07",
            "last_seen_utc": "2026-08-31 07:43:41",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "asyncrat",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1868327": [
        {
            "ioc_value": "130.12.182.39:6606",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-08-04 14:05:06",
            "last_seen_utc": "2026-08-31 07:43:41",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "asyncrat",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1868319": [
        {
            "ioc_value": "130.12.182.39:8808",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-08-04 13:05:09",
            "last_seen_utc": "2026-08-31 07:43:41",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "asyncrat",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1868287": [
        {
            "ioc_value": "79.110.49.186:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-08-04 11:47:25",
            "last_seen_utc": "2026-08-31 07:48:55",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1868286": [
        {
            "ioc_value": "169.58.82.229:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-08-04 11:47:08",
            "last_seen_utc": "2026-08-31 07:48:38",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1868285": [
        {
            "ioc_value": "102.204.223.230:5554",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-08-04 11:46:52",
            "last_seen_utc": "2026-08-31 07:48:23",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1868255": [
        {
            "ioc_value": "91.92.42.152:8080",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-08-04 09:46:41",
            "last_seen_utc": "2026-08-31 07:48:00",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1868254": [
        {
            "ioc_value": "89.36.231.206:65432",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-08-04 09:46:38",
            "last_seen_utc": "2026-08-31 07:47:55",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1868253": [
        {
            "ioc_value": "81.177.222.11:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-08-04 09:46:30",
            "last_seen_utc": "2026-08-31 07:47:46",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1868252": [
        {
            "ioc_value": "45.61.176.146:8443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.havoc",
            "malware_alias": "Havokiz",
            "malware_printable": "Havoc",
            "first_seen_utc": "2026-08-04 09:46:05",
            "last_seen_utc": "2026-08-31 07:47:16",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Havoc",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1868251": [
        {
            "ioc_value": "45.139.226.224:4321",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-08-04 09:45:57",
            "last_seen_utc": "2026-08-31 07:47:08",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1868250": [
        {
            "ioc_value": "27.124.36.136:56001",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-04 09:45:40",
            "last_seen_utc": "2026-08-31 07:46:43",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1868247": [
        {
            "ioc_value": "178.16.53.68:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-04 09:44:09",
            "last_seen_utc": "2026-08-31 07:44:34",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1868248": [
        {
            "ioc_value": "178.16.53.68:7707",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-08-04 09:44:09",
            "last_seen_utc": "2026-08-31 07:44:34",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1868246": [
        {
            "ioc_value": "172.111.232.133:7775",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.dcrat",
            "malware_alias": "DarkCrystal RAT",
            "malware_printable": "DCRat",
            "first_seen_utc": "2026-08-04 09:44:00",
            "last_seen_utc": "2026-08-31 07:44:21",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DCRat,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1868244": [
        {
            "ioc_value": "172.111.134.94:56011",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-04 09:43:59",
            "last_seen_utc": "2026-08-31 07:44:19",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1868245": [
        {
            "ioc_value": "172.111.134.94:56012",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-04 09:43:59",
            "last_seen_utc": "2026-08-31 07:44:20",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1868241": [
        {
            "ioc_value": "140.228.29.61:55555",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-04 09:43:31",
            "last_seen_utc": "2026-08-31 07:43:47",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1868240": [
        {
            "ioc_value": "138.124.62.3:4321",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-08-04 09:43:30",
            "last_seen_utc": "2026-08-31 07:43:45",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1868239": [
        {
            "ioc_value": "130.12.182.39:5333",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-08-04 09:43:25",
            "last_seen_utc": "2026-08-31 07:43:40",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1868238": [
        {
            "ioc_value": "122.51.212.92:39905",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.bianlian",
            "malware_alias": null,
            "malware_printable": "BianLian",
            "first_seen_utc": "2026-08-04 09:43:23",
            "last_seen_utc": "2026-08-31 07:43:35",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "Bianlian,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1868237": [
        {
            "ioc_value": "104.251.181.111:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-04 09:43:14",
            "last_seen_utc": "2026-08-31 07:43:19",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1868236": [
        {
            "ioc_value": "104.239.66.36:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-04 09:43:12",
            "last_seen_utc": "2026-08-31 07:43:15",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1868235": [
        {
            "ioc_value": "104.223.98.68:2028",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.dcrat",
            "malware_alias": "DarkCrystal RAT",
            "malware_printable": "DCRat",
            "first_seen_utc": "2026-08-04 09:43:11",
            "last_seen_utc": "2026-08-31 07:43:14",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DCRat,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1868193": [
        {
            "ioc_value": "178.16.55.104:8848",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-08-04 08:50:29",
            "last_seen_utc": "2026-08-31 07:44:35",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://bazaar.abuse.ch/sample/e7303de39d7b302ea161b61c4200b40ec9303dd848893096dced28351e2f4370/",
            "tags": "asyncrat",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1868136": [
        {
            "ioc_value": "64.89.160.127:6680",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-08-04 06:55:31",
            "last_seen_utc": "2026-08-31 07:47:35",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://bazaar.abuse.ch/sample/9ce274f0da79ad88585ef5377c9e5c3fa8027dd50e16c7cb9bfa133a08f2ead8/",
            "tags": "asyncrat",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1868107": [
        {
            "ioc_value": "136.115.85.178:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-08-04 06:05:07",
            "last_seen_utc": "2026-08-31 07:43:44",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "asyncrat",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1868106": [
        {
            "ioc_value": "195.177.94.210:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-08-04 06:05:06",
            "last_seen_utc": "2026-08-31 07:45:25",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "asyncrat",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1867971": [
        {
            "ioc_value": "189.249.195.86:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-08-04 05:21:19",
            "last_seen_utc": "2026-08-31 07:45:00",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://platform.censys.io/hosts/189.249.195.86?at_time=2026-08-03T16%3A58%3A19.500825484Z",
            "tags": "AS 8151,c2,censys,mythic,online",
            "anonymous": 0,
            "reporter": "f1nd3r"
        }
    ],
    "1868042": [
        {
            "ioc_value": "157.230.83.73:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-08-04 02:05:06",
            "last_seen_utc": "2026-08-31 07:44:06",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "mythic",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1867932": [
        {
            "ioc_value": "https://nonobody123.com/a85e9a98b9364c5d8f74.php",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.stealc",
            "malware_alias": null,
            "malware_printable": "Stealc",
            "first_seen_utc": "2026-08-03 19:54:25",
            "last_seen_utc": "2026-08-31 07:58:32",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "c2,loader,NEWN1,StealC,stealer",
            "anonymous": 0,
            "reporter": "Bitsight"
        }
    ],
    "1867961": [
        {
            "ioc_value": "5.56.25.151:6680",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-08-03 19:45:50",
            "last_seen_utc": "2026-08-31 07:47:26",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1867960": [
        {
            "ioc_value": "45.61.176.146:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.havoc",
            "malware_alias": "Havokiz",
            "malware_printable": "Havoc",
            "first_seen_utc": "2026-08-03 19:45:41",
            "last_seen_utc": "2026-08-31 07:47:16",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Havoc",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1867959": [
        {
            "ioc_value": "45.59.120.79:7001",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.dcrat",
            "malware_alias": "DarkCrystal RAT",
            "malware_printable": "DCRat",
            "first_seen_utc": "2026-08-03 19:45:40",
            "last_seen_utc": "2026-08-31 07:47:15",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DCRat,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1867958": [
        {
            "ioc_value": "23.160.168.51:56001",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-03 19:45:16",
            "last_seen_utc": "2026-08-31 07:46:39",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1867957": [
        {
            "ioc_value": "217.60.195.197:56003",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-03 19:45:13",
            "last_seen_utc": "2026-08-31 07:46:35",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1867956": [
        {
            "ioc_value": "198.46.173.17:8808",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-08-03 19:44:25",
            "last_seen_utc": "2026-08-31 07:45:31",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1867955": [
        {
            "ioc_value": "161.97.154.193:56003",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-03 19:43:49",
            "last_seen_utc": "2026-08-31 07:44:11",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1867954": [
        {
            "ioc_value": "130.12.182.39:6666",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-08-03 19:43:23",
            "last_seen_utc": "2026-08-31 07:43:41",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1867786": [
        {
            "ioc_value": "91.206.178.155:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.eye_pyramid",
            "malware_alias": null,
            "malware_printable": "Eye Pyramid",
            "first_seen_utc": "2026-08-03 09:46:43",
            "last_seen_utc": "2026-08-31 07:47:58",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,EyePyramid",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1867785": [
        {
            "ioc_value": "80.76.49.38:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-03 09:46:33",
            "last_seen_utc": "2026-08-31 07:47:45",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1867784": [
        {
            "ioc_value": "45.61.176.146:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.havoc",
            "malware_alias": "Havokiz",
            "malware_printable": "Havoc",
            "first_seen_utc": "2026-08-03 09:46:06",
            "last_seen_utc": "2026-08-31 07:47:16",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Havoc",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1867783": [
        {
            "ioc_value": "207.56.28.111:56002",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-03 09:44:45",
            "last_seen_utc": "2026-08-31 07:45:45",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1867782": [
        {
            "ioc_value": "207.56.28.111:56001",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-03 09:44:44",
            "last_seen_utc": "2026-08-31 07:45:45",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1867781": [
        {
            "ioc_value": "193.112.169.214:30727",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-08-03 09:44:27",
            "last_seen_utc": "2026-08-31 07:45:11",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1867780": [
        {
            "ioc_value": "192.159.99.55:8989",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.dcrat",
            "malware_alias": "DarkCrystal RAT",
            "malware_printable": "DCRat",
            "first_seen_utc": "2026-08-03 09:44:24",
            "last_seen_utc": "2026-08-31 07:45:05",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DCRat,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1867779": [
        {
            "ioc_value": "135.136.132.74:55555",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-03 09:43:28",
            "last_seen_utc": "2026-08-31 07:43:43",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1867777": [
        {
            "ioc_value": "104.207.90.3:2030",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.evilginx",
            "malware_alias": null,
            "malware_printable": "Evilginx",
            "first_seen_utc": "2026-08-03 09:43:12",
            "last_seen_utc": "2026-08-31 07:43:13",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Evilginx,EvilGoPhish",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1867778": [
        {
            "ioc_value": "104.207.90.93:2030",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.evilginx",
            "malware_alias": null,
            "malware_printable": "Evilginx",
            "first_seen_utc": "2026-08-03 09:43:12",
            "last_seen_utc": "2026-08-31 07:43:13",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Evilginx,EvilGoPhish",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1867730": [
        {
            "ioc_value": "bpo.pelorsm188.top",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-08-03 09:04:36",
            "last_seen_utc": "2026-08-30 18:46:34",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "Vidar",
            "anonymous": 0,
            "reporter": "crep1x"
        }
    ],
    "1867731": [
        {
            "ioc_value": "tyb.pelorsm188.top",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-08-03 09:04:36",
            "last_seen_utc": "2026-08-30 18:46:33",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "Vidar",
            "anonymous": 0,
            "reporter": "crep1x"
        }
    ],
    "1867732": [
        {
            "ioc_value": "sro.pelorsm188.top",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-08-03 09:04:36",
            "last_seen_utc": "2026-08-30 18:46:33",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "Vidar",
            "anonymous": 0,
            "reporter": "crep1x"
        }
    ],
    "1867733": [
        {
            "ioc_value": "ggr.pelorsm188.top",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-08-03 09:04:36",
            "last_seen_utc": "2026-08-30 18:46:34",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "Vidar",
            "anonymous": 0,
            "reporter": "crep1x"
        }
    ],
    "1867734": [
        {
            "ioc_value": "cto.pelorsm188.top",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-08-03 09:04:36",
            "last_seen_utc": "2026-08-30 18:46:34",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "Vidar",
            "anonymous": 0,
            "reporter": "crep1x"
        }
    ],
    "1867701": [
        {
            "ioc_value": "https://37.27.204.215/",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-08-03 08:50:28",
            "last_seen_utc": "2026-08-30 11:53:46",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "Vidar",
            "anonymous": 0,
            "reporter": "crep1x"
        }
    ],
    "1867690": [
        {
            "ioc_value": "https://65.108.197.205/",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-08-03 08:50:26",
            "last_seen_utc": "2026-08-30 19:49:33",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "Vidar",
            "anonymous": 0,
            "reporter": "crep1x"
        }
    ],
    "1867640": [
        {
            "ioc_value": "92.119.158.20:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-08-03 07:05:06",
            "last_seen_utc": "2026-08-31 07:48:03",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "mythic",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1867590": [
        {
            "ioc_value": "82.156.11.154:8082",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-08-03 01:05:05",
            "last_seen_utc": "2026-08-31 07:48:58",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "cobaltstrike",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1867535": [
        {
            "ioc_value": "38.60.230.135:6606",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-08-02 19:45:45",
            "last_seen_utc": "2026-08-31 07:46:59",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1867536": [
        {
            "ioc_value": "38.60.230.135:7707",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-08-02 19:45:45",
            "last_seen_utc": "2026-08-31 07:46:59",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1867537": [
        {
            "ioc_value": "38.60.230.135:8808",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-08-02 19:45:45",
            "last_seen_utc": "2026-08-31 07:46:59",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1867534": [
        {
            "ioc_value": "27.124.36.153:56003",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-02 19:45:35",
            "last_seen_utc": "2026-08-31 07:46:44",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1867532": [
        {
            "ioc_value": "217.60.77.60:56001",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-02 19:45:28",
            "last_seen_utc": "2026-08-31 07:46:37",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1867533": [
        {
            "ioc_value": "217.60.77.60:56002",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-02 19:45:28",
            "last_seen_utc": "2026-08-31 07:46:37",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1867530": [
        {
            "ioc_value": "207.56.28.108:56003",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-02 19:44:42",
            "last_seen_utc": "2026-08-31 07:45:45",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1867531": [
        {
            "ioc_value": "207.56.28.111:56003",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-02 19:44:42",
            "last_seen_utc": "2026-08-31 07:45:45",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1867529": [
        {
            "ioc_value": "198.46.173.17:6606",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-08-02 19:44:33",
            "last_seen_utc": "2026-08-31 07:45:31",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1867528": [
        {
            "ioc_value": "176.97.114.8:8848",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.dcrat",
            "malware_alias": "DarkCrystal RAT",
            "malware_printable": "DCRat",
            "first_seen_utc": "2026-08-02 19:44:07",
            "last_seen_utc": "2026-08-31 07:44:32",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DCRat,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1867527": [
        {
            "ioc_value": "109.248.151.114:9829",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-08-02 19:43:18",
            "last_seen_utc": "2026-08-31 07:43:28",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1867274": [
        {
            "ioc_value": "106.75.249.202:6666",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-08-02 11:46:58",
            "last_seen_utc": "2026-08-31 07:48:24",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1867257": [
        {
            "ioc_value": "43.131.251.190:8088",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-08-02 10:05:06",
            "last_seen_utc": "2026-08-31 07:47:01",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "mythic",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1867254": [
        {
            "ioc_value": "91.124.98.42:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-02 09:46:59",
            "last_seen_utc": "2026-08-31 07:47:56",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1867253": [
        {
            "ioc_value": "45.61.114.217:7707",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-08-02 09:46:21",
            "last_seen_utc": "2026-08-31 07:47:15",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1867251": [
        {
            "ioc_value": "38.247.147.37:56002",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-02 09:46:08",
            "last_seen_utc": "2026-08-31 07:46:58",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1867252": [
        {
            "ioc_value": "38.247.147.37:56003",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-02 09:46:08",
            "last_seen_utc": "2026-08-31 07:46:58",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1867250": [
        {
            "ioc_value": "38.247.147.37:56001",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-02 09:46:07",
            "last_seen_utc": "2026-08-31 07:46:58",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1867248": [
        {
            "ioc_value": "31.57.147.182:56001",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-02 09:45:57",
            "last_seen_utc": "2026-08-31 07:46:46",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1867249": [
        {
            "ioc_value": "31.57.147.182:56002",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-02 09:45:57",
            "last_seen_utc": "2026-08-31 07:46:46",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1867247": [
        {
            "ioc_value": "198.46.187.30:65528",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-08-02 09:44:44",
            "last_seen_utc": "2026-08-31 07:45:32",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1867246": [
        {
            "ioc_value": "194.59.30.183:56001",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-02 09:44:39",
            "last_seen_utc": "2026-08-31 07:45:19",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1867245": [
        {
            "ioc_value": "178.16.55.237:6443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-08-02 09:44:17",
            "last_seen_utc": "2026-08-31 07:44:35",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1867244": [
        {
            "ioc_value": "162.35.187.214:3333",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.evilginx",
            "malware_alias": null,
            "malware_printable": "Evilginx",
            "first_seen_utc": "2026-08-02 09:44:03",
            "last_seen_utc": "2026-08-31 07:44:13",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Evilginx,EvilGoPhish",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1867243": [
        {
            "ioc_value": "15.235.204.51:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.havoc",
            "malware_alias": "Havokiz",
            "malware_printable": "Havoc",
            "first_seen_utc": "2026-08-02 09:43:44",
            "last_seen_utc": "2026-08-31 07:43:53",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Havoc",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1867044": [
        {
            "ioc_value": "54.178.100.27:8022",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-08-01 23:47:05",
            "last_seen_utc": "2026-08-31 07:48:54",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1867043": [
        {
            "ioc_value": "185.92.190.177:8696",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-08-01 23:46:49",
            "last_seen_utc": "2026-08-31 07:48:41",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1867042": [
        {
            "ioc_value": "156.224.18.21:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-08-01 23:46:46",
            "last_seen_utc": "2026-08-31 07:48:37",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1867041": [
        {
            "ioc_value": "cs.rainbowrain.top",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-08-01 23:46:25",
            "last_seen_utc": "2026-08-31 07:48:15",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1867022": [
        {
            "ioc_value": "157.20.182.22:6666",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-08-01 23:05:05",
            "last_seen_utc": "2026-08-31 07:44:05",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "asyncrat",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1866972": [
        {
            "ioc_value": "64.20.61.215:8443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.evilginx",
            "malware_alias": null,
            "malware_printable": "Evilginx",
            "first_seen_utc": "2026-08-01 19:46:16",
            "last_seen_utc": "2026-08-31 07:47:34",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Evilginx,EvilGoPhish",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1866971": [
        {
            "ioc_value": "46.246.82.10:6490",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.dcrat",
            "malware_alias": "DarkCrystal RAT",
            "malware_printable": "DCRat",
            "first_seen_utc": "2026-08-01 19:46:07",
            "last_seen_utc": "2026-08-31 07:47:23",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DCRat,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1866970": [
        {
            "ioc_value": "45.192.211.77:56003",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-01 19:45:56",
            "last_seen_utc": "2026-08-31 07:47:13",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1866969": [
        {
            "ioc_value": "217.60.77.60:56003",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-01 19:45:32",
            "last_seen_utc": "2026-08-31 07:46:37",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1866968": [
        {
            "ioc_value": "195.177.94.61:56003",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-01 19:44:38",
            "last_seen_utc": "2026-08-31 07:45:26",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1866967": [
        {
            "ioc_value": "155.2.192.251:56003",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-01 19:43:46",
            "last_seen_utc": "2026-08-31 07:44:01",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1866966": [
        {
            "ioc_value": "139.199.160.80:32408",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-08-01 19:43:31",
            "last_seen_utc": "2026-08-31 07:43:46",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1866963": [
        {
            "ioc_value": "104.251.181.111:56003",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-01 19:43:16",
            "last_seen_utc": "2026-08-31 07:43:19",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1866964": [
        {
            "ioc_value": "106.53.107.131:30943",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-08-01 19:43:16",
            "last_seen_utc": "2026-08-31 07:43:21",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1866965": [
        {
            "ioc_value": "107.152.42.223:34321",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-08-01 19:43:16",
            "last_seen_utc": "2026-08-31 07:43:21",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1866962": [
        {
            "ioc_value": "103.148.58.18:56003",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-01 19:43:07",
            "last_seen_utc": "2026-08-31 07:43:07",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1866960": [
        {
            "ioc_value": "101.36.123.12:34321",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-08-01 19:43:03",
            "last_seen_utc": "2026-08-31 07:43:04",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1866961": [
        {
            "ioc_value": "102.117.164.193:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-08-01 19:43:03",
            "last_seen_utc": "2026-08-31 07:43:04",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1866624": [
        {
            "ioc_value": "87.199.203.248:3333",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.evilginx",
            "malware_alias": null,
            "malware_printable": "Evilginx",
            "first_seen_utc": "2026-08-01 09:46:41",
            "last_seen_utc": "2026-08-31 07:47:52",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Evilginx,EvilGoPhish",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1866622": [
        {
            "ioc_value": "85.11.167.134:56001",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-01 09:46:39",
            "last_seen_utc": "2026-08-31 07:47:49",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1866623": [
        {
            "ioc_value": "85.11.167.134:56002",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-01 09:46:39",
            "last_seen_utc": "2026-08-31 07:47:49",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1866621": [
        {
            "ioc_value": "77.246.111.132:3333",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.evilginx",
            "malware_alias": null,
            "malware_printable": "Evilginx",
            "first_seen_utc": "2026-08-01 09:46:33",
            "last_seen_utc": "2026-08-31 07:47:41",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Evilginx,EvilGoPhish",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1866620": [
        {
            "ioc_value": "47.87.84.177:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-08-01 09:46:18",
            "last_seen_utc": "2026-08-31 07:47:24",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1866618": [
        {
            "ioc_value": "43.213.166.7:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-08-01 09:45:59",
            "last_seen_utc": "2026-08-31 07:47:05",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1866619": [
        {
            "ioc_value": "43.213.254.221:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-08-01 09:45:59",
            "last_seen_utc": "2026-08-31 07:47:05",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1866617": [
        {
            "ioc_value": "31.57.38.232:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-01 09:45:50",
            "last_seen_utc": "2026-08-31 07:46:48",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1866616": [
        {
            "ioc_value": "3.115.55.199:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.brute_ratel_c4",
            "malware_alias": "BOLDBADGER,BruteRatel",
            "malware_printable": "Brute Ratel C4",
            "first_seen_utc": "2026-08-01 09:45:47",
            "last_seen_utc": "2026-08-31 07:46:44",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "BruteRatel,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1866615": [
        {
            "ioc_value": "217.60.195.197:56002",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-01 09:45:39",
            "last_seen_utc": "2026-08-31 07:46:35",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1866614": [
        {
            "ioc_value": "217.60.195.197:56001",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-01 09:45:38",
            "last_seen_utc": "2026-08-31 07:46:35",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1866613": [
        {
            "ioc_value": "202.182.108.40:21157",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-08-01 09:44:46",
            "last_seen_utc": "2026-08-31 07:45:40",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1866612": [
        {
            "ioc_value": "20.125.96.116:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-08-01 09:44:44",
            "last_seen_utc": "2026-08-31 07:45:37",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1866611": [
        {
            "ioc_value": "198.46.187.30:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-08-01 09:44:41",
            "last_seen_utc": "2026-08-31 07:45:32",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1866609": [
        {
            "ioc_value": "192.159.99.70:56002",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-01 09:44:31",
            "last_seen_utc": "2026-08-31 07:45:05",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1866610": [
        {
            "ioc_value": "192.162.199.180:4321",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-08-01 09:44:31",
            "last_seen_utc": "2026-08-31 07:45:06",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1866608": [
        {
            "ioc_value": "192.159.99.70:56001",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-01 09:44:30",
            "last_seen_utc": "2026-08-31 07:45:05",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1866607": [
        {
            "ioc_value": "168.144.89.89:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.havoc",
            "malware_alias": "Havokiz",
            "malware_printable": "Havoc",
            "first_seen_utc": "2026-08-01 09:44:05",
            "last_seen_utc": "2026-08-31 07:44:17",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Havoc",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1866606": [
        {
            "ioc_value": "16.76.80.179:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.brute_ratel_c4",
            "malware_alias": "BOLDBADGER,BruteRatel",
            "malware_printable": "Brute Ratel C4",
            "first_seen_utc": "2026-08-01 09:43:58",
            "last_seen_utc": "2026-08-31 07:44:10",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "BruteRatel,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1866603": [
        {
            "ioc_value": "104.251.181.111:56001",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-01 09:43:16",
            "last_seen_utc": "2026-08-31 07:43:19",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1866604": [
        {
            "ioc_value": "104.251.181.111:56002",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-01 09:43:16",
            "last_seen_utc": "2026-08-31 07:43:19",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1866605": [
        {
            "ioc_value": "104.253.79.117:4321",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-08-01 09:43:16",
            "last_seen_utc": "2026-08-31 07:43:20",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1866602": [
        {
            "ioc_value": "103.148.58.8:56002",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-01 09:43:09",
            "last_seen_utc": "2026-08-31 07:43:08",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1866597": [
        {
            "ioc_value": "103.148.58.10:56001",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-01 09:43:08",
            "last_seen_utc": "2026-08-31 07:43:07",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1866598": [
        {
            "ioc_value": "103.148.58.10:56002",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-01 09:43:08",
            "last_seen_utc": "2026-08-31 07:43:07",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1866599": [
        {
            "ioc_value": "103.148.58.18:56001",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-01 09:43:08",
            "last_seen_utc": "2026-08-31 07:43:07",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1866600": [
        {
            "ioc_value": "103.148.58.18:56002",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-01 09:43:08",
            "last_seen_utc": "2026-08-31 07:43:07",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1866601": [
        {
            "ioc_value": "103.148.58.8:56001",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-01 09:43:08",
            "last_seen_utc": "2026-08-31 07:43:08",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1866579": [
        {
            "ioc_value": "108.165.147.244:4444",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-08-01 07:59:50",
            "last_seen_utc": "2026-08-31 07:48:24",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-987654321",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1866518": [
        {
            "ioc_value": "124.222.145.172:8084",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-08-01 02:05:06",
            "last_seen_utc": "2026-08-31 07:48:33",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "cobaltstrike",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1866405": [
        {
            "ioc_value": "185.92.190.175:8696",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-07-31 23:46:44",
            "last_seen_utc": "2026-08-31 07:48:41",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1866406": [
        {
            "ioc_value": "185.92.190.176:8696",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-07-31 23:46:44",
            "last_seen_utc": "2026-08-31 07:48:41",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1866402": [
        {
            "ioc_value": "185.182.65.34:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-07-31 23:46:43",
            "last_seen_utc": "2026-08-31 07:48:40",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1866403": [
        {
            "ioc_value": "185.92.190.173:8696",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-07-31 23:46:43",
            "last_seen_utc": "2026-08-31 07:48:40",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1866404": [
        {
            "ioc_value": "185.92.190.174:8696",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-07-31 23:46:43",
            "last_seen_utc": "2026-08-31 07:48:40",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1866366": [
        {
            "ioc_value": "93.152.223.242:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "js.tsundere",
            "malware_alias": "DinDoor",
            "malware_printable": "Tsundere",
            "first_seen_utc": "2026-07-31 19:46:12",
            "last_seen_utc": "2026-08-31 07:48:05",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DinDoor,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1866365": [
        {
            "ioc_value": "93.115.27.97:8848",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.dcrat",
            "malware_alias": "DarkCrystal RAT",
            "malware_printable": "DCRat",
            "first_seen_utc": "2026-07-31 19:46:11",
            "last_seen_utc": "2026-08-31 07:48:04",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DCRat,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1866364": [
        {
            "ioc_value": "38.240.37.142:56003",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-07-31 19:45:26",
            "last_seen_utc": "2026-08-31 07:46:57",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1866363": [
        {
            "ioc_value": "31.57.38.232:56003",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-07-31 19:45:21",
            "last_seen_utc": "2026-08-31 07:46:48",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1866362": [
        {
            "ioc_value": "23.227.196.18:43655",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-07-31 19:45:14",
            "last_seen_utc": "2026-08-31 07:46:40",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1866361": [
        {
            "ioc_value": "194.62.248.129:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-07-31 19:44:21",
            "last_seen_utc": "2026-08-31 07:45:21",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1866360": [
        {
            "ioc_value": "193.138.195.29:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-07-31 19:44:18",
            "last_seen_utc": "2026-08-31 07:45:12",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1866359": [
        {
            "ioc_value": "185.174.102.5:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-07-31 19:44:09",
            "last_seen_utc": "2026-08-31 07:44:43",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1866358": [
        {
            "ioc_value": "167.172.142.69:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.havoc",
            "malware_alias": "Havokiz",
            "malware_printable": "Havoc",
            "first_seen_utc": "2026-07-31 19:43:52",
            "last_seen_utc": "2026-08-31 07:44:15",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Havoc",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1866357": [
        {
            "ioc_value": "118.107.46.207:8848",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.dcrat",
            "malware_alias": "DarkCrystal RAT",
            "malware_printable": "DCRat",
            "first_seen_utc": "2026-07-31 19:43:20",
            "last_seen_utc": "2026-08-31 07:43:33",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DCRat,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1866355": [
        {
            "ioc_value": "118.107.46.204:8848",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.dcrat",
            "malware_alias": "DarkCrystal RAT",
            "malware_printable": "DCRat",
            "first_seen_utc": "2026-07-31 19:43:19",
            "last_seen_utc": "2026-08-31 07:43:33",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DCRat,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1866356": [
        {
            "ioc_value": "118.107.46.207:12159",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.dcrat",
            "malware_alias": "DarkCrystal RAT",
            "malware_printable": "DCRat",
            "first_seen_utc": "2026-07-31 19:43:19",
            "last_seen_utc": "2026-08-31 07:43:33",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DCRat,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1866062": [
        {
            "ioc_value": "156.239.47.223:6005",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-07-31 11:47:13",
            "last_seen_utc": "2026-08-31 07:48:37",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1866061": [
        {
            "ioc_value": "156.224.18.21:8083",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-07-31 11:47:12",
            "last_seen_utc": "2026-08-31 07:48:37",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1866034": [
        {
            "ioc_value": "188.166.238.207:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-07-31 10:05:08",
            "last_seen_utc": "2026-08-31 07:44:59",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "mythic",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1866020": [
        {
            "ioc_value": "95.133.166.43:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-07-31 09:46:54",
            "last_seen_utc": "2026-08-31 07:48:11",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1866019": [
        {
            "ioc_value": "89.213.118.63:56002",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-07-31 09:46:47",
            "last_seen_utc": "2026-08-30 18:46:43",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1866018": [
        {
            "ioc_value": "82.22.204.150:56001",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-07-31 09:46:40",
            "last_seen_utc": "2026-08-30 18:46:38",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1866017": [
        {
            "ioc_value": "27.124.36.153:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-07-31 09:45:48",
            "last_seen_utc": "2026-08-31 07:46:44",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1866015": [
        {
            "ioc_value": "209.99.190.97:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "js.tsundere",
            "malware_alias": "DinDoor",
            "malware_printable": "Tsundere",
            "first_seen_utc": "2026-07-31 09:44:55",
            "last_seen_utc": "2026-08-31 07:45:49",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DinDoor,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1866014": [
        {
            "ioc_value": "207.174.0.103:56002",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-07-31 09:44:51",
            "last_seen_utc": "2026-08-30 18:44:53",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1866013": [
        {
            "ioc_value": "195.177.94.169:8080",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-07-31 09:44:40",
            "last_seen_utc": "2026-08-31 07:45:24",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1866011": [
        {
            "ioc_value": "194.59.30.109:6606",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-07-31 09:44:38",
            "last_seen_utc": "2026-08-30 18:44:38",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1866012": [
        {
            "ioc_value": "194.59.30.183:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-07-31 09:44:38",
            "last_seen_utc": "2026-08-31 07:45:18",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1866010": [
        {
            "ioc_value": "181.215.242.84:56001",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-07-31 09:44:19",
            "last_seen_utc": "2026-08-30 18:44:16",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1866009": [
        {
            "ioc_value": "157.254.194.126:1447",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-07-31 09:43:56",
            "last_seen_utc": "2026-08-30 18:43:50",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1866008": [
        {
            "ioc_value": "13.205.246.212:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-07-31 09:43:27",
            "last_seen_utc": "2026-08-31 07:43:39",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1866007": [
        {
            "ioc_value": "104.243.248.63:3608",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-07-31 09:43:15",
            "last_seen_utc": "2026-08-31 07:43:16",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1865067": [
        {
            "ioc_value": "27.71.16.98:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-07-31 05:45:43",
            "last_seen_utc": "2026-08-31 07:48:45",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": null,
            "tags": "7552,c2,censys,cobalt strike",
            "anonymous": 0,
            "reporter": "sojubear"
        }
    ],
    "1865072": [
        {
            "ioc_value": "124.220.34.180:6666",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-07-31 05:45:41",
            "last_seen_utc": "2026-08-31 07:48:32",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": null,
            "tags": "45090,c2,censys,cobalt strike",
            "anonymous": 0,
            "reporter": "sojubear"
        }
    ],
    "1865074": [
        {
            "ioc_value": "111.170.148.141:113",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-07-31 05:45:40",
            "last_seen_utc": "2026-08-31 07:48:25",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": null,
            "tags": "151185,c2,censys,cobalt strike",
            "anonymous": 0,
            "reporter": "sojubear"
        }
    ],
    "1865068": [
        {
            "ioc_value": "114.132.155.197:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-07-31 01:05:06",
            "last_seen_utc": "2026-08-31 07:43:31",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "mythic",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1865052": [
        {
            "ioc_value": "151.244.243.42:4443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-07-30 23:46:22",
            "last_seen_utc": "2026-08-31 07:48:34",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1864997": [
        {
            "ioc_value": "51.79.209.228:56001",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-07-30 19:46:08",
            "last_seen_utc": "2026-08-30 08:46:44",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1864998": [
        {
            "ioc_value": "51.79.209.228:56002",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-07-30 19:46:08",
            "last_seen_utc": "2026-08-30 08:46:44",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1864999": [
        {
            "ioc_value": "51.79.209.228:56003",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-07-30 19:46:08",
            "last_seen_utc": "2026-08-30 08:46:44",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1864996": [
        {
            "ioc_value": "46.246.14.5:8848",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.dcrat",
            "malware_alias": "DarkCrystal RAT",
            "malware_printable": "DCRat",
            "first_seen_utc": "2026-07-30 19:46:00",
            "last_seen_utc": "2026-08-30 08:46:39",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DCRat,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1864995": [
        {
            "ioc_value": "46.149.71.165:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-07-30 19:45:58",
            "last_seen_utc": "2026-08-31 07:47:20",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1864994": [
        {
            "ioc_value": "35.72.170.195:21672",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-07-30 19:45:39",
            "last_seen_utc": "2026-08-31 07:46:53",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1864993": [
        {
            "ioc_value": "27.124.36.136:56002",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-07-30 19:45:33",
            "last_seen_utc": "2026-08-31 07:46:43",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1864992": [
        {
            "ioc_value": "20.236.181.110:4321",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-07-30 19:44:37",
            "last_seen_utc": "2026-08-31 07:45:38",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1864988": [
        {
            "ioc_value": "195.177.94.109:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-07-30 19:44:30",
            "last_seen_utc": "2026-08-30 08:44:51",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1864989": [
        {
            "ioc_value": "195.177.94.69:27220",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-07-30 19:44:30",
            "last_seen_utc": "2026-08-30 08:44:52",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1864990": [
        {
            "ioc_value": "195.177.94.69:27221",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-07-30 19:44:30",
            "last_seen_utc": "2026-08-30 08:44:52",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1864991": [
        {
            "ioc_value": "195.242.118.106:4321",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-07-30 19:44:30",
            "last_seen_utc": "2026-08-31 07:45:27",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1864986": [
        {
            "ioc_value": "194.59.31.142:7707",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-07-30 19:44:29",
            "last_seen_utc": "2026-08-30 08:44:49",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1864987": [
        {
            "ioc_value": "194.59.31.142:8808",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-07-30 19:44:29",
            "last_seen_utc": "2026-08-30 08:44:49",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1864985": [
        {
            "ioc_value": "185.139.228.93:4321",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-07-30 19:44:15",
            "last_seen_utc": "2026-08-31 07:44:41",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1864984": [
        {
            "ioc_value": "185.103.167.150:8808",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-07-30 19:44:12",
            "last_seen_utc": "2026-08-30 08:44:26",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1864983": [
        {
            "ioc_value": "18.178.127.205:21672",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-07-30 19:44:11",
            "last_seen_utc": "2026-08-31 07:44:38",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1864982": [
        {
            "ioc_value": "18.139.36.190:24610",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-07-30 19:44:10",
            "last_seen_utc": "2026-08-30 08:44:23",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1864981": [
        {
            "ioc_value": "172.96.137.123:8443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-07-30 19:44:04",
            "last_seen_utc": "2026-08-30 08:44:16",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1864980": [
        {
            "ioc_value": "154.215.14.139:8808",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-07-30 19:43:41",
            "last_seen_utc": "2026-08-30 08:43:49",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1864979": [
        {
            "ioc_value": "132.226.72.148:4321",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-07-30 19:43:26",
            "last_seen_utc": "2026-08-31 07:43:42",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1864976": [
        {
            "ioc_value": "118.107.46.177:12159",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.dcrat",
            "malware_alias": "DarkCrystal RAT",
            "malware_printable": "DCRat",
            "first_seen_utc": "2026-07-30 19:43:21",
            "last_seen_utc": "2026-08-31 07:43:33",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DCRat,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1864977": [
        {
            "ioc_value": "118.107.46.177:8848",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.dcrat",
            "malware_alias": "DarkCrystal RAT",
            "malware_printable": "DCRat",
            "first_seen_utc": "2026-07-30 19:43:21",
            "last_seen_utc": "2026-08-31 07:43:33",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DCRat,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1864978": [
        {
            "ioc_value": "118.107.46.204:12159",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.dcrat",
            "malware_alias": "DarkCrystal RAT",
            "malware_printable": "DCRat",
            "first_seen_utc": "2026-07-30 19:43:21",
            "last_seen_utc": "2026-08-31 07:43:33",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DCRat,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1864975": [
        {
            "ioc_value": "107.175.32.45:8761",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-07-30 19:43:16",
            "last_seen_utc": "2026-08-31 07:43:24",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1864974": [
        {
            "ioc_value": "104.207.90.244:2030",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.evilginx",
            "malware_alias": null,
            "malware_printable": "Evilginx",
            "first_seen_utc": "2026-07-30 19:43:12",
            "last_seen_utc": "2026-08-30 08:43:13",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Evilginx,EvilGoPhish",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1864973": [
        {
            "ioc_value": "103.53.80.201:3312",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-07-30 19:43:09",
            "last_seen_utc": "2026-08-31 07:43:10",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1864706": [
        {
            "ioc_value": "93.152.223.221:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "js.tsundere",
            "malware_alias": "DinDoor",
            "malware_printable": "Tsundere",
            "first_seen_utc": "2026-07-30 09:46:46",
            "last_seen_utc": "2026-08-31 07:48:04",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DinDoor,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1864705": [
        {
            "ioc_value": "51.79.185.253:56003",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-07-30 09:46:19",
            "last_seen_utc": "2026-08-29 18:46:27",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1864704": [
        {
            "ioc_value": "50.114.184.63:444",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-07-30 09:46:18",
            "last_seen_utc": "2026-08-31 07:47:26",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1864703": [
        {
            "ioc_value": "50.114.184.63:442",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-07-30 09:46:17",
            "last_seen_utc": "2026-08-31 07:47:26",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1864702": [
        {
            "ioc_value": "46.151.182.16:2202",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-07-30 09:46:11",
            "last_seen_utc": "2026-08-31 07:47:20",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1864701": [
        {
            "ioc_value": "27.124.36.151:56002",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-07-30 09:45:43",
            "last_seen_utc": "2026-08-31 07:46:44",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1864700": [
        {
            "ioc_value": "217.60.241.73:7011",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-07-30 09:45:35",
            "last_seen_utc": "2026-08-29 18:45:46",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1864699": [
        {
            "ioc_value": "209.99.190.23:45001",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-07-30 09:44:46",
            "last_seen_utc": "2026-08-29 18:45:06",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1864698": [
        {
            "ioc_value": "2.27.248.116:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "js.tsundere",
            "malware_alias": "DinDoor",
            "malware_printable": "Tsundere",
            "first_seen_utc": "2026-07-30 09:44:36",
            "last_seen_utc": "2026-08-31 07:45:34",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DinDoor,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1864697": [
        {
            "ioc_value": "176.65.148.198:7777",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-07-30 09:44:08",
            "last_seen_utc": "2026-08-29 08:44:18",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1864696": [
        {
            "ioc_value": "173.199.70.174:14321",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-07-30 09:44:06",
            "last_seen_utc": "2026-08-31 07:44:29",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1864694": [
        {
            "ioc_value": "144.172.93.33:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.havoc",
            "malware_alias": "Havokiz",
            "malware_printable": "Havoc",
            "first_seen_utc": "2026-07-30 09:43:35",
            "last_seen_utc": "2026-08-29 18:43:39",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Havoc",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1864693": [
        {
            "ioc_value": "103.148.58.8:56003",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-07-30 09:43:08",
            "last_seen_utc": "2026-08-31 07:43:08",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1864665": [
        {
            "ioc_value": "195.177.94.109:56003",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-07-30 09:34:33",
            "last_seen_utc": "2026-08-29 18:44:44",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "",
            "tags": "PureHVNC,PureRAT,ResolverRAT",
            "anonymous": 0,
            "reporter": "whoamix302"
        }
    ],
    "1864666": [
        {
            "ioc_value": "195.177.94.109:56002",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-07-30 09:34:33",
            "last_seen_utc": "2026-08-29 18:44:44",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "",
            "tags": "PureHVNC,PureRAT,ResolverRAT",
            "anonymous": 0,
            "reporter": "whoamix302"
        }
    ],
    "1864673": [
        {
            "ioc_value": "103.148.58.10:56003",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-07-30 09:34:33",
            "last_seen_utc": "2026-08-31 07:43:07",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "",
            "tags": "PureHVNC,PureRAT,ResolverRAT",
            "anonymous": 0,
            "reporter": "whoamix302"
        }
    ],
    "1864645": [
        {
            "ioc_value": "188.209.158.220:56003",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-07-30 09:34:32",
            "last_seen_utc": "2026-08-31 07:45:00",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "",
            "tags": "PureHVNC,PureRAT,ResolverRAT",
            "anonymous": 0,
            "reporter": "whoamix302"
        }
    ],
    "1864649": [
        {
            "ioc_value": "184.174.20.138:56003",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-07-30 09:34:32",
            "last_seen_utc": "2026-08-31 07:44:40",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "",
            "tags": "PureHVNC,PureRAT,ResolverRAT",
            "anonymous": 0,
            "reporter": "whoamix302"
        }
    ],
    "1864652": [
        {
            "ioc_value": "85.11.167.61:8000",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-07-30 09:34:32",
            "last_seen_utc": "2026-08-31 07:47:50",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "",
            "tags": "PureHVNC,PureRAT,ResolverRAT",
            "anonymous": 0,
            "reporter": "whoamix302"
        }
    ],
    "1864643": [
        {
            "ioc_value": "188.209.158.220:56002",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-07-30 09:34:31",
            "last_seen_utc": "2026-08-31 07:44:59",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "",
            "tags": "PureHVNC,PureRAT,ResolverRAT",
            "anonymous": 0,
            "reporter": "whoamix302"
        }
    ],
    "1864644": [
        {
            "ioc_value": "188.209.158.220:56001",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-07-30 09:34:31",
            "last_seen_utc": "2026-08-31 07:44:59",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "",
            "tags": "PureHVNC,PureRAT,ResolverRAT",
            "anonymous": 0,
            "reporter": "whoamix302"
        }
    ],
    "1863827": [
        {
            "ioc_value": "156.224.18.21:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-07-29 23:46:20",
            "last_seen_utc": "2026-08-30 08:47:41",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1863593": [
        {
            "ioc_value": "91.199.133.133:8080",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.mirai",
            "malware_alias": "Katana",
            "malware_printable": "Mirai",
            "first_seen_utc": "2026-07-29 19:46:24",
            "last_seen_utc": "2026-08-30 08:47:11",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mirai",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1863592": [
        {
            "ioc_value": "78.153.149.82:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.mirai",
            "malware_alias": "Katana",
            "malware_printable": "Mirai",
            "first_seen_utc": "2026-07-29 19:46:13",
            "last_seen_utc": "2026-08-31 07:47:42",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mirai",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1863590": [
        {
            "ioc_value": "67.210.97.40:7707",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-07-29 19:46:10",
            "last_seen_utc": "2026-08-31 07:47:39",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1863591": [
        {
            "ioc_value": "67.210.97.40:8808",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-07-29 19:46:10",
            "last_seen_utc": "2026-08-31 07:47:39",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1863589": [
        {
            "ioc_value": "57.129.92.151:4321",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-07-29 19:46:04",
            "last_seen_utc": "2026-08-31 07:47:31",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1863587": [
        {
            "ioc_value": "51.79.185.253:56001",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-07-29 19:46:01",
            "last_seen_utc": "2026-08-31 07:47:27",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1863588": [
        {
            "ioc_value": "51.79.185.253:56002",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-07-29 19:46:01",
            "last_seen_utc": "2026-08-31 07:47:27",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1863586": [
        {
            "ioc_value": "45.195.8.67:4321",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-07-29 19:45:46",
            "last_seen_utc": "2026-08-31 07:47:13",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1863585": [
        {
            "ioc_value": "43.213.254.221:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-07-29 19:45:41",
            "last_seen_utc": "2026-08-31 07:47:05",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1863583": [
        {
            "ioc_value": "27.124.36.151:56001",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-07-29 19:45:30",
            "last_seen_utc": "2026-08-31 07:46:44",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1863584": [
        {
            "ioc_value": "27.124.36.151:56003",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-07-29 19:45:30",
            "last_seen_utc": "2026-08-31 07:46:44",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1863579": [
        {
            "ioc_value": "194.59.31.51:8808",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-07-29 19:44:28",
            "last_seen_utc": "2026-08-29 08:44:51",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1863580": [
        {
            "ioc_value": "195.20.17.146:56776",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-07-29 19:44:28",
            "last_seen_utc": "2026-08-29 08:44:55",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1863578": [
        {
            "ioc_value": "194.59.31.51:7707",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-07-29 19:44:27",
            "last_seen_utc": "2026-08-29 08:44:51",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1863577": [
        {
            "ioc_value": "192.71.244.238:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-07-29 19:44:25",
            "last_seen_utc": "2026-08-29 08:44:46",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1863576": [
        {
            "ioc_value": "192.253.245.178:2026",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.dcrat",
            "malware_alias": "DarkCrystal RAT",
            "malware_printable": "DCRat",
            "first_seen_utc": "2026-07-29 19:44:24",
            "last_seen_utc": "2026-08-29 08:44:45",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DCRat,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1863575": [
        {
            "ioc_value": "185.212.128.207:9000",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.evilginx",
            "malware_alias": null,
            "malware_printable": "Evilginx",
            "first_seen_utc": "2026-07-29 19:44:16",
            "last_seen_utc": "2026-08-31 07:44:45",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Evilginx,EvilGoPhish",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1863574": [
        {
            "ioc_value": "185.174.102.28:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-07-29 19:44:15",
            "last_seen_utc": "2026-08-31 07:44:43",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1863573": [
        {
            "ioc_value": "178.16.53.65:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-07-29 19:44:08",
            "last_seen_utc": "2026-08-31 07:44:34",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1863572": [
        {
            "ioc_value": "172.86.89.227:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-07-29 19:44:02",
            "last_seen_utc": "2026-08-29 08:44:14",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1863571": [
        {
            "ioc_value": "162.216.231.230:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-07-29 19:43:54",
            "last_seen_utc": "2026-08-29 08:44:00",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1863570": [
        {
            "ioc_value": "155.2.192.251:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-07-29 19:43:45",
            "last_seen_utc": "2026-08-31 07:44:01",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1863569": [
        {
            "ioc_value": "154.194.50.252:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-07-29 19:43:42",
            "last_seen_utc": "2026-08-31 07:43:57",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1863568": [
        {
            "ioc_value": "149.56.30.94:3122",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.chaos",
            "malware_alias": "FakeRyuk,RyukJoke,Yashma",
            "malware_printable": "Chaos",
            "first_seen_utc": "2026-07-29 19:43:39",
            "last_seen_utc": "2026-08-29 08:43:43",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CHAOS,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1863567": [
        {
            "ioc_value": "142.93.52.11:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-07-29 19:43:33",
            "last_seen_utc": "2026-08-31 07:43:48",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1863566": [
        {
            "ioc_value": "130.12.182.209:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-07-29 19:43:26",
            "last_seen_utc": "2026-08-31 07:43:39",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1863563": [
        {
            "ioc_value": "104.239.66.154:56001",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-07-29 19:43:14",
            "last_seen_utc": "2026-08-30 18:43:12",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1863564": [
        {
            "ioc_value": "104.239.66.154:56002",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-07-29 19:43:14",
            "last_seen_utc": "2026-08-30 18:43:12",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1863565": [
        {
            "ioc_value": "104.239.66.154:56003",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-07-29 19:43:14",
            "last_seen_utc": "2026-08-30 18:43:12",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1863562": [
        {
            "ioc_value": "103.97.131.179:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-07-29 19:43:12",
            "last_seen_utc": "2026-08-31 07:43:12",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1863378": [
        {
            "ioc_value": "14.225.212.124:30005",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-07-29 11:47:01",
            "last_seen_utc": "2026-08-31 07:48:33",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1863346": [
        {
            "ioc_value": "93.152.223.222:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "js.tsundere",
            "malware_alias": "DinDoor",
            "malware_printable": "Tsundere",
            "first_seen_utc": "2026-07-29 09:46:12",
            "last_seen_utc": "2026-08-31 07:48:04",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DinDoor,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1863347": [
        {
            "ioc_value": "93.152.223.224:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "js.tsundere",
            "malware_alias": "DinDoor",
            "malware_printable": "Tsundere",
            "first_seen_utc": "2026-07-29 09:46:12",
            "last_seen_utc": "2026-08-31 07:48:04",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DinDoor,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1863344": [
        {
            "ioc_value": "84.201.20.74:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-07-29 09:46:02",
            "last_seen_utc": "2026-08-31 07:47:49",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1863341": [
        {
            "ioc_value": "67.210.97.40:6606",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-07-29 09:45:54",
            "last_seen_utc": "2026-08-31 07:47:39",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1863339": [
        {
            "ioc_value": "23.94.252.80:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "js.tsundere",
            "malware_alias": "DinDoor",
            "malware_printable": "Tsundere",
            "first_seen_utc": "2026-07-29 09:45:17",
            "last_seen_utc": "2026-08-31 07:46:42",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DinDoor,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1863336": [
        {
            "ioc_value": "193.233.198.62:56003",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-07-29 09:44:19",
            "last_seen_utc": "2026-08-29 18:44:40",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1863335": [
        {
            "ioc_value": "178.16.53.65:1907",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.dcrat",
            "malware_alias": "DarkCrystal RAT",
            "malware_printable": "DCRat",
            "first_seen_utc": "2026-07-29 09:44:01",
            "last_seen_utc": "2026-08-31 07:44:34",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DCRat,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1863333": [
        {
            "ioc_value": "168.222.97.120:1447",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-07-29 09:43:54",
            "last_seen_utc": "2026-08-29 18:44:02",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1863334": [
        {
            "ioc_value": "169.58.50.199:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-07-29 09:43:54",
            "last_seen_utc": "2026-08-29 18:44:03",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1863315": [
        {
            "ioc_value": "94.26.3.166:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-07-29 08:59:54",
            "last_seen_utc": "2026-08-31 07:48:10",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1863312": [
        {
            "ioc_value": "91.92.40.56:9267",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-07-29 08:59:50",
            "last_seen_utc": "2026-08-29 18:46:55",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1863311": [
        {
            "ioc_value": "89.213.118.63:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-07-29 08:59:48",
            "last_seen_utc": "2026-08-31 07:47:55",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1863310": [
        {
            "ioc_value": "64.224.17.110:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-07-29 08:59:34",
            "last_seen_utc": "2026-08-31 07:47:34",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1863309": [
        {
            "ioc_value": "51.79.185.253:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-07-29 08:59:29",
            "last_seen_utc": "2026-08-31 07:47:27",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1863308": [
        {
            "ioc_value": "5.253.86.251:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-07-29 08:59:27",
            "last_seen_utc": "2026-08-31 07:47:26",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1863305": [
        {
            "ioc_value": "45.89.48.12:56001",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-07-29 08:59:22",
            "last_seen_utc": "2026-08-31 07:47:19",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1863306": [
        {
            "ioc_value": "45.89.48.12:56002",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-07-29 08:59:22",
            "last_seen_utc": "2026-08-31 07:47:19",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1863307": [
        {
            "ioc_value": "45.89.48.12:56003",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-07-29 08:59:22",
            "last_seen_utc": "2026-08-31 07:47:19",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1863304": [
        {
            "ioc_value": "45.192.211.63:56003",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-07-29 08:59:16",
            "last_seen_utc": "2026-08-31 07:47:12",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1863299": [
        {
            "ioc_value": "27.124.36.151:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-07-29 08:59:00",
            "last_seen_utc": "2026-08-31 07:46:43",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1863298": [
        {
            "ioc_value": "27.124.36.136:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-07-29 08:58:59",
            "last_seen_utc": "2026-08-31 07:46:43",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1863295": [
        {
            "ioc_value": "217.156.122.76:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-07-29 08:58:52",
            "last_seen_utc": "2026-08-31 07:46:32",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1863296": [
        {
            "ioc_value": "217.60.195.153:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-07-29 08:58:52",
            "last_seen_utc": "2026-08-31 07:46:34",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1863297": [
        {
            "ioc_value": "217.60.195.167:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-07-29 08:58:52",
            "last_seen_utc": "2026-08-31 07:46:34",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1863294": [
        {
            "ioc_value": "209.99.190.23:55012",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-07-29 08:58:17",
            "last_seen_utc": "2026-08-31 07:45:48",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1863292": [
        {
            "ioc_value": "194.9.6.82:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-07-29 08:58:05",
            "last_seen_utc": "2026-08-31 07:45:22",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1863255": [
        {
            "ioc_value": "193.164.5.4:9991",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-07-29 08:58:02",
            "last_seen_utc": "2026-08-31 07:45:13",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1863241": [
        {
            "ioc_value": "192.229.115.162:56004",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-07-29 08:58:01",
            "last_seen_utc": "2026-08-31 07:45:08",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1863230": [
        {
            "ioc_value": "192.229.115.154:56004",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-07-29 08:58:00",
            "last_seen_utc": "2026-08-31 07:45:07",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1863234": [
        {
            "ioc_value": "192.229.115.156:56004",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-07-29 08:58:00",
            "last_seen_utc": "2026-08-31 07:45:08",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1863237": [
        {
            "ioc_value": "192.229.115.162:56003",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-07-29 08:58:00",
            "last_seen_utc": "2026-08-31 07:45:08",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1863164": [
        {
            "ioc_value": "185.247.208.91:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-07-29 08:57:56",
            "last_seen_utc": "2026-08-31 07:44:50",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1863169": [
        {
            "ioc_value": "185.254.99.153:56001",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-07-29 08:57:56",
            "last_seen_utc": "2026-08-31 07:44:50",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1863089": [
        {
            "ioc_value": "185.174.101.235:55555",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-07-29 08:57:52",
            "last_seen_utc": "2026-08-31 07:44:42",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1863050": [
        {
            "ioc_value": "178.211.155.64:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-07-29 08:57:46",
            "last_seen_utc": "2026-08-31 07:44:36",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1863049": [
        {
            "ioc_value": "178.16.53.65:2828",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-07-29 08:57:45",
            "last_seen_utc": "2026-08-31 07:44:34",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1863048": [
        {
            "ioc_value": "176.96.136.230:56003",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-07-29 08:57:44",
            "last_seen_utc": "2026-08-31 07:44:31",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1863047": [
        {
            "ioc_value": "176.96.136.230:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-07-29 08:57:43",
            "last_seen_utc": "2026-08-31 07:44:31",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1863045": [
        {
            "ioc_value": "163.5.210.173:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-07-29 08:57:36",
            "last_seen_utc": "2026-08-31 07:44:14",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1863046": [
        {
            "ioc_value": "167.148.41.137:56003",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-07-29 08:57:36",
            "last_seen_utc": "2026-08-29 18:43:59",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1863044": [
        {
            "ioc_value": "160.119.69.21:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-07-29 08:57:33",
            "last_seen_utc": "2026-08-31 07:44:10",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1863043": [
        {
            "ioc_value": "158.94.210.70:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-07-29 08:57:32",
            "last_seen_utc": "2026-08-31 07:44:08",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1863041": [
        {
            "ioc_value": "151.242.63.129:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-07-29 08:57:21",
            "last_seen_utc": "2026-08-31 07:43:54",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1863042": [
        {
            "ioc_value": "151.242.97.15:56831",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-07-29 08:57:21",
            "last_seen_utc": "2026-08-31 07:43:55",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1863040": [
        {
            "ioc_value": "140.228.29.61:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-07-29 08:57:12",
            "last_seen_utc": "2026-08-31 07:43:47",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1862853": [
        {
            "ioc_value": "103.114.218.145:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-07-29 08:56:51",
            "last_seen_utc": "2026-08-31 07:43:06",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1861775": [
        {
            "ioc_value": "176.96.136.230:56001",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-07-29 07:42:09",
            "last_seen_utc": "2026-08-31 07:44:31",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": "",
            "tags": "PureRat",
            "anonymous": 0,
            "reporter": "RacWatchin8872"
        }
    ],
    "1861777": [
        {
            "ioc_value": "45.192.211.7:56002",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-07-29 07:42:09",
            "last_seen_utc": "2026-08-31 07:47:13",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": "",
            "tags": "PureRat",
            "anonymous": 0,
            "reporter": "RacWatchin8872"
        }
    ],
    "1861778": [
        {
            "ioc_value": "103.68.109.13:56002",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-07-29 07:42:08",
            "last_seen_utc": "2026-08-31 07:43:11",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": "",
            "tags": "PureRat",
            "anonymous": 0,
            "reporter": "RacWatchin8872"
        }
    ],
    "1861780": [
        {
            "ioc_value": "176.96.136.230:56002",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-07-29 07:42:08",
            "last_seen_utc": "2026-08-31 07:44:31",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": "",
            "tags": "PureRat",
            "anonymous": 0,
            "reporter": "RacWatchin8872"
        }
    ],
    "1861788": [
        {
            "ioc_value": "157.20.182.21:9992",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-07-29 07:42:04",
            "last_seen_utc": "2026-08-31 07:44:05",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "",
            "tags": "AsynRat,Server",
            "anonymous": 0,
            "reporter": "RacWatchin8872"
        }
    ],
    "1862621": [
        {
            "ioc_value": "154.12.94.16:8443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-07-29 07:32:16",
            "last_seen_utc": "2026-08-31 07:48:35",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-666666666",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1862620": [
        {
            "ioc_value": "117.72.199.102:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-07-29 07:32:11",
            "last_seen_utc": "2026-08-31 07:48:28",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-987654321",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1862523": [
        {
            "ioc_value": "102.204.223.106:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-07-29 05:46:21",
            "last_seen_utc": "2026-08-31 07:48:23",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1861818": [
        {
            "ioc_value": "31.58.179.22:10140",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-07-28 19:45:36",
            "last_seen_utc": "2026-08-30 08:46:12",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1861817": [
        {
            "ioc_value": "31.57.184.154:2504",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-07-28 19:45:34",
            "last_seen_utc": "2026-08-31 07:46:46",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1861816": [
        {
            "ioc_value": "23.94.148.17:7707",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-07-28 19:45:30",
            "last_seen_utc": "2026-08-31 07:46:41",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1861814": [
        {
            "ioc_value": "204.44.69.230:7707",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-07-28 19:44:36",
            "last_seen_utc": "2026-08-31 07:45:43",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1861744": [
        {
            "ioc_value": "45.192.211.7:56001",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-07-28 16:59:29",
            "last_seen_utc": "2026-08-31 07:47:12",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "censys,PureRAT",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1861745": [
        {
            "ioc_value": "45.192.211.7:56003",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-07-28 16:59:29",
            "last_seen_utc": "2026-08-31 07:47:13",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "censys,PureRAT",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1861746": [
        {
            "ioc_value": "80.76.49.3:56003",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-07-28 16:59:29",
            "last_seen_utc": "2026-08-31 07:47:45",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "censys,PureRAT",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1861739": [
        {
            "ioc_value": "45.192.211.19:56001",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-07-28 16:59:28",
            "last_seen_utc": "2026-08-31 07:47:11",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "censys,PureRAT",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1861740": [
        {
            "ioc_value": "45.192.211.19:56002",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-07-28 16:59:28",
            "last_seen_utc": "2026-08-31 07:47:11",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "censys,PureRAT",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1861741": [
        {
            "ioc_value": "45.192.211.19:56003",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-07-28 16:59:28",
            "last_seen_utc": "2026-08-31 07:47:11",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "censys,PureRAT",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1861742": [
        {
            "ioc_value": "45.192.211.63:56002",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-07-28 16:59:28",
            "last_seen_utc": "2026-08-31 07:47:12",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "censys,PureRAT",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1861743": [
        {
            "ioc_value": "45.192.211.77:56002",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-07-28 16:59:28",
            "last_seen_utc": "2026-08-31 07:47:13",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "censys,PureRAT",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1861722": [
        {
            "ioc_value": "193.233.198.62:56002",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-07-28 16:59:27",
            "last_seen_utc": "2026-08-29 18:44:40",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "censys,PureRAT",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1861730": [
        {
            "ioc_value": "45.119.98.111:56001",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-07-28 16:59:27",
            "last_seen_utc": "2026-08-31 07:47:06",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "censys,PureRAT",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1861731": [
        {
            "ioc_value": "45.119.98.111:56002",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-07-28 16:59:27",
            "last_seen_utc": "2026-08-31 07:47:06",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "censys,PureRAT",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1861732": [
        {
            "ioc_value": "45.119.98.111:56003",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-07-28 16:59:27",
            "last_seen_utc": "2026-08-31 07:47:07",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "censys,PureRAT",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1861710": [
        {
            "ioc_value": "108.187.4.116:56003",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-07-28 16:59:26",
            "last_seen_utc": "2026-08-31 07:43:25",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "censys,PureRAT",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1861711": [
        {
            "ioc_value": "108.187.4.145:56001",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-07-28 16:59:26",
            "last_seen_utc": "2026-08-31 07:43:26",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "censys,PureRAT",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1861712": [
        {
            "ioc_value": "108.187.4.145:56002",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-07-28 16:59:26",
            "last_seen_utc": "2026-08-31 07:43:26",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "censys,PureRAT",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1861713": [
        {
            "ioc_value": "108.187.4.145:56003",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-07-28 16:59:26",
            "last_seen_utc": "2026-08-31 07:43:26",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "censys,PureRAT",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1861714": [
        {
            "ioc_value": "112.121.176.2:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-07-28 16:59:26",
            "last_seen_utc": "2026-08-31 07:43:29",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "censys,PureRAT",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1861715": [
        {
            "ioc_value": "112.121.176.3:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-07-28 16:59:26",
            "last_seen_utc": "2026-08-31 07:43:29",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "censys,PureRAT",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1861717": [
        {
            "ioc_value": "112.121.176.5:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-07-28 16:59:26",
            "last_seen_utc": "2026-08-31 07:43:30",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "censys,PureRAT",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1861718": [
        {
            "ioc_value": "112.121.176.6:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-07-28 16:59:26",
            "last_seen_utc": "2026-08-31 07:43:30",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "censys,PureRAT",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1861705": [
        {
            "ioc_value": "103.68.109.13:56001",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-07-28 16:59:25",
            "last_seen_utc": "2026-08-31 07:43:11",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "censys,PureRAT",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1861706": [
        {
            "ioc_value": "103.68.109.13:56003",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-07-28 16:59:25",
            "last_seen_utc": "2026-08-31 07:43:11",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "censys,PureRAT",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1861707": [
        {
            "ioc_value": "104.164.46.39:8080",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-07-28 16:59:25",
            "last_seen_utc": "2026-08-30 18:43:11",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "censys,PureRAT",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1861708": [
        {
            "ioc_value": "108.187.4.116:56001",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-07-28 16:59:25",
            "last_seen_utc": "2026-08-31 07:43:25",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "censys,PureRAT",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1861709": [
        {
            "ioc_value": "108.187.4.116:56002",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-07-28 16:59:25",
            "last_seen_utc": "2026-08-31 07:43:25",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "censys,PureRAT",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1861522": [
        {
            "ioc_value": "96.126.176.92:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-07-28 09:46:46",
            "last_seen_utc": "2026-08-31 07:48:12",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1861521": [
        {
            "ioc_value": "93.152.223.158:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "js.tsundere",
            "malware_alias": "DinDoor",
            "malware_printable": "Tsundere",
            "first_seen_utc": "2026-07-28 09:46:44",
            "last_seen_utc": "2026-08-31 07:48:04",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DinDoor,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1861520": [
        {
            "ioc_value": "49.235.50.231:14486",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.deimos_c2",
            "malware_alias": null,
            "malware_printable": "DeimosC2",
            "first_seen_utc": "2026-07-28 09:46:12",
            "last_seen_utc": "2026-08-31 07:47:25",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "Deimos,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1861519": [
        {
            "ioc_value": "46.246.6.7:2222",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.dcrat",
            "malware_alias": "DarkCrystal RAT",
            "malware_printable": "DCRat",
            "first_seen_utc": "2026-07-28 09:46:11",
            "last_seen_utc": "2026-08-30 18:46:18",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DCRat,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1861518": [
        {
            "ioc_value": "46.151.182.76:6606",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-07-28 09:46:09",
            "last_seen_utc": "2026-08-31 07:47:21",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1861516": [
        {
            "ioc_value": "23.94.252.87:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "js.tsundere",
            "malware_alias": "DinDoor",
            "malware_printable": "Tsundere",
            "first_seen_utc": "2026-07-28 09:45:42",
            "last_seen_utc": "2026-08-31 07:46:42",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DinDoor,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1861517": [
        {
            "ioc_value": "24.244.73.237:40056",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-07-28 09:45:42",
            "last_seen_utc": "2026-08-31 07:46:42",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1861515": [
        {
            "ioc_value": "23.94.252.55:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "js.tsundere",
            "malware_alias": "DinDoor",
            "malware_printable": "Tsundere",
            "first_seen_utc": "2026-07-28 09:45:41",
            "last_seen_utc": "2026-08-31 07:46:41",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DinDoor,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1861513": [
        {
            "ioc_value": "207.246.75.30:8808",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-07-28 09:44:46",
            "last_seen_utc": "2026-08-29 18:45:00",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1861512": [
        {
            "ioc_value": "206.189.167.120:65000",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-07-28 09:44:45",
            "last_seen_utc": "2026-08-31 07:45:43",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1861511": [
        {
            "ioc_value": "2.27.63.244:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-07-28 09:44:40",
            "last_seen_utc": "2026-08-31 07:45:36",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1861509": [
        {
            "ioc_value": "158.94.210.161:2222",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.dcrat",
            "malware_alias": "DarkCrystal RAT",
            "malware_printable": "DCRat",
            "first_seen_utc": "2026-07-28 09:43:56",
            "last_seen_utc": "2026-08-30 18:43:51",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DCRat,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1861508": [
        {
            "ioc_value": "157.245.228.139:65000",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-07-28 09:43:54",
            "last_seen_utc": "2026-08-31 07:44:06",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1861507": [
        {
            "ioc_value": "130.12.182.249:6606",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-07-28 09:43:26",
            "last_seen_utc": "2026-08-31 07:43:40",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1861326": [
        {
            "ioc_value": "189.249.193.61:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-07-27 22:05:05",
            "last_seen_utc": "2026-08-29 08:44:41",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "mythic",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1861181": [
        {
            "ioc_value": "36.139.36.124:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-07-27 21:05:07",
            "last_seen_utc": "2026-08-31 07:46:53",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "adaptix",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1860744": [
        {
            "ioc_value": "46.151.182.76:8808",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-07-27 19:45:24",
            "last_seen_utc": "2026-08-31 07:47:21",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1860743": [
        {
            "ioc_value": "204.44.69.230:8808",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-07-27 19:44:20",
            "last_seen_utc": "2026-08-31 07:45:43",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1860739": [
        {
            "ioc_value": "130.12.182.249:8808",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-07-27 19:43:22",
            "last_seen_utc": "2026-08-31 07:43:40",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1860738": [
        {
            "ioc_value": "130.12.182.249:7707",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-07-27 19:43:21",
            "last_seen_utc": "2026-08-31 07:43:40",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1860247": [
        {
            "ioc_value": "193.233.198.62:56001",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-07-27 13:25:21",
            "last_seen_utc": "2026-08-29 18:44:40",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": null,
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1860089": [
        {
            "ioc_value": "46.151.182.76:7707",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-07-27 09:45:41",
            "last_seen_utc": "2026-08-31 07:47:21",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1860087": [
        {
            "ioc_value": "204.44.69.230:6606",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-07-27 09:44:29",
            "last_seen_utc": "2026-08-31 07:45:42",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1860086": [
        {
            "ioc_value": "2.26.26.153:43216",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-07-27 09:44:23",
            "last_seen_utc": "2026-08-31 07:45:33",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1860085": [
        {
            "ioc_value": "194.233.80.96:4321",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-07-27 09:44:20",
            "last_seen_utc": "2026-08-31 07:45:17",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1859700": [
        {
            "ioc_value": "141.255.162.234:37422",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-07-26 23:45:57",
            "last_seen_utc": "2026-08-31 07:48:34",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1859680": [
        {
            "ioc_value": "47.113.98.42:53",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-07-26 21:46:16",
            "last_seen_utc": "2026-08-31 07:48:51",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1859678": [
        {
            "ioc_value": "dns1.dreamls.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-07-26 21:45:45",
            "last_seen_utc": "2026-08-31 07:48:17",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1859679": [
        {
            "ioc_value": "dns2.dreamls.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-07-26 21:45:45",
            "last_seen_utc": "2026-08-31 07:48:17",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1858980": [
        {
            "ioc_value": "2.27.248.237:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "js.tsundere",
            "malware_alias": "DinDoor",
            "malware_printable": "Tsundere",
            "first_seen_utc": "2026-07-26 19:44:16",
            "last_seen_utc": "2026-08-31 07:45:34",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DinDoor,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1858979": [
        {
            "ioc_value": "192.162.199.143:8848",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.dcrat",
            "malware_alias": "DarkCrystal RAT",
            "malware_printable": "DCRat",
            "first_seen_utc": "2026-07-26 19:44:08",
            "last_seen_utc": "2026-08-31 07:45:05",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DCRat,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1857981": [
        {
            "ioc_value": "198.98.53.100:8080",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.aisuru",
            "malware_alias": null,
            "malware_printable": "Aisuru",
            "first_seen_utc": "2026-07-26 10:55:50",
            "last_seen_utc": "2026-08-30 00:35:12",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "Aisuru,c2",
            "anonymous": 0,
            "reporter": "Bitsight"
        }
    ],
    "1858180": [
        {
            "ioc_value": "199.246.88.101:5432",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-07-26 09:44:26",
            "last_seen_utc": "2026-08-31 07:45:32",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "Covenant,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1858179": [
        {
            "ioc_value": "103.67.163.201:7707",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-07-26 09:43:12",
            "last_seen_utc": "2026-08-31 07:43:11",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1857979": [
        {
            "ioc_value": "54.178.100.27:8021",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-07-25 23:46:33",
            "last_seen_utc": "2026-08-31 07:48:54",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1857725": [
        {
            "ioc_value": "82.158.88.41:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-07-25 19:46:06",
            "last_seen_utc": "2026-08-31 07:47:46",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1857722": [
        {
            "ioc_value": "27.124.20.3:4321",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-07-25 19:45:23",
            "last_seen_utc": "2026-08-31 07:46:43",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1857720": [
        {
            "ioc_value": "2.27.248.209:4321",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-07-25 19:44:25",
            "last_seen_utc": "2026-08-31 07:45:34",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1857719": [
        {
            "ioc_value": "185.147.83.59:48321",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-07-25 19:44:10",
            "last_seen_utc": "2026-08-31 07:44:42",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1857718": [
        {
            "ioc_value": "146.70.87.23:43225",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-07-25 19:43:34",
            "last_seen_utc": "2026-08-29 18:43:40",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1857717": [
        {
            "ioc_value": "144.208.127.87:10443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-07-25 19:43:33",
            "last_seen_utc": "2026-08-30 18:43:38",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1857716": [
        {
            "ioc_value": "141.255.164.33:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "js.tsundere",
            "malware_alias": "DinDoor",
            "malware_printable": "Tsundere",
            "first_seen_utc": "2026-07-25 19:43:29",
            "last_seen_utc": "2026-08-31 07:43:47",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DinDoor,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1857715": [
        {
            "ioc_value": "103.67.163.201:8808",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-07-25 19:43:11",
            "last_seen_utc": "2026-08-31 07:43:11",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1857362": [
        {
            "ioc_value": "117.28.246.18:8067",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-07-25 11:45:55",
            "last_seen_utc": "2026-08-31 07:48:27",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1857317": [
        {
            "ioc_value": "74.249.84.175:4321",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-07-25 09:46:00",
            "last_seen_utc": "2026-08-31 07:47:41",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1857316": [
        {
            "ioc_value": "51.107.74.185:4321",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-07-25 09:45:51",
            "last_seen_utc": "2026-08-31 07:47:26",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1857313": [
        {
            "ioc_value": "31.76.96.194:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "js.tsundere",
            "malware_alias": "DinDoor",
            "malware_printable": "Tsundere",
            "first_seen_utc": "2026-07-25 09:45:30",
            "last_seen_utc": "2026-08-31 07:46:49",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DinDoor,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1857314": [
        {
            "ioc_value": "31.76.96.195:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "js.tsundere",
            "malware_alias": "DinDoor",
            "malware_printable": "Tsundere",
            "first_seen_utc": "2026-07-25 09:45:30",
            "last_seen_utc": "2026-08-31 07:46:49",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DinDoor,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1857311": [
        {
            "ioc_value": "27.124.20.5:4321",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-07-25 09:45:27",
            "last_seen_utc": "2026-08-31 07:46:43",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1857312": [
        {
            "ioc_value": "27.124.20.6:4321",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-07-25 09:45:27",
            "last_seen_utc": "2026-08-31 07:46:43",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1857310": [
        {
            "ioc_value": "207.57.123.129:43211",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-07-25 09:44:42",
            "last_seen_utc": "2026-08-31 07:45:45",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1857308": [
        {
            "ioc_value": "2.27.28.207:42153",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-07-25 09:44:36",
            "last_seen_utc": "2026-08-31 07:45:35",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1857309": [
        {
            "ioc_value": "2.27.29.171:42216",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-07-25 09:44:36",
            "last_seen_utc": "2026-08-31 07:45:35",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1857307": [
        {
            "ioc_value": "196.251.107.131:6606",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-07-25 09:44:33",
            "last_seen_utc": "2026-08-31 07:45:28",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1857304": [
        {
            "ioc_value": "144.172.118.84:4321",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-07-25 09:43:30",
            "last_seen_utc": "2026-08-31 07:43:49",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1857303": [
        {
            "ioc_value": "119.28.212.86:44321",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-07-25 09:43:20",
            "last_seen_utc": "2026-08-31 07:43:34",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1857302": [
        {
            "ioc_value": "103.67.163.201:6606",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-07-25 09:43:10",
            "last_seen_utc": "2026-08-31 07:43:11",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1857015": [
        {
            "ioc_value": "209.200.246.194:34586",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-07-24 23:46:13",
            "last_seen_utc": "2026-08-31 07:48:44",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1856912": [
        {
            "ioc_value": "87.251.64.204:63812",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-07-24 19:45:44",
            "last_seen_utc": "2026-08-31 07:47:52",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1856910": [
        {
            "ioc_value": "45.11.59.152:43200",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-07-24 19:45:13",
            "last_seen_utc": "2026-08-31 07:47:06",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1856908": [
        {
            "ioc_value": "23.94.252.7:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "js.tsundere",
            "malware_alias": "DinDoor",
            "malware_printable": "Tsundere",
            "first_seen_utc": "2026-07-24 19:44:59",
            "last_seen_utc": "2026-08-31 07:46:42",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DinDoor,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1856907": [
        {
            "ioc_value": "2.27.248.80:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "js.tsundere",
            "malware_alias": "DinDoor",
            "malware_printable": "Tsundere",
            "first_seen_utc": "2026-07-24 19:44:16",
            "last_seen_utc": "2026-08-31 07:45:35",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DinDoor,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1856905": [
        {
            "ioc_value": "185.212.129.117:9000",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.evilginx",
            "malware_alias": null,
            "malware_printable": "Evilginx",
            "first_seen_utc": "2026-07-24 19:44:03",
            "last_seen_utc": "2026-08-31 07:44:46",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Evilginx,EvilGoPhish",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1856897": [
        {
            "ioc_value": "156.247.47.108:12159",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.dcrat",
            "malware_alias": "DarkCrystal RAT",
            "malware_printable": "DCRat",
            "first_seen_utc": "2026-07-24 19:43:39",
            "last_seen_utc": "2026-08-31 07:44:04",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DCRat,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1856898": [
        {
            "ioc_value": "156.247.47.108:8848",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.dcrat",
            "malware_alias": "DarkCrystal RAT",
            "malware_printable": "DCRat",
            "first_seen_utc": "2026-07-24 19:43:39",
            "last_seen_utc": "2026-08-31 07:44:04",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DCRat,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1856899": [
        {
            "ioc_value": "156.247.47.109:12159",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.dcrat",
            "malware_alias": "DarkCrystal RAT",
            "malware_printable": "DCRat",
            "first_seen_utc": "2026-07-24 19:43:39",
            "last_seen_utc": "2026-08-31 07:44:04",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DCRat,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1856900": [
        {
            "ioc_value": "156.247.47.109:8848",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.dcrat",
            "malware_alias": "DarkCrystal RAT",
            "malware_printable": "DCRat",
            "first_seen_utc": "2026-07-24 19:43:39",
            "last_seen_utc": "2026-08-31 07:44:04",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DCRat,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1856901": [
        {
            "ioc_value": "156.247.47.110:12159",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.dcrat",
            "malware_alias": "DarkCrystal RAT",
            "malware_printable": "DCRat",
            "first_seen_utc": "2026-07-24 19:43:39",
            "last_seen_utc": "2026-08-31 07:44:04",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DCRat,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1856902": [
        {
            "ioc_value": "156.247.47.110:8848",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.dcrat",
            "malware_alias": "DarkCrystal RAT",
            "malware_printable": "DCRat",
            "first_seen_utc": "2026-07-24 19:43:39",
            "last_seen_utc": "2026-08-31 07:44:04",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DCRat,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1856895": [
        {
            "ioc_value": "156.247.47.106:12159",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.dcrat",
            "malware_alias": "DarkCrystal RAT",
            "malware_printable": "DCRat",
            "first_seen_utc": "2026-07-24 19:43:38",
            "last_seen_utc": "2026-08-31 07:44:03",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DCRat,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1856896": [
        {
            "ioc_value": "156.247.47.106:8848",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.dcrat",
            "malware_alias": "DarkCrystal RAT",
            "malware_printable": "DCRat",
            "first_seen_utc": "2026-07-24 19:43:38",
            "last_seen_utc": "2026-08-31 07:44:04",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DCRat,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1856894": [
        {
            "ioc_value": "151.236.21.109:2096",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.havoc",
            "malware_alias": "Havokiz",
            "malware_printable": "Havoc",
            "first_seen_utc": "2026-07-24 19:43:33",
            "last_seen_utc": "2026-08-31 07:43:54",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Havoc",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1856708": [
        {
            "ioc_value": "23.94.145.121:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "js.tsundere",
            "malware_alias": "DinDoor",
            "malware_printable": "Tsundere",
            "first_seen_utc": "2026-07-24 09:45:54",
            "last_seen_utc": "2026-08-31 07:46:41",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DinDoor,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1856704": [
        {
            "ioc_value": "157.20.182.21:4444",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-07-24 09:43:55",
            "last_seen_utc": "2026-08-31 07:44:05",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1856675": [
        {
            "ioc_value": "42.193.22.177:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-07-24 07:25:20",
            "last_seen_utc": "2026-08-31 07:48:47",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-391144938",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1856638": [
        {
            "ioc_value": "198.98.53.100:8443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.aisuru",
            "malware_alias": null,
            "malware_printable": "Aisuru",
            "first_seen_utc": "2026-07-24 06:20:07",
            "last_seen_utc": "2026-08-31 07:52:48",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "Aisuru,c2",
            "anonymous": 0,
            "reporter": "Bitsight"
        }
    ],
    "1856292": [
        {
            "ioc_value": "93.152.224.94:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "js.tsundere",
            "malware_alias": "DinDoor",
            "malware_printable": "Tsundere",
            "first_seen_utc": "2026-07-23 19:46:19",
            "last_seen_utc": "2026-08-31 07:48:05",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DinDoor,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1856291": [
        {
            "ioc_value": "93.152.223.159:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "js.tsundere",
            "malware_alias": "DinDoor",
            "malware_printable": "Tsundere",
            "first_seen_utc": "2026-07-23 19:46:18",
            "last_seen_utc": "2026-08-31 07:48:04",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DinDoor,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1856288": [
        {
            "ioc_value": "2.27.248.75:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "js.tsundere",
            "malware_alias": "DinDoor",
            "malware_printable": "Tsundere",
            "first_seen_utc": "2026-07-23 19:44:28",
            "last_seen_utc": "2026-08-31 07:45:35",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DinDoor,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1856285": [
        {
            "ioc_value": "2.27.248.232:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "js.tsundere",
            "malware_alias": "DinDoor",
            "malware_printable": "Tsundere",
            "first_seen_utc": "2026-07-23 19:44:27",
            "last_seen_utc": "2026-08-31 07:45:34",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DinDoor,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1856286": [
        {
            "ioc_value": "2.27.248.236:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "js.tsundere",
            "malware_alias": "DinDoor",
            "malware_printable": "Tsundere",
            "first_seen_utc": "2026-07-23 19:44:27",
            "last_seen_utc": "2026-08-31 07:45:34",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DinDoor,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1856287": [
        {
            "ioc_value": "2.27.248.72:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "js.tsundere",
            "malware_alias": "DinDoor",
            "malware_printable": "Tsundere",
            "first_seen_utc": "2026-07-23 19:44:27",
            "last_seen_utc": "2026-08-31 07:45:35",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DinDoor,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1856213": [
        {
            "ioc_value": "www.ai2.qzz.io",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-07-23 15:46:18",
            "last_seen_utc": "2026-08-31 07:48:20",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1855967": [
        {
            "ioc_value": "2.27.160.24:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "js.tsundere",
            "malware_alias": "DinDoor",
            "malware_printable": "Tsundere",
            "first_seen_utc": "2026-07-23 09:44:27",
            "last_seen_utc": "2026-08-31 07:45:33",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DinDoor,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1855968": [
        {
            "ioc_value": "2.27.248.234:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "js.tsundere",
            "malware_alias": "DinDoor",
            "malware_printable": "Tsundere",
            "first_seen_utc": "2026-07-23 09:44:27",
            "last_seen_utc": "2026-08-31 07:45:34",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DinDoor,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1855963": [
        {
            "ioc_value": "157.20.182.22:9992",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-07-23 09:43:48",
            "last_seen_utc": "2026-08-31 07:44:06",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1855962": [
        {
            "ioc_value": "157.20.182.21:1444",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-07-23 09:43:47",
            "last_seen_utc": "2026-08-31 07:44:05",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1855961": [
        {
            "ioc_value": "151.243.145.220:3333",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.evilginx",
            "malware_alias": null,
            "malware_printable": "Evilginx",
            "first_seen_utc": "2026-07-23 09:43:39",
            "last_seen_utc": "2026-08-31 07:43:55",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Evilginx,EvilGoPhish",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1855925": [
        {
            "ioc_value": "64.177.113.11:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-07-23 08:05:07",
            "last_seen_utc": "2026-08-29 18:46:32",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "mythic",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1855923": [
        {
            "ioc_value": "174.138.9.149:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-07-23 08:05:05",
            "last_seen_utc": "2026-08-31 07:44:29",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "mythic",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1855877": [
        {
            "ioc_value": "cdn.pixelcss.org",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-07-23 05:46:03",
            "last_seen_utc": "2026-08-31 07:48:14",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1855460": [
        {
            "ioc_value": "43.228.157.252:6606",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-07-22 19:45:15",
            "last_seen_utc": "2026-08-31 07:47:06",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1855456": [
        {
            "ioc_value": "165.22.129.73:65000",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-07-22 19:43:47",
            "last_seen_utc": "2026-08-31 07:44:15",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1855455": [
        {
            "ioc_value": "157.20.182.22:1444",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-07-22 19:43:42",
            "last_seen_utc": "2026-08-31 07:44:05",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1855453": [
        {
            "ioc_value": "137.184.163.27:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-07-22 19:43:25",
            "last_seen_utc": "2026-08-31 07:43:44",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1855451": [
        {
            "ioc_value": "12.187.175.73:8797",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-07-22 19:43:21",
            "last_seen_utc": "2026-08-31 07:43:34",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1855382": [
        {
            "ioc_value": "43.134.38.218:4543",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-07-22 17:05:52",
            "last_seen_utc": "2026-08-31 07:47:03",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "mythic",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1855287": [
        {
            "ioc_value": "172.111.163.172:65070",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-07-22 12:25:04",
            "last_seen_utc": "2026-08-31 01:48:12",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "RAT,RemcosRAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1855249": [
        {
            "ioc_value": "45.142.141.139:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-07-22 09:45:30",
            "last_seen_utc": "2026-08-30 08:46:28",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1855246": [
        {
            "ioc_value": "20.200.61.22:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-07-22 09:44:24",
            "last_seen_utc": "2026-08-31 07:45:38",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1855243": [
        {
            "ioc_value": "157.20.182.21:1338",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-07-22 09:43:45",
            "last_seen_utc": "2026-08-29 18:43:51",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1855239": [
        {
            "ioc_value": "132.145.210.148:8443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-07-22 09:43:25",
            "last_seen_utc": "2026-08-31 07:43:42",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1855238": [
        {
            "ioc_value": "104.248.69.160:65000",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-07-22 09:43:14",
            "last_seen_utc": "2026-08-31 07:43:17",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1855202": [
        {
            "ioc_value": "http://vriclactrina.cz/index.php",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.smokeloader",
            "malware_alias": "Dofoil,Sharik,Smoke,Smoke Loader",
            "malware_printable": "SmokeLoader",
            "first_seen_utc": "2026-07-22 08:06:59",
            "last_seen_utc": "2026-08-31 07:29:20",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "c2,SmokeLoader",
            "anonymous": 0,
            "reporter": "Bitsight"
        }
    ],
    "1855047": [
        {
            "ioc_value": "86.48.16.94:30100",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-07-21 19:46:20",
            "last_seen_utc": "2026-08-31 07:47:51",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1855046": [
        {
            "ioc_value": "85.208.69.45:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.bianlian",
            "malware_alias": null,
            "malware_printable": "BianLian",
            "first_seen_utc": "2026-07-21 19:46:19",
            "last_seen_utc": "2026-08-31 07:47:50",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "Bianlian,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1855044": [
        {
            "ioc_value": "45.142.141.139:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-07-21 19:45:42",
            "last_seen_utc": "2026-08-29 18:46:12",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1855043": [
        {
            "ioc_value": "43.213.171.100:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-07-21 19:45:41",
            "last_seen_utc": "2026-08-31 07:47:05",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1855041": [
        {
            "ioc_value": "43.213.142.102:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-07-21 19:45:40",
            "last_seen_utc": "2026-08-31 07:47:05",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1855039": [
        {
            "ioc_value": "34.106.101.107:6932",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-07-21 19:45:33",
            "last_seen_utc": "2026-08-31 07:46:51",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1855040": [
        {
            "ioc_value": "34.28.220.109:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-07-21 19:45:33",
            "last_seen_utc": "2026-08-31 07:46:52",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1855038": [
        {
            "ioc_value": "2.27.122.16:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "js.tsundere",
            "malware_alias": "DinDoor",
            "malware_printable": "Tsundere",
            "first_seen_utc": "2026-07-21 19:44:32",
            "last_seen_utc": "2026-08-31 07:45:33",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DinDoor,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1855035": [
        {
            "ioc_value": "141.253.195.133:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-07-21 19:43:32",
            "last_seen_utc": "2026-08-31 07:43:47",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1855034": [
        {
            "ioc_value": "132.145.210.148:11235",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-07-21 19:43:28",
            "last_seen_utc": "2026-08-31 07:43:42",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1854871": [
        {
            "ioc_value": "185.33.86.141:29292",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-07-21 09:44:16",
            "last_seen_utc": "2026-08-31 07:44:51",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1854508": [
        {
            "ioc_value": "94.154.43.77:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.mirai",
            "malware_alias": "Katana",
            "malware_printable": "Mirai",
            "first_seen_utc": "2026-07-20 19:45:56",
            "last_seen_utc": "2026-08-31 07:48:07",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mirai",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1854504": [
        {
            "ioc_value": "220.154.3.197:9443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-07-20 19:45:02",
            "last_seen_utc": "2026-08-31 07:46:38",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1854503": [
        {
            "ioc_value": "203.83.238.164:9003",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-07-20 19:44:22",
            "last_seen_utc": "2026-08-31 07:45:41",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1854502": [
        {
            "ioc_value": "2.27.248.61:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "js.tsundere",
            "malware_alias": "DinDoor",
            "malware_printable": "Tsundere",
            "first_seen_utc": "2026-07-20 19:44:19",
            "last_seen_utc": "2026-08-31 07:45:34",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DinDoor,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1854498": [
        {
            "ioc_value": "151.243.101.44:21343",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-07-20 19:43:37",
            "last_seen_utc": "2026-08-31 07:43:55",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1854496": [
        {
            "ioc_value": "14.22.75.6:9003",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-07-20 19:43:29",
            "last_seen_utc": "2026-08-31 07:43:46",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1854497": [
        {
            "ioc_value": "14.22.75.6:9443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-07-20 19:43:29",
            "last_seen_utc": "2026-08-31 07:43:46",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1854495": [
        {
            "ioc_value": "12.202.180.13:6745",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-07-20 19:43:22",
            "last_seen_utc": "2026-08-31 07:43:34",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1854201": [
        {
            "ioc_value": "89.124.104.192:49999",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-07-20 09:45:58",
            "last_seen_utc": "2026-08-31 07:47:54",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1854200": [
        {
            "ioc_value": "220.154.3.197:8766",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-07-20 09:45:09",
            "last_seen_utc": "2026-08-31 07:46:38",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1854198": [
        {
            "ioc_value": "203.83.238.164:8766",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-07-20 09:44:25",
            "last_seen_utc": "2026-08-31 07:45:41",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1854199": [
        {
            "ioc_value": "203.83.238.164:9443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-07-20 09:44:25",
            "last_seen_utc": "2026-08-31 07:45:41",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1854196": [
        {
            "ioc_value": "185.212.131.28:9000",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.evilginx",
            "malware_alias": null,
            "malware_printable": "Evilginx",
            "first_seen_utc": "2026-07-20 09:44:09",
            "last_seen_utc": "2026-08-31 07:44:48",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Evilginx,EvilGoPhish",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1854195": [
        {
            "ioc_value": "185.212.128.155:9000",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.evilginx",
            "malware_alias": null,
            "malware_printable": "Evilginx",
            "first_seen_utc": "2026-07-20 09:44:07",
            "last_seen_utc": "2026-08-31 07:44:45",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Evilginx,EvilGoPhish",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1854193": [
        {
            "ioc_value": "169.58.12.228:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.evilginx",
            "malware_alias": null,
            "malware_printable": "Evilginx",
            "first_seen_utc": "2026-07-20 09:43:51",
            "last_seen_utc": "2026-08-31 07:44:18",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Evilginx,EvilGoPhish",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1854188": [
        {
            "ioc_value": "103.185.249.13:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-07-20 09:43:11",
            "last_seen_utc": "2026-08-31 07:43:09",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1853903": [
        {
            "ioc_value": "213.160.77.221:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.evilginx",
            "malware_alias": null,
            "malware_printable": "Evilginx",
            "first_seen_utc": "2026-07-19 19:44:23",
            "last_seen_utc": "2026-08-31 07:45:51",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Evilginx,EvilGoPhish",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1853898": [
        {
            "ioc_value": "14.22.75.6:8766",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-07-19 19:43:26",
            "last_seen_utc": "2026-08-31 07:43:46",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1853729": [
        {
            "ioc_value": "154.12.85.75:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-07-19 10:16:42",
            "last_seen_utc": "2026-08-31 07:48:35",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-987654321",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1853717": [
        {
            "ioc_value": "185.147.83.58:64213",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-07-19 09:44:11",
            "last_seen_utc": "2026-08-31 07:44:42",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1853568": [
        {
            "ioc_value": "38.76.169.75:870",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-07-18 23:46:07",
            "last_seen_utc": "2026-08-31 07:48:46",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1853534": [
        {
            "ioc_value": "64.89.161.190:7707",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-07-18 19:45:54",
            "last_seen_utc": "2026-08-31 07:47:36",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1853334": [
        {
            "ioc_value": "45.55.98.175:60560",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.brute_ratel_c4",
            "malware_alias": "BOLDBADGER,BruteRatel",
            "malware_printable": "Brute Ratel C4",
            "first_seen_utc": "2026-07-18 09:46:14",
            "last_seen_utc": "2026-08-31 07:47:14",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "BruteRatel,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1853333": [
        {
            "ioc_value": "31.57.93.182:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-07-18 09:45:59",
            "last_seen_utc": "2026-08-31 07:46:48",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1853331": [
        {
            "ioc_value": "217.217.97.111:4321",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-07-18 09:45:49",
            "last_seen_utc": "2026-08-31 07:46:32",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1852991": [
        {
            "ioc_value": "45.194.17.39:18443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-07-17 21:46:50",
            "last_seen_utc": "2026-08-30 08:47:51",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1852912": [
        {
            "ioc_value": "20.2.87.168:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-07-17 21:05:07",
            "last_seen_utc": "2026-08-31 07:45:38",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "mythic",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1852888": [
        {
            "ioc_value": "207.180.29.217:6606",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-07-17 19:44:34",
            "last_seen_utc": "2026-08-29 08:45:13",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1852883": [
        {
            "ioc_value": "15.235.149.212:9443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.evilginx",
            "malware_alias": null,
            "malware_printable": "Evilginx",
            "first_seen_utc": "2026-07-17 19:43:41",
            "last_seen_utc": "2026-08-31 07:43:53",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Evilginx,EvilGoPhish",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1852645": [
        {
            "ioc_value": "43.225.157.146:7707",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-07-16 19:46:09",
            "last_seen_utc": "2026-08-31 07:47:05",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1852641": [
        {
            "ioc_value": "188.166.40.236:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-07-16 19:44:30",
            "last_seen_utc": "2026-08-31 07:44:59",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1852491": [
        {
            "ioc_value": "203.91.75.89:5005",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-07-16 09:47:53",
            "last_seen_utc": "2026-08-31 07:48:43",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1852489": [
        {
            "ioc_value": "64.89.161.190:6606",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-07-16 09:46:46",
            "last_seen_utc": "2026-08-31 07:47:36",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1852483": [
        {
            "ioc_value": "209.99.189.225:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-07-16 09:45:04",
            "last_seen_utc": "2026-08-31 07:45:48",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1851436": [
        {
            "ioc_value": "64.89.161.94:2404",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-07-16 07:11:05",
            "last_seen_utc": "2026-08-31 03:56:14",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://bazaar.abuse.ch/sample/b19a5e35b834b52e290d4287956eaaf93e5d19a92ced03638fd7f0305c23b896/",
            "tags": "remcos",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1851397": [
        {
            "ioc_value": "14.29.160.181:8888",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-07-16 04:05:05",
            "last_seen_utc": "2026-08-31 07:48:34",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "cobaltstrike",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1851283": [
        {
            "ioc_value": "185.212.131.22:9000",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.evilginx",
            "malware_alias": null,
            "malware_printable": "Evilginx",
            "first_seen_utc": "2026-07-15 19:44:19",
            "last_seen_utc": "2026-08-31 07:44:48",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Evilginx,EvilGoPhish",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1850971": [
        {
            "ioc_value": "74.0.32.137:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.evilginx",
            "malware_alias": null,
            "malware_printable": "Evilginx",
            "first_seen_utc": "2026-07-15 09:46:18",
            "last_seen_utc": "2026-08-31 07:47:41",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Evilginx,EvilGoPhish",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1850710": [
        {
            "ioc_value": "64.89.161.190:8808",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-07-14 19:45:50",
            "last_seen_utc": "2026-08-31 07:47:37",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1850708": [
        {
            "ioc_value": "45.155.69.254:1488",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-07-14 19:45:31",
            "last_seen_utc": "2026-08-31 07:47:10",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1850700": [
        {
            "ioc_value": "158.94.211.63:32333",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-07-14 19:43:47",
            "last_seen_utc": "2026-08-31 07:44:08",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1850698": [
        {
            "ioc_value": "151.145.34.33:8080",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.chaos",
            "malware_alias": "FakeRyuk,RyukJoke,Yashma",
            "malware_printable": "Chaos",
            "first_seen_utc": "2026-07-14 19:43:39",
            "last_seen_utc": "2026-08-31 07:43:54",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CHAOS,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1850666": [
        {
            "ioc_value": "45.55.232.28:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-07-14 18:05:08",
            "last_seen_utc": "2026-08-31 07:47:14",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "asyncrat",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1850215": [
        {
            "ioc_value": "35.78.107.61:4321",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-07-14 09:46:14",
            "last_seen_utc": "2026-08-29 08:46:14",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1849979": [
        {
            "ioc_value": "85.8.149.156:444",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-07-13 19:45:28",
            "last_seen_utc": "2026-08-31 07:47:51",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1849976": [
        {
            "ioc_value": "37.235.54.142:53236",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.havoc",
            "malware_alias": "Havokiz",
            "malware_printable": "Havoc",
            "first_seen_utc": "2026-07-13 19:44:54",
            "last_seen_utc": "2026-08-31 07:46:53",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Havoc",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1849974": [
        {
            "ioc_value": "23.27.52.106:28736",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-07-13 19:44:48",
            "last_seen_utc": "2026-08-31 07:46:41",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1849967": [
        {
            "ioc_value": "185.212.131.27:9000",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.evilginx",
            "malware_alias": null,
            "malware_printable": "Evilginx",
            "first_seen_utc": "2026-07-13 19:43:57",
            "last_seen_utc": "2026-08-31 07:44:48",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Evilginx,EvilGoPhish",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1849957": [
        {
            "ioc_value": "36.140.162.173:7777",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-07-13 19:05:07",
            "last_seen_utc": "2026-08-31 07:48:46",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "cobaltstrike",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1849604": [
        {
            "ioc_value": "103.214.146.46:8001",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.aisuru",
            "malware_alias": null,
            "malware_printable": "Aisuru",
            "first_seen_utc": "2026-07-13 07:03:02",
            "last_seen_utc": "2026-08-31 07:54:56",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://github.com/deepfield/public-research/blob/main/aisuru/README.md",
            "tags": "airashi,aisuru,botnet,c2,ddos,mirai",
            "anonymous": 0,
            "reporter": "deepfield"
        }
    ],
    "1849605": [
        {
            "ioc_value": "103.214.146.46:8080",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.aisuru",
            "malware_alias": null,
            "malware_printable": "Aisuru",
            "first_seen_utc": "2026-07-13 07:03:01",
            "last_seen_utc": "2026-08-30 02:46:33",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://github.com/deepfield/public-research/blob/main/aisuru/README.md",
            "tags": "airashi,aisuru,botnet,c2,ddos,mirai",
            "anonymous": 0,
            "reporter": "deepfield"
        }
    ],
    "1849094": [
        {
            "ioc_value": "45.198.224.93:4321",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-07-12 19:45:37",
            "last_seen_utc": "2026-08-29 08:46:30",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1849088": [
        {
            "ioc_value": "137.220.152.132:8848",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.dcrat",
            "malware_alias": "DarkCrystal RAT",
            "malware_printable": "DCRat",
            "first_seen_utc": "2026-07-12 19:43:29",
            "last_seen_utc": "2026-08-30 08:43:38",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DCRat,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1848961": [
        {
            "ioc_value": "196.251.121.120:35630",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.dcrat",
            "malware_alias": "DarkCrystal RAT",
            "malware_printable": "DCRat",
            "first_seen_utc": "2026-07-12 11:05:05",
            "last_seen_utc": "2026-08-31 07:45:28",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "dcrat",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1848945": [
        {
            "ioc_value": "45.198.224.94:4321",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-07-12 09:45:30",
            "last_seen_utc": "2026-08-29 18:46:16",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1848944": [
        {
            "ioc_value": "38.54.8.74:4321",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-07-12 09:45:25",
            "last_seen_utc": "2026-08-31 07:46:59",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1848937": [
        {
            "ioc_value": "118.107.45.29:50555",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "apk.hook",
            "malware_alias": null,
            "malware_printable": "Hook",
            "first_seen_utc": "2026-07-12 09:43:23",
            "last_seen_utc": "2026-08-31 07:43:32",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Hook",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1848938": [
        {
            "ioc_value": "118.107.45.70:50555",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "apk.hook",
            "malware_alias": null,
            "malware_printable": "Hook",
            "first_seen_utc": "2026-07-12 09:43:23",
            "last_seen_utc": "2026-08-31 07:43:32",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Hook",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1848939": [
        {
            "ioc_value": "118.107.45.73:50555",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "apk.hook",
            "malware_alias": null,
            "malware_printable": "Hook",
            "first_seen_utc": "2026-07-12 09:43:23",
            "last_seen_utc": "2026-08-31 07:43:33",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Hook",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1848936": [
        {
            "ioc_value": "107.172.90.117:4322",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-07-12 09:43:18",
            "last_seen_utc": "2026-08-31 07:43:22",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1848772": [
        {
            "ioc_value": "82.158.229.189:18443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-07-11 19:46:05",
            "last_seen_utc": "2026-08-31 07:47:46",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1848773": [
        {
            "ioc_value": "82.158.229.30:18443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-07-11 19:46:05",
            "last_seen_utc": "2026-08-31 07:47:46",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1848771": [
        {
            "ioc_value": "82.158.229.143:18443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-07-11 19:46:04",
            "last_seen_utc": "2026-08-31 07:47:46",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1848768": [
        {
            "ioc_value": "31.207.4.197:9872",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-07-11 19:45:23",
            "last_seen_utc": "2026-08-31 07:46:45",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1848765": [
        {
            "ioc_value": "185.244.149.240:61443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.bianlian",
            "malware_alias": null,
            "malware_printable": "BianLian",
            "first_seen_utc": "2026-07-11 19:44:14",
            "last_seen_utc": "2026-08-31 07:44:49",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "Bianlian,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1848764": [
        {
            "ioc_value": "178.104.249.136:4321",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-07-11 19:43:59",
            "last_seen_utc": "2026-08-31 07:44:33",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1848759": [
        {
            "ioc_value": "156.234.43.100:8848",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.dcrat",
            "malware_alias": "DarkCrystal RAT",
            "malware_printable": "DCRat",
            "first_seen_utc": "2026-07-11 19:43:43",
            "last_seen_utc": "2026-08-31 07:44:03",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DCRat,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1848760": [
        {
            "ioc_value": "156.234.43.101:8848",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.dcrat",
            "malware_alias": "DarkCrystal RAT",
            "malware_printable": "DCRat",
            "first_seen_utc": "2026-07-11 19:43:43",
            "last_seen_utc": "2026-08-31 07:44:03",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DCRat,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1848761": [
        {
            "ioc_value": "156.234.43.102:8848",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.dcrat",
            "malware_alias": "DarkCrystal RAT",
            "malware_printable": "DCRat",
            "first_seen_utc": "2026-07-11 19:43:43",
            "last_seen_utc": "2026-08-31 07:44:03",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DCRat,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1848762": [
        {
            "ioc_value": "156.234.43.98:8848",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.dcrat",
            "malware_alias": "DarkCrystal RAT",
            "malware_printable": "DCRat",
            "first_seen_utc": "2026-07-11 19:43:43",
            "last_seen_utc": "2026-08-31 07:44:03",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DCRat,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1848763": [
        {
            "ioc_value": "156.234.43.99:8848",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.dcrat",
            "malware_alias": "DarkCrystal RAT",
            "malware_printable": "DCRat",
            "first_seen_utc": "2026-07-11 19:43:43",
            "last_seen_utc": "2026-08-31 07:44:03",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DCRat,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1848757": [
        {
            "ioc_value": "137.220.152.132:12159",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.dcrat",
            "malware_alias": "DarkCrystal RAT",
            "malware_printable": "DCRat",
            "first_seen_utc": "2026-07-11 19:43:27",
            "last_seen_utc": "2026-08-29 08:43:36",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DCRat,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1848755": [
        {
            "ioc_value": "1.14.234.68:4321",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-07-11 19:43:03",
            "last_seen_utc": "2026-08-31 07:43:02",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1848616": [
        {
            "ioc_value": "123.58.64.57:50040",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-07-11 11:46:37",
            "last_seen_utc": "2026-08-31 07:48:32",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1848599": [
        {
            "ioc_value": "172.174.154.130:1024",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.dcrat",
            "malware_alias": "DarkCrystal RAT",
            "malware_printable": "DCRat",
            "first_seen_utc": "2026-07-11 11:05:05",
            "last_seen_utc": "2026-08-31 07:44:21",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "dcrat",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1848583": [
        {
            "ioc_value": "137.220.194.15:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-07-11 09:46:53",
            "last_seen_utc": "2026-08-31 07:48:33",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1848544": [
        {
            "ioc_value": "81.70.21.248:8088",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-07-11 08:52:51",
            "last_seen_utc": "2026-08-31 07:48:58",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-666666666",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1848358": [
        {
            "ioc_value": "8.134.70.73:6111",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-07-10 23:46:33",
            "last_seen_utc": "2026-08-31 07:48:55",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1847999": [
        {
            "ioc_value": "101.42.255.92:2234",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-07-10 11:46:34",
            "last_seen_utc": "2026-08-31 07:48:22",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1847977": [
        {
            "ioc_value": "101.42.255.92:8081",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-07-10 10:05:08",
            "last_seen_utc": "2026-08-31 07:48:22",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "cobaltstrike",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1847970": [
        {
            "ioc_value": "74.0.32.137:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.evilginx",
            "malware_alias": null,
            "malware_printable": "Evilginx",
            "first_seen_utc": "2026-07-10 09:46:14",
            "last_seen_utc": "2026-08-31 07:47:40",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Evilginx,EvilGoPhish",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1847966": [
        {
            "ioc_value": "38.207.176.218:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-07-10 09:45:41",
            "last_seen_utc": "2026-08-31 07:46:57",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1847963": [
        {
            "ioc_value": "179.43.149.253:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-07-10 09:44:08",
            "last_seen_utc": "2026-08-31 07:44:37",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1847959": [
        {
            "ioc_value": "104.250.161.126:2061",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-07-10 09:43:16",
            "last_seen_utc": "2026-08-31 07:43:18",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1847955": [
        {
            "ioc_value": "100.31.133.28:3333",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.evilginx",
            "malware_alias": null,
            "malware_printable": "Evilginx",
            "first_seen_utc": "2026-07-10 09:43:03",
            "last_seen_utc": "2026-08-31 07:43:03",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Evilginx,EvilGoPhish",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1847905": [
        {
            "ioc_value": "119.45.160.160:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-07-10 06:05:05",
            "last_seen_utc": "2026-08-31 07:48:30",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "cobaltstrike",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1847753": [
        {
            "ioc_value": "37.72.172.58:4212",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-07-09 19:45:23",
            "last_seen_utc": "2026-08-31 07:46:54",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1847751": [
        {
            "ioc_value": "213.209.159.91:22",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-07-09 19:44:37",
            "last_seen_utc": "2026-08-31 07:45:51",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1847750": [
        {
            "ioc_value": "212.46.38.117:4445",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.havoc",
            "malware_alias": "Havokiz",
            "malware_printable": "Havoc",
            "first_seen_utc": "2026-07-09 19:44:36",
            "last_seen_utc": "2026-08-31 07:45:50",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Havoc",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1847748": [
        {
            "ioc_value": "179.43.149.251:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-07-09 19:43:58",
            "last_seen_utc": "2026-08-31 07:44:36",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1847744": [
        {
            "ioc_value": "122.114.12.155:17891",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-07-09 19:43:22",
            "last_seen_utc": "2026-08-30 08:43:29",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1847743": [
        {
            "ioc_value": "115.42.60.122:7912",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.dcrat",
            "malware_alias": "DarkCrystal RAT",
            "malware_printable": "DCRat",
            "first_seen_utc": "2026-07-09 19:43:21",
            "last_seen_utc": "2026-08-31 07:43:32",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DCRat,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1847068": [
        {
            "ioc_value": "203.91.75.89:5006",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-07-09 11:47:21",
            "last_seen_utc": "2026-08-31 07:48:43",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1847000": [
        {
            "ioc_value": "5.230.201.242:1995",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.dcrat",
            "malware_alias": "DarkCrystal RAT",
            "malware_printable": "DCRat",
            "first_seen_utc": "2026-07-09 09:46:09",
            "last_seen_utc": "2026-08-31 07:47:25",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DCRat,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1846995": [
        {
            "ioc_value": "37.72.172.58:6606",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-07-09 09:45:45",
            "last_seen_utc": "2026-08-31 07:46:55",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1846988": [
        {
            "ioc_value": "179.43.149.252:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-07-09 09:44:06",
            "last_seen_utc": "2026-08-31 07:44:36",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1846987": [
        {
            "ioc_value": "179.43.149.251:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-07-09 09:44:05",
            "last_seen_utc": "2026-08-31 07:44:36",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1846984": [
        {
            "ioc_value": "176.120.22.129:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.poshc2",
            "malware_alias": null,
            "malware_printable": "PoshC2",
            "first_seen_utc": "2026-07-09 09:44:00",
            "last_seen_utc": "2026-08-31 07:44:30",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PoshC2",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1846983": [
        {
            "ioc_value": "173.249.22.152:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.evilginx",
            "malware_alias": null,
            "malware_printable": "Evilginx",
            "first_seen_utc": "2026-07-09 09:43:59",
            "last_seen_utc": "2026-08-31 07:44:29",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Evilginx,EvilGoPhish",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1846977": [
        {
            "ioc_value": "157.173.195.214:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.evilginx",
            "malware_alias": null,
            "malware_printable": "Evilginx",
            "first_seen_utc": "2026-07-09 09:43:45",
            "last_seen_utc": "2026-08-31 07:44:05",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Evilginx,EvilGoPhish",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1846849": [
        {
            "ioc_value": "193.29.13.44:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-07-09 02:05:05",
            "last_seen_utc": "2026-08-31 07:45:15",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "mythic",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1846736": [
        {
            "ioc_value": "213.209.159.91:4556",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-07-08 19:44:32",
            "last_seen_utc": "2026-08-31 07:45:51",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1846734": [
        {
            "ioc_value": "179.43.149.252:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-07-08 19:43:55",
            "last_seen_utc": "2026-08-31 07:44:37",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1846733": [
        {
            "ioc_value": "164.68.123.50:4321",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-07-08 19:43:45",
            "last_seen_utc": "2026-08-31 07:44:14",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1846504": [
        {
            "ioc_value": "185.92.190.185:8898",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-07-08 11:46:49",
            "last_seen_utc": "2026-08-31 07:48:42",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1846505": [
        {
            "ioc_value": "185.92.190.187:8898",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-07-08 11:46:49",
            "last_seen_utc": "2026-08-31 07:48:42",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1846419": [
        {
            "ioc_value": "139.226.191.149:2082",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-07-08 07:40:42",
            "last_seen_utc": "2026-08-31 07:48:33",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-987654321",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1846237": [
        {
            "ioc_value": "185.92.190.183:8898",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-07-07 23:46:32",
            "last_seen_utc": "2026-08-31 07:48:41",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1846238": [
        {
            "ioc_value": "185.92.190.184:8898",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-07-07 23:46:32",
            "last_seen_utc": "2026-08-31 07:48:42",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1846239": [
        {
            "ioc_value": "185.92.190.186:8898",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-07-07 23:46:32",
            "last_seen_utc": "2026-08-31 07:48:42",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1846003": [
        {
            "ioc_value": "93.152.224.44:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "js.tsundere",
            "malware_alias": "DinDoor",
            "malware_printable": "Tsundere",
            "first_seen_utc": "2026-07-07 09:46:09",
            "last_seen_utc": "2026-08-31 07:48:05",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DinDoor,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1846002": [
        {
            "ioc_value": "91.92.33.250:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "js.tsundere",
            "malware_alias": "DinDoor",
            "malware_printable": "Tsundere",
            "first_seen_utc": "2026-07-07 09:46:08",
            "last_seen_utc": "2026-08-31 07:47:59",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DinDoor,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1845803": [
        {
            "ioc_value": "217.60.97.2:3000",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.evilginx",
            "malware_alias": null,
            "malware_printable": "Evilginx",
            "first_seen_utc": "2026-07-06 19:45:03",
            "last_seen_utc": "2026-08-31 07:46:37",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Evilginx,EvilGoPhish",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1845588": [
        {
            "ioc_value": "38.46.218.34:9999",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "apk.vo1d",
            "malware_alias": null,
            "malware_printable": "vo1d",
            "first_seen_utc": "2026-07-06 10:58:18",
            "last_seen_utc": "2026-08-31 05:49:52",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "loader,Vo1d",
            "anonymous": 0,
            "reporter": "Bitsight"
        }
    ],
    "1845505": [
        {
            "ioc_value": "23.95.217.96:6745",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-07-06 09:45:31",
            "last_seen_utc": "2026-08-31 07:46:42",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1845504": [
        {
            "ioc_value": "222.167.211.55:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "js.tsundere",
            "malware_alias": "DinDoor",
            "malware_printable": "Tsundere",
            "first_seen_utc": "2026-07-06 09:45:29",
            "last_seen_utc": "2026-08-31 07:46:39",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DinDoor,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1845502": [
        {
            "ioc_value": "203.161.57.75:8234",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-07-06 09:44:36",
            "last_seen_utc": "2026-08-31 07:45:41",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1845499": [
        {
            "ioc_value": "2.27.122.16:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "js.tsundere",
            "malware_alias": "DinDoor",
            "malware_printable": "Tsundere",
            "first_seen_utc": "2026-07-06 09:44:33",
            "last_seen_utc": "2026-08-31 07:45:33",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DinDoor,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1845497": [
        {
            "ioc_value": "173.249.41.141:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.havoc",
            "malware_alias": "Havokiz",
            "malware_printable": "Havoc",
            "first_seen_utc": "2026-07-06 09:43:59",
            "last_seen_utc": "2026-08-31 07:44:29",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Havoc",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1845496": [
        {
            "ioc_value": "157.245.54.75:9000",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pupy",
            "malware_alias": "Patpoopy",
            "malware_printable": "pupy",
            "first_seen_utc": "2026-07-06 09:43:45",
            "last_seen_utc": "2026-08-30 08:43:55",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PupyRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1845493": [
        {
            "ioc_value": "143.198.120.167:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.havoc",
            "malware_alias": "Havokiz",
            "malware_printable": "Havoc",
            "first_seen_utc": "2026-07-06 09:43:32",
            "last_seen_utc": "2026-08-31 07:43:48",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Havoc",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1845343": [
        {
            "ioc_value": "134.209.41.160:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-07-06 04:05:04",
            "last_seen_utc": "2026-08-31 07:43:43",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "mythic",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1845294": [
        {
            "ioc_value": "31.220.93.222:4321",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-07-05 19:45:18",
            "last_seen_utc": "2026-08-31 07:46:46",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1845293": [
        {
            "ioc_value": "194.26.192.117:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-07-05 19:44:18",
            "last_seen_utc": "2026-08-31 07:45:17",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1845266": [
        {
            "ioc_value": "141.94.121.162:8888",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.dcrat",
            "malware_alias": "DarkCrystal RAT",
            "malware_printable": "DCRat",
            "first_seen_utc": "2026-07-05 18:05:04",
            "last_seen_utc": "2026-08-31 07:43:47",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "dcrat",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1845011": [
        {
            "ioc_value": "111.229.248.198:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-07-05 13:33:27",
            "last_seen_utc": "2026-08-31 07:48:25",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-1234567890",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1844960": [
        {
            "ioc_value": "http://91.202.233.134/4d95d68e3fc64f3bbbf5.php",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.stealc",
            "malware_alias": null,
            "malware_printable": "Stealc",
            "first_seen_utc": "2026-07-05 09:50:45",
            "last_seen_utc": "2026-08-31 07:40:51",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://bazaar.abuse.ch/sample/1095cf2951bbc8b1ecd33798afad192449a102aa1b976fb60bf566a08d693587/",
            "tags": "stealc",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1844953": [
        {
            "ioc_value": "170.168.15.43:4322",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-07-05 09:43:57",
            "last_seen_utc": "2026-08-31 07:44:19",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1844951": [
        {
            "ioc_value": "144.31.62.81:56123",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-07-05 09:43:36",
            "last_seen_utc": "2026-08-31 07:43:50",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1844949": [
        {
            "ioc_value": "143.92.43.241:12159",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.dcrat",
            "malware_alias": "DarkCrystal RAT",
            "malware_printable": "DCRat",
            "first_seen_utc": "2026-07-05 09:43:35",
            "last_seen_utc": "2026-08-31 07:43:48",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DCRat,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1844950": [
        {
            "ioc_value": "143.92.43.246:12159",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.dcrat",
            "malware_alias": "DarkCrystal RAT",
            "malware_printable": "DCRat",
            "first_seen_utc": "2026-07-05 09:43:35",
            "last_seen_utc": "2026-08-31 07:43:49",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DCRat,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1844948": [
        {
            "ioc_value": "143.92.43.160:12159",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.dcrat",
            "malware_alias": "DarkCrystal RAT",
            "malware_printable": "DCRat",
            "first_seen_utc": "2026-07-05 09:43:34",
            "last_seen_utc": "2026-08-31 07:43:48",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DCRat,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1844861": [
        {
            "ioc_value": "110.40.147.249:60010",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-07-04 23:45:52",
            "last_seen_utc": "2026-08-31 07:48:24",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1844840": [
        {
            "ioc_value": "92.4.65.88:3333",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.evilginx",
            "malware_alias": null,
            "malware_printable": "Evilginx",
            "first_seen_utc": "2026-07-04 19:45:47",
            "last_seen_utc": "2026-08-31 07:48:03",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Evilginx,EvilGoPhish",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1844835": [
        {
            "ioc_value": "179.43.149.250:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-07-04 19:43:50",
            "last_seen_utc": "2026-08-31 07:44:36",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1844471": [
        {
            "ioc_value": "130.12.182.95:7707",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-07-04 09:43:25",
            "last_seen_utc": "2026-08-31 07:43:41",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1844166": [
        {
            "ioc_value": "86.109.75.177:17635",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-07-03 19:46:03",
            "last_seen_utc": "2026-08-29 08:47:06",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1843816": [
        {
            "ioc_value": "106.13.78.105:18443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-07-02 23:45:57",
            "last_seen_utc": "2026-08-31 07:48:23",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1843760": [
        {
            "ioc_value": "172.94.18.103:70",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-07-02 19:43:55",
            "last_seen_utc": "2026-08-31 07:44:28",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1843754": [
        {
            "ioc_value": "143.92.43.160:8848",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.dcrat",
            "malware_alias": "DarkCrystal RAT",
            "malware_printable": "DCRat",
            "first_seen_utc": "2026-07-02 19:43:31",
            "last_seen_utc": "2026-08-31 07:43:48",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DCRat,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1843755": [
        {
            "ioc_value": "143.92.43.241:8848",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.dcrat",
            "malware_alias": "DarkCrystal RAT",
            "malware_printable": "DCRat",
            "first_seen_utc": "2026-07-02 19:43:31",
            "last_seen_utc": "2026-08-31 07:43:48",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DCRat,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1843756": [
        {
            "ioc_value": "143.92.43.246:8848",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.dcrat",
            "malware_alias": "DarkCrystal RAT",
            "malware_printable": "DCRat",
            "first_seen_utc": "2026-07-02 19:43:31",
            "last_seen_utc": "2026-08-31 07:43:49",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DCRat,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1843500": [
        {
            "ioc_value": "82.157.78.201:8080",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-07-02 12:05:06",
            "last_seen_utc": "2026-08-31 07:48:58",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "cobaltstrike",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1843418": [
        {
            "ioc_value": "220.154.3.197:9003",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-07-02 11:44:21",
            "last_seen_utc": "2026-08-31 07:46:38",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "",
            "tags": "Mythic,MythicC2",
            "anonymous": 0,
            "reporter": "navneeet"
        }
    ],
    "1843426": [
        {
            "ioc_value": "167.99.166.159:8686",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-07-02 11:44:19",
            "last_seen_utc": "2026-08-31 07:44:16",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "",
            "tags": "Mythic,MythicC2",
            "anonymous": 0,
            "reporter": "navneeet"
        }
    ],
    "1843475": [
        {
            "ioc_value": "39.106.80.126:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-07-02 10:05:08",
            "last_seen_utc": "2026-08-31 07:48:47",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "cobaltstrike",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1843465": [
        {
            "ioc_value": "82.165.79.60:12001",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.sliver",
            "malware_alias": null,
            "malware_printable": "Sliver",
            "first_seen_utc": "2026-07-02 09:45:46",
            "last_seen_utc": "2026-08-31 07:47:47",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Sliver",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1843466": [
        {
            "ioc_value": "82.165.79.60:12002",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.sliver",
            "malware_alias": null,
            "malware_printable": "Sliver",
            "first_seen_utc": "2026-07-02 09:45:46",
            "last_seen_utc": "2026-08-31 07:47:47",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Sliver",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1843463": [
        {
            "ioc_value": "70.34.251.19:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pupy",
            "malware_alias": "Patpoopy",
            "malware_printable": "pupy",
            "first_seen_utc": "2026-07-02 09:45:42",
            "last_seen_utc": "2026-08-31 07:47:40",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PupyRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1843455": [
        {
            "ioc_value": "159.65.42.43:60560",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.brute_ratel_c4",
            "malware_alias": "BOLDBADGER,BruteRatel",
            "malware_printable": "Brute Ratel C4",
            "first_seen_utc": "2026-07-02 09:43:38",
            "last_seen_utc": "2026-08-31 07:44:09",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "BruteRatel,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1843453": [
        {
            "ioc_value": "141.94.121.162:6060",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.dcrat",
            "malware_alias": "DarkCrystal RAT",
            "malware_printable": "DCRat",
            "first_seen_utc": "2026-07-02 09:43:24",
            "last_seen_utc": "2026-08-31 07:43:47",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DCRat,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1843432": [
        {
            "ioc_value": "121.43.181.37:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-07-02 08:15:52",
            "last_seen_utc": "2026-08-31 07:48:32",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-987654321",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1843350": [
        {
            "ioc_value": "209.200.246.194:37865",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-07-01 23:46:22",
            "last_seen_utc": "2026-08-31 07:48:44",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1843298": [
        {
            "ioc_value": "62.4.0.66:4321",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-07-01 19:45:50",
            "last_seen_utc": "2026-08-29 08:46:48",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1843292": [
        {
            "ioc_value": "185.235.138.19:3000",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.evilginx",
            "malware_alias": null,
            "malware_printable": "Evilginx",
            "first_seen_utc": "2026-07-01 19:44:11",
            "last_seen_utc": "2026-08-30 18:44:23",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Evilginx,EvilGoPhish",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1840740": [
        {
            "ioc_value": "130.12.182.95:6606",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-07-01 09:43:22",
            "last_seen_utc": "2026-08-31 07:43:41",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1840739": [
        {
            "ioc_value": "109.237.64.48:44704",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-07-01 09:43:17",
            "last_seen_utc": "2026-08-31 07:43:28",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1840722": [
        {
            "ioc_value": "119.91.243.238:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-07-01 08:05:06",
            "last_seen_utc": "2026-08-31 07:48:31",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "cobaltstrike",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1840704": [
        {
            "ioc_value": "43.144.19.224:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-07-01 07:05:06",
            "last_seen_utc": "2026-08-31 07:48:48",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "cobaltstrike",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1840388": [
        {
            "ioc_value": "91.92.43.194:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "js.tsundere",
            "malware_alias": "DinDoor",
            "malware_printable": "Tsundere",
            "first_seen_utc": "2026-06-30 19:46:09",
            "last_seen_utc": "2026-08-31 07:48:01",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DinDoor,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1840389": [
        {
            "ioc_value": "91.92.43.195:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "js.tsundere",
            "malware_alias": "DinDoor",
            "malware_printable": "Tsundere",
            "first_seen_utc": "2026-06-30 19:46:09",
            "last_seen_utc": "2026-08-31 07:48:01",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DinDoor,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1840390": [
        {
            "ioc_value": "91.92.43.196:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "js.tsundere",
            "malware_alias": "DinDoor",
            "malware_printable": "Tsundere",
            "first_seen_utc": "2026-06-30 19:46:09",
            "last_seen_utc": "2026-08-31 07:48:01",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DinDoor,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1840387": [
        {
            "ioc_value": "91.92.43.193:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "js.tsundere",
            "malware_alias": "DinDoor",
            "malware_printable": "Tsundere",
            "first_seen_utc": "2026-06-30 19:46:08",
            "last_seen_utc": "2026-08-31 07:48:01",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DinDoor,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1840379": [
        {
            "ioc_value": "193.24.123.25:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "js.tsundere",
            "malware_alias": "DinDoor",
            "malware_printable": "Tsundere",
            "first_seen_utc": "2026-06-30 19:44:21",
            "last_seen_utc": "2026-08-31 07:45:15",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DinDoor,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1840375": [
        {
            "ioc_value": "138.124.240.76:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "js.tsundere",
            "malware_alias": "DinDoor",
            "malware_printable": "Tsundere",
            "first_seen_utc": "2026-06-30 19:43:26",
            "last_seen_utc": "2026-08-31 07:43:45",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DinDoor,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1840376": [
        {
            "ioc_value": "138.124.240.76:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "js.tsundere",
            "malware_alias": "DinDoor",
            "malware_printable": "Tsundere",
            "first_seen_utc": "2026-06-30 19:43:26",
            "last_seen_utc": "2026-08-31 07:43:45",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DinDoor,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1840377": [
        {
            "ioc_value": "138.124.240.77:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "js.tsundere",
            "malware_alias": "DinDoor",
            "malware_printable": "Tsundere",
            "first_seen_utc": "2026-06-30 19:43:26",
            "last_seen_utc": "2026-08-31 07:43:45",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DinDoor,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1840372": [
        {
            "ioc_value": "107.172.22.3:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.havoc",
            "malware_alias": "Havokiz",
            "malware_printable": "Havoc",
            "first_seen_utc": "2026-06-30 19:43:15",
            "last_seen_utc": "2026-08-31 07:43:22",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Havoc",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1840357": [
        {
            "ioc_value": "89.110.90.71:4444",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-06-30 17:45:50",
            "last_seen_utc": "2026-08-31 07:47:54",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1840351": [
        {
            "ioc_value": "2.26.1.177:4321",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-06-30 17:44:15",
            "last_seen_utc": "2026-08-31 07:45:32",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1840350": [
        {
            "ioc_value": "185.117.90.47:3000",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.evilginx",
            "malware_alias": null,
            "malware_printable": "Evilginx",
            "first_seen_utc": "2026-06-30 17:43:56",
            "last_seen_utc": "2026-08-29 18:44:20",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Evilginx,EvilGoPhish",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1840347": [
        {
            "ioc_value": "172.94.18.103:69",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-06-30 17:43:45",
            "last_seen_utc": "2026-08-31 07:44:28",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1840271": [
        {
            "ioc_value": "152.32.132.177:8899",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-06-30 09:54:11",
            "last_seen_utc": "2026-08-31 07:48:34",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-666666666",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1840265": [
        {
            "ioc_value": "170.64.130.99:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-06-30 09:43:50",
            "last_seen_utc": "2026-08-31 07:44:19",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1840262": [
        {
            "ioc_value": "141.94.121.162:6666",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.dcrat",
            "malware_alias": "DarkCrystal RAT",
            "malware_printable": "DCRat",
            "first_seen_utc": "2026-06-30 09:43:27",
            "last_seen_utc": "2026-08-31 07:43:47",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DCRat,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1840261": [
        {
            "ioc_value": "136.113.49.8:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-06-30 09:43:24",
            "last_seen_utc": "2026-08-31 07:43:44",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1840203": [
        {
            "ioc_value": "130.12.182.95:8808",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-06-30 05:05:05",
            "last_seen_utc": "2026-08-31 07:43:41",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "asyncrat",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1839238": [
        {
            "ioc_value": "updatesrv.net",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-06-29 11:46:18",
            "last_seen_utc": "2026-08-31 07:48:20",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1839239": [
        {
            "ioc_value": "web-analyzer-serv32.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-06-29 11:46:18",
            "last_seen_utc": "2026-08-31 07:48:20",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1839220": [
        {
            "ioc_value": "45.92.158.150:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-06-29 09:45:31",
            "last_seen_utc": "2026-08-31 07:47:19",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1838799": [
        {
            "ioc_value": "45.150.38.95:4321",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-06-28 19:44:54",
            "last_seen_utc": "2026-08-31 07:47:09",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1838789": [
        {
            "ioc_value": "104.248.201.191:8080",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-06-28 19:05:05",
            "last_seen_utc": "2026-08-31 07:48:23",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "cobaltstrike",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1838755": [
        {
            "ioc_value": "185.212.128.231:9000",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.evilginx",
            "malware_alias": null,
            "malware_printable": "Evilginx",
            "first_seen_utc": "2026-06-28 09:43:55",
            "last_seen_utc": "2026-08-31 07:44:45",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Evilginx,EvilGoPhish",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1838665": [
        {
            "ioc_value": "45.141.234.47:4321",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-06-27 19:45:17",
            "last_seen_utc": "2026-08-30 08:46:28",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1838660": [
        {
            "ioc_value": "155.94.163.75:8797",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-06-27 19:43:32",
            "last_seen_utc": "2026-08-31 07:44:02",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1838659": [
        {
            "ioc_value": "138.124.84.7:4321",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-06-27 19:43:20",
            "last_seen_utc": "2026-08-31 07:43:45",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1838629": [
        {
            "ioc_value": "47.86.184.71:53",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-06-27 15:46:40",
            "last_seen_utc": "2026-08-31 07:48:53",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1838628": [
        {
            "ioc_value": "test.officeplustool.top",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-06-27 15:46:01",
            "last_seen_utc": "2026-08-31 07:48:20",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1838532": [
        {
            "ioc_value": "8.152.212.104:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-06-27 07:05:05",
            "last_seen_utc": "2026-08-31 07:48:56",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "cobaltstrike",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1838492": [
        {
            "ioc_value": "20.69.167.4:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.havoc",
            "malware_alias": "Havokiz",
            "malware_printable": "Havoc",
            "first_seen_utc": "2026-06-27 03:05:08",
            "last_seen_utc": "2026-08-31 07:45:39",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "havoc",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1838183": [
        {
            "ioc_value": "82.165.79.60:1336",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.sliver",
            "malware_alias": null,
            "malware_printable": "Sliver",
            "first_seen_utc": "2026-06-26 19:45:25",
            "last_seen_utc": "2026-08-31 07:47:47",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Sliver",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1838123": [
        {
            "ioc_value": "https://k1h.hopesm188.top/",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-06-26 12:25:15",
            "last_seen_utc": "2026-08-31 07:23:25",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "k5yss1,Vidar",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1838124": [
        {
            "ioc_value": "k1h.hopesm188.top",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-06-26 12:25:15",
            "last_seen_utc": "2026-08-31 07:23:26",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "k5yss1,Vidar",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1837880": [
        {
            "ioc_value": "122.51.221.207:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-06-26 07:18:38",
            "last_seen_utc": "2026-08-31 07:48:32",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": null,
            "tags": "45090,c2,censys,cobalt strike",
            "anonymous": 0,
            "reporter": "sojubear"
        }
    ],
    "1837449": [
        {
            "ioc_value": "50.114.184.63:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-06-25 18:54:17",
            "last_seen_utc": "2026-08-31 07:47:26",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "",
            "tags": "PureHVNC,PureRAT,ResolverRAT",
            "anonymous": 0,
            "reporter": "whoamix302"
        }
    ],
    "1837476": [
        {
            "ioc_value": "45.192.211.64:56002",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-06-25 18:54:02",
            "last_seen_utc": "2026-08-31 07:47:12",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "",
            "tags": "PureHVNC,PureRAT,ResolverRAT",
            "anonymous": 0,
            "reporter": "whoamix302"
        }
    ],
    "1837477": [
        {
            "ioc_value": "45.192.211.64:56003",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-06-25 18:54:02",
            "last_seen_utc": "2026-08-31 07:47:12",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "",
            "tags": "PureHVNC,PureRAT,ResolverRAT",
            "anonymous": 0,
            "reporter": "whoamix302"
        }
    ],
    "1837478": [
        {
            "ioc_value": "45.192.211.64:56001",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-06-25 18:54:02",
            "last_seen_utc": "2026-08-31 07:47:12",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "",
            "tags": "PureHVNC,PureRAT,ResolverRAT",
            "anonymous": 0,
            "reporter": "whoamix302"
        }
    ],
    "1837499": [
        {
            "ioc_value": "216.107.139.88:56001",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-06-25 18:53:44",
            "last_seen_utc": "2026-08-31 07:45:52",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "",
            "tags": "PureHVNC,PureRAT,ResolverRAT",
            "anonymous": 0,
            "reporter": "whoamix302"
        }
    ],
    "1837500": [
        {
            "ioc_value": "94.26.3.104:56001",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-06-25 18:53:44",
            "last_seen_utc": "2026-08-31 07:48:09",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "",
            "tags": "PureHVNC,PureRAT,ResolverRAT",
            "anonymous": 0,
            "reporter": "whoamix302"
        }
    ],
    "1837501": [
        {
            "ioc_value": "94.26.3.104:56002",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-06-25 18:53:43",
            "last_seen_utc": "2026-08-31 07:48:09",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "",
            "tags": "PureHVNC,PureRAT,ResolverRAT",
            "anonymous": 0,
            "reporter": "whoamix302"
        }
    ],
    "1837502": [
        {
            "ioc_value": "94.26.3.104:56003",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-06-25 18:53:43",
            "last_seen_utc": "2026-08-31 07:48:09",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "",
            "tags": "PureHVNC,PureRAT,ResolverRAT",
            "anonymous": 0,
            "reporter": "whoamix302"
        }
    ],
    "1837441": [
        {
            "ioc_value": "45.192.211.59:56001",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-06-25 15:17:46",
            "last_seen_utc": "2026-08-31 07:47:11",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "",
            "tags": "PureHVNC,PureRAT,ResolverRAT",
            "anonymous": 0,
            "reporter": "whoamix302"
        }
    ],
    "1837442": [
        {
            "ioc_value": "45.192.211.59:56002",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-06-25 15:17:45",
            "last_seen_utc": "2026-08-31 07:47:11",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "",
            "tags": "PureHVNC,PureRAT,ResolverRAT",
            "anonymous": 0,
            "reporter": "whoamix302"
        }
    ],
    "1837443": [
        {
            "ioc_value": "45.192.211.59:56003",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-06-25 15:17:44",
            "last_seen_utc": "2026-08-31 07:47:12",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "",
            "tags": "PureHVNC,PureRAT,ResolverRAT",
            "anonymous": 0,
            "reporter": "whoamix302"
        }
    ],
    "1837265": [
        {
            "ioc_value": "45.192.211.63:56001",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-06-25 08:21:13",
            "last_seen_utc": "2026-08-31 07:47:12",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "",
            "tags": "PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1837243": [
        {
            "ioc_value": "169.239.128.43:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-06-25 08:08:03",
            "last_seen_utc": "2026-08-31 07:48:38",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-987654321",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1837080": [
        {
            "ioc_value": "146.190.80.105:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.havoc",
            "malware_alias": "Havokiz",
            "malware_printable": "Havoc",
            "first_seen_utc": "2026-06-24 19:43:22",
            "last_seen_utc": "2026-08-31 07:43:50",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Havoc",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1836781": [
        {
            "ioc_value": "38.207.177.71:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-06-24 09:45:14",
            "last_seen_utc": "2026-08-31 07:46:57",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1836771": [
        {
            "ioc_value": "107.172.140.187:32333",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-06-24 09:43:12",
            "last_seen_utc": "2026-08-31 07:43:21",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1836745": [
        {
            "ioc_value": "45.192.211.77:56001",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-06-24 07:46:37",
            "last_seen_utc": "2026-08-31 07:47:13",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://bazaar.abuse.ch/sample/d025a29613e300d7755f878eb1d23d8a8a042cb2d3eb9005d66664ab9b97c677/",
            "tags": "PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1836703": [
        {
            "ioc_value": "www.rmsmarineservice.com.qwqqwq.ggff.net",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-06-24 03:45:54",
            "last_seen_utc": "2026-08-31 07:48:21",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1836662": [
        {
            "ioc_value": "156.239.47.147:4221",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-06-23 19:43:29",
            "last_seen_utc": "2026-08-31 07:44:03",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1836201": [
        {
            "ioc_value": "62.234.22.228:51123",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-06-22 23:46:20",
            "last_seen_utc": "2026-08-31 07:48:54",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1835561": [
        {
            "ioc_value": "185.212.128.215:9000",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.evilginx",
            "malware_alias": null,
            "malware_printable": "Evilginx",
            "first_seen_utc": "2026-06-22 09:43:56",
            "last_seen_utc": "2026-08-31 07:44:45",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Evilginx,EvilGoPhish",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1835556": [
        {
            "ioc_value": "102.220.160.250:7829",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-06-22 09:43:03",
            "last_seen_utc": "2026-08-31 07:43:06",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1834913": [
        {
            "ioc_value": "176.65.144.30:1337",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.netsupportmanager_rat",
            "malware_alias": "NetSupport",
            "malware_printable": "NetSupportManager RAT",
            "first_seen_utc": "2026-06-21 18:27:31",
            "last_seen_utc": "2026-08-30 00:06:13",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "clickfix,evalusion,jarm:1276612955,merry-florist,netsupport,port:1337,single-gateway,unc2190",
            "anonymous": 0,
            "reporter": "Justice_Hammer"
        }
    ],
    "1834914": [
        {
            "ioc_value": "momsdodigital.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "win.netsupportmanager_rat",
            "malware_alias": "NetSupport",
            "malware_printable": "NetSupportManager RAT",
            "first_seen_utc": "2026-06-21 18:27:30",
            "last_seen_utc": "2026-08-30 00:06:15",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "central-hub,clickfix,clickfix-hub,evalusion,merry-florist,netsupport,unc2190,wordpress-compromise",
            "anonymous": 0,
            "reporter": "Justice_Hammer"
        }
    ],
    "1834916": [
        {
            "ioc_value": "daskljtitaskastvv.pro",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "win.netsupportmanager_rat",
            "malware_alias": "NetSupport",
            "malware_printable": "NetSupportManager RAT",
            "first_seen_utc": "2026-06-21 18:27:30",
            "last_seen_utc": "2026-08-30 00:06:14",
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "clickfix,evalusion,fake-captcha,merry-florist,netsupport,unc2190,wordpress-injection",
            "anonymous": 0,
            "reporter": "Justice_Hammer"
        }
    ],
    "1834915": [
        {
            "ioc_value": "deoint.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "win.netsupportmanager_rat",
            "malware_alias": "NetSupport",
            "malware_printable": "NetSupportManager RAT",
            "first_seen_utc": "2026-06-21 18:27:29",
            "last_seen_utc": "2026-08-30 00:06:14",
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "clickfix,evalusion,fake-captcha,merry-florist,netsupport,unc2190,wordpress-injection",
            "anonymous": 0,
            "reporter": "Justice_Hammer"
        }
    ],
    "1834917": [
        {
            "ioc_value": "lobsterrakkos.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.netsupportmanager_rat",
            "malware_alias": "NetSupport",
            "malware_printable": "NetSupportManager RAT",
            "first_seen_utc": "2026-06-21 18:27:28",
            "last_seen_utc": "2026-08-30 00:06:12",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "c2-rotation,clickfix,evalusion,merry-florist,netsupport,single-gateway,unc2190",
            "anonymous": 0,
            "reporter": "Justice_Hammer"
        }
    ],
    "1834918": [
        {
            "ioc_value": "kiskapeskaloska.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.netsupportmanager_rat",
            "malware_alias": "NetSupport",
            "malware_printable": "NetSupportManager RAT",
            "first_seen_utc": "2026-06-21 18:27:28",
            "last_seen_utc": "2026-08-30 00:06:12",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "c2-rotation,clickfix,evalusion,merry-florist,netsupport,single-gateway,unc2190",
            "anonymous": 0,
            "reporter": "Justice_Hammer"
        }
    ],
    "1834919": [
        {
            "ioc_value": "lopapopamiskasupa.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.netsupportmanager_rat",
            "malware_alias": "NetSupport",
            "malware_printable": "NetSupportManager RAT",
            "first_seen_utc": "2026-06-21 18:27:28",
            "last_seen_utc": "2026-08-30 00:06:12",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "c2-rotation,clickfix,evalusion,merry-florist,netsupport,single-gateway,unc2190",
            "anonymous": 0,
            "reporter": "Justice_Hammer"
        }
    ],
    "1834920": [
        {
            "ioc_value": "kasmokitomaccito.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.netsupportmanager_rat",
            "malware_alias": "NetSupport",
            "malware_printable": "NetSupportManager RAT",
            "first_seen_utc": "2026-06-21 18:27:26",
            "last_seen_utc": "2026-08-30 00:06:12",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "c2-rotation,clickfix,evalusion,merry-florist,netsupport,single-gateway,unc2190",
            "anonymous": 0,
            "reporter": "Justice_Hammer"
        }
    ],
    "1834921": [
        {
            "ioc_value": "posostamioalkfjka.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.netsupportmanager_rat",
            "malware_alias": "NetSupport",
            "malware_printable": "NetSupportManager RAT",
            "first_seen_utc": "2026-06-21 18:27:26",
            "last_seen_utc": "2026-08-30 00:06:13",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "c2-rotation,clickfix,evalusion,merry-florist,netsupport,single-gateway,unc2190",
            "anonymous": 0,
            "reporter": "Justice_Hammer"
        }
    ],
    "1834922": [
        {
            "ioc_value": "ostamioalkfjka.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.netsupportmanager_rat",
            "malware_alias": "NetSupport",
            "malware_printable": "NetSupportManager RAT",
            "first_seen_utc": "2026-06-21 18:27:25",
            "last_seen_utc": "2026-08-30 00:06:13",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "c2-rotation,clickfix,evalusion,merry-florist,netsupport,single-gateway,unc2190",
            "anonymous": 0,
            "reporter": "Justice_Hammer"
        }
    ],
    "1834923": [
        {
            "ioc_value": "opfiksotpffff.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.netsupportmanager_rat",
            "malware_alias": "NetSupport",
            "malware_printable": "NetSupportManager RAT",
            "first_seen_utc": "2026-06-21 18:27:25",
            "last_seen_utc": "2026-08-30 00:06:13",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "c2-rotation,clickfix,evalusion,merry-florist,netsupport,single-gateway,unc2190",
            "anonymous": 0,
            "reporter": "Justice_Hammer"
        }
    ],
    "1834924": [
        {
            "ioc_value": "oficekoslosld.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.netsupportmanager_rat",
            "malware_alias": "NetSupport",
            "malware_printable": "NetSupportManager RAT",
            "first_seen_utc": "2026-06-21 18:27:24",
            "last_seen_utc": "2026-08-30 00:06:13",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "c2-rotation,clickfix,evalusion,merry-florist,netsupport,single-gateway,unc2190",
            "anonymous": 0,
            "reporter": "Justice_Hammer"
        }
    ],
    "1834925": [
        {
            "ioc_value": "tomaskoslimsok.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.netsupportmanager_rat",
            "malware_alias": "NetSupport",
            "malware_printable": "NetSupportManager RAT",
            "first_seen_utc": "2026-06-21 18:27:24",
            "last_seen_utc": "2026-08-30 00:06:13",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "c2-rotation,clickfix,evalusion,merry-florist,netsupport,single-gateway,unc2190",
            "anonymous": 0,
            "reporter": "Justice_Hammer"
        }
    ],
    "1834926": [
        {
            "ioc_value": "msiulosjudiid.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.netsupportmanager_rat",
            "malware_alias": "NetSupport",
            "malware_printable": "NetSupportManager RAT",
            "first_seen_utc": "2026-06-21 18:27:22",
            "last_seen_utc": "2026-08-30 00:06:12",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "c2-rotation,clickfix,evalusion,merry-florist,netsupport,single-gateway,unc2190",
            "anonymous": 0,
            "reporter": "Justice_Hammer"
        }
    ],
    "1834927": [
        {
            "ioc_value": "mxjxifkfkkffjjf.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.netsupportmanager_rat",
            "malware_alias": "NetSupport",
            "malware_printable": "NetSupportManager RAT",
            "first_seen_utc": "2026-06-21 18:27:21",
            "last_seen_utc": "2026-08-30 00:06:13",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "c2-rotation,clickfix,evalusion,merry-florist,netsupport,single-gateway,unc2190",
            "anonymous": 0,
            "reporter": "Justice_Hammer"
        }
    ],
    "1834928": [
        {
            "ioc_value": "fopsadfposkdf.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.netsupportmanager_rat",
            "malware_alias": "NetSupport",
            "malware_printable": "NetSupportManager RAT",
            "first_seen_utc": "2026-06-21 18:27:21",
            "last_seen_utc": "2026-08-30 00:06:12",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "c2-rotation,clickfix,evalusion,merry-florist,netsupport,single-gateway,unc2190",
            "anonymous": 0,
            "reporter": "Justice_Hammer"
        }
    ],
    "1834929": [
        {
            "ioc_value": "hdudidjdjdndjdjd.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.netsupportmanager_rat",
            "malware_alias": "NetSupport",
            "malware_printable": "NetSupportManager RAT",
            "first_seen_utc": "2026-06-21 18:27:20",
            "last_seen_utc": "2026-08-30 00:06:12",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "c2-rotation,clickfix,evalusion,merry-florist,netsupport,single-gateway,unc2190",
            "anonymous": 0,
            "reporter": "Justice_Hammer"
        }
    ],
    "1834930": [
        {
            "ioc_value": "skadfjsdijfhsfso9to.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.netsupportmanager_rat",
            "malware_alias": "NetSupport",
            "malware_printable": "NetSupportManager RAT",
            "first_seen_utc": "2026-06-21 18:27:19",
            "last_seen_utc": "2026-08-30 00:06:13",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "c2-rotation,clickfix,evalusion,merry-florist,netsupport,single-gateway,unc2190",
            "anonymous": 0,
            "reporter": "Justice_Hammer"
        }
    ],
    "1834931": [
        {
            "ioc_value": "asmfmfmfmf.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.netsupportmanager_rat",
            "malware_alias": "NetSupport",
            "malware_printable": "NetSupportManager RAT",
            "first_seen_utc": "2026-06-21 18:27:19",
            "last_seen_utc": "2026-08-30 00:06:12",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "c2-rotation,clickfix,evalusion,merry-florist,netsupport,single-gateway,unc2190",
            "anonymous": 0,
            "reporter": "Justice_Hammer"
        }
    ],
    "1834932": [
        {
            "ioc_value": "daisiiafsfk.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.netsupportmanager_rat",
            "malware_alias": "NetSupport",
            "malware_printable": "NetSupportManager RAT",
            "first_seen_utc": "2026-06-21 18:27:19",
            "last_seen_utc": "2026-08-30 00:06:12",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "c2-rotation,clickfix,evalusion,merry-florist,netsupport,single-gateway,unc2190",
            "anonymous": 0,
            "reporter": "Justice_Hammer"
        }
    ],
    "1834933": [
        {
            "ioc_value": "dkilkamajsiot.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.netsupportmanager_rat",
            "malware_alias": "NetSupport",
            "malware_printable": "NetSupportManager RAT",
            "first_seen_utc": "2026-06-21 18:27:18",
            "last_seen_utc": "2026-08-30 00:06:12",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "c2-rotation,clickfix,evalusion,merry-florist,netsupport,single-gateway,unc2190",
            "anonymous": 0,
            "reporter": "Justice_Hammer"
        }
    ],
    "1834934": [
        {
            "ioc_value": "lopstmisot.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.netsupportmanager_rat",
            "malware_alias": "NetSupport",
            "malware_printable": "NetSupportManager RAT",
            "first_seen_utc": "2026-06-21 18:27:18",
            "last_seen_utc": "2026-08-30 00:06:12",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "c2-rotation,clickfix,evalusion,merry-florist,netsupport,single-gateway,unc2190",
            "anonymous": 0,
            "reporter": "Justice_Hammer"
        }
    ],
    "1834935": [
        {
            "ioc_value": "fastoqoakkas.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.netsupportmanager_rat",
            "malware_alias": "NetSupport",
            "malware_printable": "NetSupportManager RAT",
            "first_seen_utc": "2026-06-21 18:27:18",
            "last_seen_utc": "2026-08-30 00:06:12",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "c2-rotation,clickfix,evalusion,merry-florist,netsupport,single-gateway,unc2190",
            "anonymous": 0,
            "reporter": "Justice_Hammer"
        }
    ],
    "1834936": [
        {
            "ioc_value": "asqmvmastt.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.netsupportmanager_rat",
            "malware_alias": "NetSupport",
            "malware_printable": "NetSupportManager RAT",
            "first_seen_utc": "2026-06-21 18:27:17",
            "last_seen_utc": "2026-08-30 00:06:12",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "c2-rotation,clickfix,evalusion,merry-florist,netsupport,single-gateway,unc2190",
            "anonymous": 0,
            "reporter": "Justice_Hammer"
        }
    ],
    "1834937": [
        {
            "ioc_value": "aosotaka.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.netsupportmanager_rat",
            "malware_alias": "NetSupport",
            "malware_printable": "NetSupportManager RAT",
            "first_seen_utc": "2026-06-21 18:27:17",
            "last_seen_utc": "2026-08-30 00:06:12",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "c2-rotation,clickfix,evalusion,merry-florist,netsupport,single-gateway,unc2190",
            "anonymous": 0,
            "reporter": "Justice_Hammer"
        }
    ],
    "1834938": [
        {
            "ioc_value": "foasfjkasf.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.netsupportmanager_rat",
            "malware_alias": "NetSupport",
            "malware_printable": "NetSupportManager RAT",
            "first_seen_utc": "2026-06-21 18:27:17",
            "last_seen_utc": "2026-08-30 00:06:12",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "c2-rotation,clickfix,evalusion,merry-florist,netsupport,single-gateway,unc2190",
            "anonymous": 0,
            "reporter": "Justice_Hammer"
        }
    ],
    "1834771": [
        {
            "ioc_value": "89.42.134.220:6606",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-06-21 09:45:40",
            "last_seen_utc": "2026-08-31 07:47:56",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1834770": [
        {
            "ioc_value": "51.79.51.255:4321",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-06-21 09:45:23",
            "last_seen_utc": "2026-08-31 07:47:28",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1834187": [
        {
            "ioc_value": "23.141.12.111:8899",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-06-19 23:46:13",
            "last_seen_utc": "2026-08-31 07:48:45",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1834170": [
        {
            "ioc_value": "97.74.92.237:63334",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-06-19 19:45:40",
            "last_seen_utc": "2026-08-31 07:48:12",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1834168": [
        {
            "ioc_value": "211.235.43.192:7707",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-06-19 19:44:17",
            "last_seen_utc": "2026-08-31 07:45:50",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1834132": [
        {
            "ioc_value": "47.242.0.207:8080",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-06-19 15:46:26",
            "last_seen_utc": "2026-08-31 07:48:52",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1834133": [
        {
            "ioc_value": "47.242.0.207:9999",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-06-19 15:46:26",
            "last_seen_utc": "2026-08-31 07:48:52",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1834131": [
        {
            "ioc_value": "114.134.187.38:9999",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-06-19 15:45:55",
            "last_seen_utc": "2026-08-31 07:48:26",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1834098": [
        {
            "ioc_value": "185.92.190.214:8896",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-06-19 11:46:35",
            "last_seen_utc": "2026-08-29 18:47:27",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1834099": [
        {
            "ioc_value": "185.92.190.216:8896",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-06-19 11:46:35",
            "last_seen_utc": "2026-08-29 18:47:27",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1834082": [
        {
            "ioc_value": "golviewcheckus.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "win.netsupportmanager_rat",
            "malware_alias": "NetSupport",
            "malware_printable": "NetSupportManager RAT",
            "first_seen_utc": "2026-06-19 11:36:32",
            "last_seen_utc": "2026-08-30 00:06:13",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://gist.github.com/jay-salihov/ea2ec22039ad225094e9e25260f4af89",
            "tags": "ClickFix,NetSupport,PowerShell",
            "anonymous": 0,
            "reporter": "alpaco"
        }
    ],
    "1834083": [
        {
            "ioc_value": "tiqwtkmma.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.netsupportmanager_rat",
            "malware_alias": "NetSupport",
            "malware_printable": "NetSupportManager RAT",
            "first_seen_utc": "2026-06-19 11:36:32",
            "last_seen_utc": "2026-08-30 00:06:13",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://gist.github.com/jay-salihov/ea2ec22039ad225094e9e25260f4af89",
            "tags": "C2,NetSupport,RAT",
            "anonymous": 0,
            "reporter": "alpaco"
        }
    ],
    "1834084": [
        {
            "ioc_value": "zbxcgtqt.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.netsupportmanager_rat",
            "malware_alias": "NetSupport",
            "malware_printable": "NetSupportManager RAT",
            "first_seen_utc": "2026-06-19 11:36:31",
            "last_seen_utc": "2026-08-30 00:06:13",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://gist.github.com/jay-salihov/ea2ec22039ad225094e9e25260f4af89",
            "tags": "C2,NetSupport,RAT",
            "anonymous": 0,
            "reporter": "alpaco"
        }
    ],
    "1834051": [
        {
            "ioc_value": "103.153.254.32:6933",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-06-19 09:43:05",
            "last_seen_utc": "2026-08-31 07:43:08",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1833852": [
        {
            "ioc_value": "115.190.108.6:54233",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.poshc2",
            "malware_alias": null,
            "malware_printable": "PoshC2",
            "first_seen_utc": "2026-06-18 19:43:11",
            "last_seen_utc": "2026-08-31 07:43:31",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PoshC2",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1833750": [
        {
            "ioc_value": "54.38.94.225:8884",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.eye_pyramid",
            "malware_alias": null,
            "malware_printable": "Eye Pyramid",
            "first_seen_utc": "2026-06-18 09:45:43",
            "last_seen_utc": "2026-08-31 07:47:30",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,EyePyramid",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1833500": [
        {
            "ioc_value": "20.39.60.137:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.havoc",
            "malware_alias": "Havokiz",
            "malware_printable": "Havoc",
            "first_seen_utc": "2026-06-17 17:00:15",
            "last_seen_utc": "2026-08-31 07:45:39",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "havoc",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1833435": [
        {
            "ioc_value": "185.92.190.217:8896",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-06-17 11:46:36",
            "last_seen_utc": "2026-08-29 18:47:27",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1833008": [
        {
            "ioc_value": "212.14.244.222:807",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-06-16 23:46:00",
            "last_seen_utc": "2026-08-31 07:48:44",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1833009": [
        {
            "ioc_value": "212.14.244.222:809",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-06-16 23:46:00",
            "last_seen_utc": "2026-08-31 07:48:44",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1832762": [
        {
            "ioc_value": "119.59.118.75:4321",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-06-16 19:43:12",
            "last_seen_utc": "2026-08-31 07:43:34",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1832647": [
        {
            "ioc_value": "39.106.205.6:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-06-16 11:00:15",
            "last_seen_utc": "2026-08-31 07:48:47",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "cobaltstrike",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1832633": [
        {
            "ioc_value": "91.132.161.21:4321",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-06-16 09:45:48",
            "last_seen_utc": "2026-08-31 07:47:56",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1832629": [
        {
            "ioc_value": "2.26.229.254:4321",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-06-16 09:44:09",
            "last_seen_utc": "2026-08-31 07:45:33",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1832514": [
        {
            "ioc_value": "usa.goturbo88.top",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-06-15 22:24:53",
            "last_seen_utc": "2026-08-30 18:46:33",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "i7sb1k,Vidar",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1832399": [
        {
            "ioc_value": "23.95.170.223:18443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-06-15 15:46:19",
            "last_seen_utc": "2026-08-31 07:48:45",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1832398": [
        {
            "ioc_value": "cs.tpedu2metricstw.dpdns.org",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-06-15 15:45:49",
            "last_seen_utc": "2026-08-31 07:48:16",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1832372": [
        {
            "ioc_value": "gnw.goturbo88.top",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-06-15 13:24:49",
            "last_seen_utc": "2026-08-30 18:46:34",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "i7sb1k,Vidar",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1832323": [
        {
            "ioc_value": "89.42.134.220:1803",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-06-15 09:45:54",
            "last_seen_utc": "2026-08-31 07:47:55",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1832320": [
        {
            "ioc_value": "8.210.84.56:8000",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-06-15 09:45:46",
            "last_seen_utc": "2026-08-31 07:47:43",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1832313": [
        {
            "ioc_value": "131.143.251.246:53921",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-06-15 09:43:17",
            "last_seen_utc": "2026-08-31 07:43:42",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1832243": [
        {
            "ioc_value": "snd.goturbo88.top",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-06-15 06:13:23",
            "last_seen_utc": "2026-08-30 18:46:33",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "Vidar",
            "anonymous": 0,
            "reporter": "crep1x"
        }
    ],
    "1832244": [
        {
            "ioc_value": "ikg.goturbo88.top",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-06-15 06:13:23",
            "last_seen_utc": "2026-08-30 18:46:33",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "Vidar",
            "anonymous": 0,
            "reporter": "crep1x"
        }
    ],
    "1832245": [
        {
            "ioc_value": "ggt.goturbo88.top",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-06-15 06:13:23",
            "last_seen_utc": "2026-08-30 18:46:34",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "Vidar",
            "anonymous": 0,
            "reporter": "crep1x"
        }
    ],
    "1832163": [
        {
            "ioc_value": "89.42.134.220:8808",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-06-14 19:45:30",
            "last_seen_utc": "2026-08-31 07:47:56",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1832158": [
        {
            "ioc_value": "43.133.164.200:4321",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-06-14 19:44:54",
            "last_seen_utc": "2026-08-31 07:47:01",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1831995": [
        {
            "ioc_value": "64.225.102.218:31400",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.evilginx",
            "malware_alias": null,
            "malware_printable": "Evilginx",
            "first_seen_utc": "2026-06-14 09:45:07",
            "last_seen_utc": "2026-08-31 07:47:35",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Evilginx,EvilGoPhish",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1831987": [
        {
            "ioc_value": "185.207.154.11:4848",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-06-14 09:43:43",
            "last_seen_utc": "2026-08-31 07:44:44",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1831838": [
        {
            "ioc_value": "45.153.127.224:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.chaos",
            "malware_alias": "FakeRyuk,RyukJoke,Yashma",
            "malware_printable": "Chaos",
            "first_seen_utc": "2026-06-13 19:45:04",
            "last_seen_utc": "2026-08-31 07:47:09",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CHAOS,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1831732": [
        {
            "ioc_value": "89.42.134.220:1991",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-06-13 09:46:08",
            "last_seen_utc": "2026-08-31 07:47:55",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1831722": [
        {
            "ioc_value": "130.185.82.117:5641",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-06-13 09:43:18",
            "last_seen_utc": "2026-08-31 07:43:41",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1831720": [
        {
            "ioc_value": "108.181.115.254:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.ransomhub",
            "malware_alias": null,
            "malware_printable": "RansomHub",
            "first_seen_utc": "2026-06-13 09:43:12",
            "last_seen_utc": "2026-08-31 07:43:24",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RansomHub",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1831721": [
        {
            "ioc_value": "108.181.115.254:7045",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.ransomhub",
            "malware_alias": null,
            "malware_printable": "RansomHub",
            "first_seen_utc": "2026-06-13 09:43:12",
            "last_seen_utc": "2026-08-31 07:43:25",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RansomHub",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1831717": [
        {
            "ioc_value": "101.33.202.134:9989",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-06-13 09:43:02",
            "last_seen_utc": "2026-08-31 07:43:03",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1830843": [
        {
            "ioc_value": "31.57.184.154:7008",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-06-12 09:44:45",
            "last_seen_utc": "2026-08-30 08:46:11",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1830834": [
        {
            "ioc_value": "114.132.238.70:4321",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-06-12 09:43:11",
            "last_seen_utc": "2026-08-31 07:43:31",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1830833": [
        {
            "ioc_value": "110.42.34.220:4321",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-06-12 09:43:10",
            "last_seen_utc": "2026-08-31 07:43:29",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1830390": [
        {
            "ioc_value": "209.99.188.193:43221",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-06-11 19:44:02",
            "last_seen_utc": "2026-08-31 07:45:48",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1830387": [
        {
            "ioc_value": "192.3.139.18:15221",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-06-11 19:43:50",
            "last_seen_utc": "2026-08-31 07:45:11",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1830307": [
        {
            "ioc_value": "172.94.18.103:79",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-06-11 14:00:17",
            "last_seen_utc": "2026-08-31 07:44:28",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "asyncrat",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1830206": [
        {
            "ioc_value": "117.72.159.215:8080",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-06-11 12:42:24",
            "last_seen_utc": "2026-08-31 07:48:27",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": "https://www.shodan.io/host/117.72.159.215#8080",
            "tags": "c2,cobaltstrike,cs-watermark-987654321,shodan",
            "anonymous": 0,
            "reporter": "juroots"
        }
    ],
    "1830053": [
        {
            "ioc_value": "206.81.21.156:4321",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-06-11 09:44:07",
            "last_seen_utc": "2026-08-31 07:45:44",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1830007": [
        {
            "ioc_value": "45.87.53.6:8443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-06-11 06:43:05",
            "last_seen_utc": "2026-08-31 07:48:50",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-987654321",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1830006": [
        {
            "ioc_value": "120.55.3.157:10000",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-06-11 06:43:04",
            "last_seen_utc": "2026-08-31 07:48:31",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-987654321",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1830004": [
        {
            "ioc_value": "43.136.180.88:8080",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-06-11 06:42:48",
            "last_seen_utc": "2026-08-31 07:48:48",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-666666666",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1830002": [
        {
            "ioc_value": "43.136.180.88:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-06-11 06:42:47",
            "last_seen_utc": "2026-08-31 07:48:48",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-666666666",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1830003": [
        {
            "ioc_value": "47.121.181.148:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-06-11 06:42:47",
            "last_seen_utc": "2026-08-31 07:48:51",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-666666",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1829957": [
        {
            "ioc_value": "192.144.213.21:18443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-06-11 05:26:05",
            "last_seen_utc": "2026-08-31 07:48:42",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": null,
            "tags": "45090,c2,censys,cobalt strike",
            "anonymous": 0,
            "reporter": "sojubear"
        }
    ],
    "1829899": [
        {
            "ioc_value": "193.135.137.240:4321",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-06-10 19:43:51",
            "last_seen_utc": "2026-08-31 07:45:12",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1829893": [
        {
            "ioc_value": "172.94.18.103:71",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-06-10 19:43:34",
            "last_seen_utc": "2026-08-31 07:44:28",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1829892": [
        {
            "ioc_value": "170.39.185.141:2030",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.evilginx",
            "malware_alias": null,
            "malware_printable": "Evilginx",
            "first_seen_utc": "2026-06-10 19:43:32",
            "last_seen_utc": "2026-08-31 07:44:19",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Evilginx,EvilGoPhish",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1829779": [
        {
            "ioc_value": "185.92.190.214:5896",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-06-10 11:45:53",
            "last_seen_utc": "2026-08-29 18:47:27",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1829780": [
        {
            "ioc_value": "185.92.190.215:5896",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-06-10 11:45:53",
            "last_seen_utc": "2026-08-29 18:47:27",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1829781": [
        {
            "ioc_value": "185.92.190.215:8896",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-06-10 11:45:53",
            "last_seen_utc": "2026-08-29 18:47:27",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1829782": [
        {
            "ioc_value": "185.92.190.216:5896",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-06-10 11:45:53",
            "last_seen_utc": "2026-08-29 18:47:27",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1829783": [
        {
            "ioc_value": "185.92.190.217:5896",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-06-10 11:45:53",
            "last_seen_utc": "2026-08-29 18:47:27",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1829777": [
        {
            "ioc_value": "185.92.190.213:5896",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-06-10 11:45:52",
            "last_seen_utc": "2026-08-29 18:47:27",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1829778": [
        {
            "ioc_value": "185.92.190.213:8896",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-06-10 11:45:52",
            "last_seen_utc": "2026-08-29 18:47:27",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1825867": [
        {
            "ioc_value": "64.89.162.117:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-06-10 09:45:40",
            "last_seen_utc": "2026-08-31 07:47:37",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1825853": [
        {
            "ioc_value": "192.208.12.91:3000",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.evilginx",
            "malware_alias": null,
            "malware_printable": "Evilginx",
            "first_seen_utc": "2026-06-10 09:44:00",
            "last_seen_utc": "2026-08-31 07:45:07",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Evilginx,EvilGoPhish",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1825850": [
        {
            "ioc_value": "163.245.217.48:3333",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.evilginx",
            "malware_alias": null,
            "malware_printable": "Evilginx",
            "first_seen_utc": "2026-06-10 09:43:35",
            "last_seen_utc": "2026-08-31 07:44:14",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Evilginx,EvilGoPhish",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1825846": [
        {
            "ioc_value": "107.175.87.234:65321",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-06-10 09:43:10",
            "last_seen_utc": "2026-08-31 07:43:24",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1825788": [
        {
            "ioc_value": "34.92.128.98:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-06-10 07:18:53",
            "last_seen_utc": "2026-08-31 07:48:46",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-987654321",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1825703": [
        {
            "ioc_value": "8.163.59.20:8008",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-06-10 06:00:25",
            "last_seen_utc": "2026-08-31 07:48:57",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "cobaltstrike",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1825613": [
        {
            "ioc_value": "46.151.182.16:1011",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-06-09 19:44:51",
            "last_seen_utc": "2026-08-31 07:47:20",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1824508": [
        {
            "ioc_value": "209.200.246.194:17568",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-06-07 23:45:14",
            "last_seen_utc": "2026-08-31 07:48:43",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1824433": [
        {
            "ioc_value": "82.156.224.184:8080",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.havoc",
            "malware_alias": "Havokiz",
            "malware_printable": "Havoc",
            "first_seen_utc": "2026-06-07 19:45:00",
            "last_seen_utc": "2026-08-31 07:47:46",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Havoc",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1824426": [
        {
            "ioc_value": "172.189.57.198:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.havoc",
            "malware_alias": "Havokiz",
            "malware_printable": "Havoc",
            "first_seen_utc": "2026-06-07 19:43:30",
            "last_seen_utc": "2026-08-31 07:44:22",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Havoc",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1824255": [
        {
            "ioc_value": "31.57.184.154:2505",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-06-07 09:44:50",
            "last_seen_utc": "2026-08-31 07:46:47",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1824254": [
        {
            "ioc_value": "209.99.188.193:4323",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-06-07 09:44:10",
            "last_seen_utc": "2026-08-31 07:45:48",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1824251": [
        {
            "ioc_value": "154.94.232.165:4321",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-06-07 09:43:26",
            "last_seen_utc": "2026-08-29 08:43:50",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1824247": [
        {
            "ioc_value": "137.184.163.27:5613",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-06-07 09:43:16",
            "last_seen_utc": "2026-08-31 07:43:44",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1824088": [
        {
            "ioc_value": "94.26.3.52:56003",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-06-07 07:23:27",
            "last_seen_utc": "2026-08-31 07:48:10",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "PureHVNC,PureRAT,ResolverRAT",
            "anonymous": 0,
            "reporter": "whoamix302"
        }
    ],
    "1824099": [
        {
            "ioc_value": "77.83.39.141:56003",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-06-07 07:23:22",
            "last_seen_utc": "2026-08-31 07:47:42",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "PureHVNC,PureRAT,ResolverRAT",
            "anonymous": 0,
            "reporter": "whoamix302"
        }
    ],
    "1824130": [
        {
            "ioc_value": "46.151.182.243:55380",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.dcrat",
            "malware_alias": "DarkCrystal RAT",
            "malware_printable": "DCRat",
            "first_seen_utc": "2026-06-06 19:44:30",
            "last_seen_utc": "2026-08-31 07:47:21",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DCRat,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1824029": [
        {
            "ioc_value": "154.12.86.154:55555",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-06-06 11:45:14",
            "last_seen_utc": "2026-08-31 07:48:35",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1824030": [
        {
            "ioc_value": "154.12.86.154:8889",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-06-06 11:45:14",
            "last_seen_utc": "2026-08-31 07:48:35",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1824031": [
        {
            "ioc_value": "154.12.86.154:9004",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-06-06 11:45:14",
            "last_seen_utc": "2026-08-31 07:48:35",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1824012": [
        {
            "ioc_value": "47.101.51.235:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-06-06 10:32:30",
            "last_seen_utc": "2026-08-31 07:48:50",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-666666",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1823853": [
        {
            "ioc_value": "https://pas.sm188star.top/",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-06-06 05:24:31",
            "last_seen_utc": "2026-08-31 07:22:12",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "ar3k0,Vidar",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1823854": [
        {
            "ioc_value": "pas.sm188star.top",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-06-06 05:24:31",
            "last_seen_utc": "2026-08-31 07:22:13",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "ar3k0,Vidar",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1823730": [
        {
            "ioc_value": "101.43.103.154:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-06-06 03:44:58",
            "last_seen_utc": "2026-08-31 07:48:22",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1822674": [
        {
            "ioc_value": "dev.useimage.sbs",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-06-05 05:14:52",
            "last_seen_utc": "2026-08-31 07:48:16",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "CobaltStrike",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1822600": [
        {
            "ioc_value": "34.202.161.96:53",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-06-04 23:45:28",
            "last_seen_utc": "2026-08-31 07:48:45",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1822599": [
        {
            "ioc_value": "updates.fisgloval.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-06-04 23:45:07",
            "last_seen_utc": "2026-08-31 07:48:20",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1822526": [
        {
            "ioc_value": "163.172.174.237:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.brute_ratel_c4",
            "malware_alias": "BOLDBADGER,BruteRatel",
            "malware_printable": "Brute Ratel C4",
            "first_seen_utc": "2026-06-04 19:43:27",
            "last_seen_utc": "2026-08-31 07:44:13",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "BruteRatel,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1822527": [
        {
            "ioc_value": "163.172.174.237:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.brute_ratel_c4",
            "malware_alias": "BOLDBADGER,BruteRatel",
            "malware_printable": "Brute Ratel C4",
            "first_seen_utc": "2026-06-04 19:43:27",
            "last_seen_utc": "2026-08-31 07:44:13",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "BruteRatel,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1822415": [
        {
            "ioc_value": "120.26.208.96:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-06-04 14:50:35",
            "last_seen_utc": "2026-08-31 07:48:31",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": "",
            "tags": "Agentemis,BEACON,Cobalt Strike,CobaltStrike,cobeacon",
            "anonymous": 0,
            "reporter": "whoamix302"
        }
    ],
    "1822346": [
        {
            "ioc_value": "154.12.86.154:44444",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-06-04 11:46:46",
            "last_seen_utc": "2026-08-31 07:48:35",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1822301": [
        {
            "ioc_value": "82.23.246.160:8848",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.dcrat",
            "malware_alias": "DarkCrystal RAT",
            "malware_printable": "DCRat",
            "first_seen_utc": "2026-06-04 09:45:35",
            "last_seen_utc": "2026-08-31 07:47:48",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DCRat,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1822296": [
        {
            "ioc_value": "156.247.40.190:8848",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.dcrat",
            "malware_alias": "DarkCrystal RAT",
            "malware_printable": "DCRat",
            "first_seen_utc": "2026-06-04 09:43:29",
            "last_seen_utc": "2026-08-31 07:44:03",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DCRat,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1821798": [
        {
            "ioc_value": "13.236.153.60:8888",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-06-03 15:24:07",
            "last_seen_utc": "2026-08-31 07:43:39",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "asyncrat",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1821844": [
        {
            "ioc_value": "47.82.234.12:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-06-03 15:23:52",
            "last_seen_utc": "2026-08-31 07:48:53",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "cobaltstrike",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1821716": [
        {
            "ioc_value": "82.23.246.160:12159",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.dcrat",
            "malware_alias": "DarkCrystal RAT",
            "malware_printable": "DCRat",
            "first_seen_utc": "2026-06-03 09:45:37",
            "last_seen_utc": "2026-08-31 07:47:48",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DCRat,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1821713": [
        {
            "ioc_value": "156.247.40.190:12159",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.dcrat",
            "malware_alias": "DarkCrystal RAT",
            "malware_printable": "DCRat",
            "first_seen_utc": "2026-06-03 09:43:30",
            "last_seen_utc": "2026-08-31 07:44:03",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DCRat,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1821517": [
        {
            "ioc_value": "45.198.224.19:4321",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-06-02 19:45:08",
            "last_seen_utc": "2026-08-29 08:46:30",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1821227": [
        {
            "ioc_value": "198.13.51.245:4321",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-06-02 14:05:08",
            "last_seen_utc": "2026-08-31 07:45:29",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": "https://www.shodan.io/host/198.13.51.245#4321",
            "tags": "adaptixc2,c2,shodan",
            "anonymous": 0,
            "reporter": "juroots"
        }
    ],
    "1821221": [
        {
            "ioc_value": "34.61.52.162:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-06-02 14:04:12",
            "last_seen_utc": "2026-08-31 07:46:52",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": "https://www.shodan.io/host/34.61.52.162#443",
            "tags": "c2,mythic,shodan",
            "anonymous": 0,
            "reporter": "juroots"
        }
    ],
    "1820723": [
        {
            "ioc_value": "178.16.54.48:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.eye_pyramid",
            "malware_alias": null,
            "malware_printable": "Eye Pyramid",
            "first_seen_utc": "2026-06-01 19:43:43",
            "last_seen_utc": "2026-08-31 07:44:35",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,EyePyramid",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1820722": [
        {
            "ioc_value": "178.16.52.47:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.eye_pyramid",
            "malware_alias": null,
            "malware_printable": "Eye Pyramid",
            "first_seen_utc": "2026-06-01 19:43:42",
            "last_seen_utc": "2026-08-31 07:44:34",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,EyePyramid",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1820506": [
        {
            "ioc_value": "165.22.225.218:5443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-06-01 06:44:52",
            "last_seen_utc": "2026-08-31 07:48:38",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-987654321",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1820398": [
        {
            "ioc_value": "154.38.114.115:53",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-05-31 21:46:19",
            "last_seen_utc": "2026-08-29 18:47:22",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1820327": [
        {
            "ioc_value": "64.89.160.44:7777",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.dcrat",
            "malware_alias": "DarkCrystal RAT",
            "malware_printable": "DCRat",
            "first_seen_utc": "2026-05-31 15:04:22",
            "last_seen_utc": "2026-08-31 07:47:36",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "dcrat",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1820291": [
        {
            "ioc_value": "64.176.73.125:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pupy",
            "malware_alias": "Patpoopy",
            "malware_printable": "pupy",
            "first_seen_utc": "2026-05-31 09:45:39",
            "last_seen_utc": "2026-08-31 07:47:34",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PupyRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1820290": [
        {
            "ioc_value": "31.57.184.154:2503",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-05-31 09:44:59",
            "last_seen_utc": "2026-08-31 07:46:46",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1820214": [
        {
            "ioc_value": "64.89.160.44:1000",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-05-31 06:48:28",
            "last_seen_utc": "2026-08-31 07:47:36",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": null,
            "tags": "205759,asyncrat,c2,censys",
            "anonymous": 0,
            "reporter": "sojubear"
        }
    ],
    "1820043": [
        {
            "ioc_value": "38.54.63.135:4321",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-05-30 09:45:23",
            "last_seen_utc": "2026-08-31 07:46:59",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1820039": [
        {
            "ioc_value": "114.132.190.121:4321",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-05-30 09:43:14",
            "last_seen_utc": "2026-08-31 07:43:31",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1819982": [
        {
            "ioc_value": "40.85.252.198:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.havoc",
            "malware_alias": "Havokiz",
            "malware_printable": "Havoc",
            "first_seen_utc": "2026-05-30 07:04:38",
            "last_seen_utc": "2026-08-29 08:46:20",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "havoc",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1819906": [
        {
            "ioc_value": "43.140.219.30:7112",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.chaos",
            "malware_alias": "FakeRyuk,RyukJoke,Yashma",
            "malware_printable": "Chaos",
            "first_seen_utc": "2026-05-29 19:45:33",
            "last_seen_utc": "2026-08-31 07:47:04",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CHAOS,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1819901": [
        {
            "ioc_value": "192.162.199.25:4321",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-05-29 19:44:12",
            "last_seen_utc": "2026-08-31 07:45:06",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1819895": [
        {
            "ioc_value": "162.248.224.236:7492",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.ransomhub",
            "malware_alias": null,
            "malware_printable": "RansomHub",
            "first_seen_utc": "2026-05-29 19:43:42",
            "last_seen_utc": "2026-08-31 07:44:12",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RansomHub",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1819896": [
        {
            "ioc_value": "162.248.225.165:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.ransomhub",
            "malware_alias": null,
            "malware_printable": "RansomHub",
            "first_seen_utc": "2026-05-29 19:43:42",
            "last_seen_utc": "2026-08-31 07:44:12",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RansomHub",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1819897": [
        {
            "ioc_value": "162.248.225.165:8603",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.ransomhub",
            "malware_alias": null,
            "malware_printable": "RansomHub",
            "first_seen_utc": "2026-05-29 19:43:42",
            "last_seen_utc": "2026-08-31 07:44:12",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RansomHub",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1819894": [
        {
            "ioc_value": "162.248.224.236:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.ransomhub",
            "malware_alias": null,
            "malware_printable": "RansomHub",
            "first_seen_utc": "2026-05-29 19:43:41",
            "last_seen_utc": "2026-08-31 07:44:12",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RansomHub",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1819842": [
        {
            "ioc_value": "mub.depansm188.top",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-05-29 15:30:50",
            "last_seen_utc": "2026-08-31 00:21:46",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "vidar",
            "anonymous": 0,
            "reporter": "crep1x"
        }
    ],
    "1819843": [
        {
            "ioc_value": "https://mub.depansm188.top/",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-05-29 15:30:50",
            "last_seen_utc": "2026-08-31 00:21:46",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "vidar",
            "anonymous": 0,
            "reporter": "crep1x"
        }
    ],
    "1819786": [
        {
            "ioc_value": "118.89.79.131:6528",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-05-29 11:46:33",
            "last_seen_utc": "2026-08-31 07:48:30",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1819753": [
        {
            "ioc_value": "168.144.36.228:9000",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pupy",
            "malware_alias": "Patpoopy",
            "malware_printable": "pupy",
            "first_seen_utc": "2026-05-29 09:43:47",
            "last_seen_utc": "2026-08-30 18:43:58",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PupyRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1819593": [
        {
            "ioc_value": "31.57.184.154:7005",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-05-28 19:44:44",
            "last_seen_utc": "2026-08-31 07:46:47",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1819406": [
        {
            "ioc_value": "91.215.85.212:45423",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-05-28 09:46:09",
            "last_seen_utc": "2026-08-31 07:47:58",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1819405": [
        {
            "ioc_value": "85.209.90.132:4321",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-05-28 09:46:05",
            "last_seen_utc": "2026-08-31 07:47:51",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1819402": [
        {
            "ioc_value": "43.133.165.151:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-05-28 09:45:23",
            "last_seen_utc": "2026-08-31 07:47:03",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1819396": [
        {
            "ioc_value": "202.95.8.97:4321",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-05-28 09:44:19",
            "last_seen_utc": "2026-08-31 07:45:40",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1819397": [
        {
            "ioc_value": "202.95.8.98:4321",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-05-28 09:44:19",
            "last_seen_utc": "2026-08-31 07:45:40",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1819394": [
        {
            "ioc_value": "193.5.65.169:4348",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.ransomhub",
            "malware_alias": null,
            "malware_printable": "RansomHub",
            "first_seen_utc": "2026-05-28 09:44:10",
            "last_seen_utc": "2026-08-31 07:45:16",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RansomHub",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1819395": [
        {
            "ioc_value": "193.5.65.169:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.ransomhub",
            "malware_alias": null,
            "malware_printable": "RansomHub",
            "first_seen_utc": "2026-05-28 09:44:10",
            "last_seen_utc": "2026-08-31 07:45:16",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RansomHub",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1819387": [
        {
            "ioc_value": "113.31.106.85:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-05-28 09:43:13",
            "last_seen_utc": "2026-08-31 07:43:30",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1819225": [
        {
            "ioc_value": "91.200.84.198:8515",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-05-27 19:45:55",
            "last_seen_utc": "2026-08-31 07:47:57",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1819222": [
        {
            "ioc_value": "43.106.14.139:8085",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.havoc",
            "malware_alias": "Havokiz",
            "malware_printable": "Havoc",
            "first_seen_utc": "2026-05-27 19:45:12",
            "last_seen_utc": "2026-08-31 07:47:00",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Havoc",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1819220": [
        {
            "ioc_value": "18.162.155.202:3350",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.deimos_c2",
            "malware_alias": null,
            "malware_printable": "DeimosC2",
            "first_seen_utc": "2026-05-27 19:43:47",
            "last_seen_utc": "2026-08-31 07:44:37",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "Deimos,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1819146": [
        {
            "ioc_value": "8.134.70.73:9999",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-05-27 15:46:43",
            "last_seen_utc": "2026-08-31 07:48:55",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1818956": [
        {
            "ioc_value": "8.163.49.50:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-05-27 07:09:22",
            "last_seen_utc": "2026-08-31 07:48:57",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": null,
            "tags": "c2,censys,cobalt strike",
            "anonymous": 0,
            "reporter": "sojubear"
        }
    ],
    "1818872": [
        {
            "ioc_value": "155.102.136.60:4506",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.deimos_c2",
            "malware_alias": null,
            "malware_printable": "DeimosC2",
            "first_seen_utc": "2026-05-26 19:43:28",
            "last_seen_utc": "2026-08-31 07:44:00",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "Deimos,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1818696": [
        {
            "ioc_value": "193.24.123.160:45631",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-05-26 09:44:02",
            "last_seen_utc": "2026-08-31 07:45:14",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1818588": [
        {
            "ioc_value": "31.57.184.154:56001",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-05-26 08:35:13",
            "last_seen_utc": "2026-08-31 07:46:47",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "",
            "tags": "PureHVNC,PureRAT,ResolverRAT",
            "anonymous": 0,
            "reporter": "whoamix302"
        }
    ],
    "1818605": [
        {
            "ioc_value": "103.17.38.43:56001",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-05-26 08:35:01",
            "last_seen_utc": "2026-08-31 07:43:08",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "",
            "tags": "PureHVNC,PureRAT,ResolverRAT",
            "anonymous": 0,
            "reporter": "whoamix302"
        }
    ],
    "1818480": [
        {
            "ioc_value": "47.108.25.113:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-05-25 22:46:18",
            "last_seen_utc": "2026-08-31 07:48:51",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1818434": [
        {
            "ioc_value": "37.77.150.174:4333",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.eye_pyramid",
            "malware_alias": null,
            "malware_printable": "Eye Pyramid",
            "first_seen_utc": "2026-05-25 19:44:52",
            "last_seen_utc": "2026-08-31 07:46:55",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,EyePyramid",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1818433": [
        {
            "ioc_value": "37.77.150.174:4332",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.eye_pyramid",
            "malware_alias": null,
            "malware_printable": "Eye Pyramid",
            "first_seen_utc": "2026-05-25 19:44:51",
            "last_seen_utc": "2026-08-31 07:46:55",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,EyePyramid",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1818431": [
        {
            "ioc_value": "202.95.8.92:4321",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-05-25 19:44:05",
            "last_seen_utc": "2026-08-31 07:45:40",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1818346": [
        {
            "ioc_value": "45.153.127.224:8080",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.chaos",
            "malware_alias": "FakeRyuk,RyukJoke,Yashma",
            "malware_printable": "Chaos",
            "first_seen_utc": "2026-05-25 14:00:07",
            "last_seen_utc": "2026-08-31 07:47:09",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": "https://tracker.viriback.com/index.php?q=45.153.127.224",
            "tags": "Chaos,ViriBack",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1818053": [
        {
            "ioc_value": "45.154.12.150:53",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-05-24 14:46:49",
            "last_seen_utc": "2026-08-31 07:48:49",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1817829": [
        {
            "ioc_value": "172.94.18.103:75",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-05-24 11:05:15",
            "last_seen_utc": "2026-08-31 07:44:28",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "asyncrat",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1817758": [
        {
            "ioc_value": "https://cyy.turbo88ml.top/",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-05-23 22:00:09",
            "last_seen_utc": "2026-08-31 07:21:31",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "vidar",
            "anonymous": 0,
            "reporter": "crep1x"
        }
    ],
    "1817757": [
        {
            "ioc_value": "cyy.turbo88ml.top",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-05-23 22:00:08",
            "last_seen_utc": "2026-08-31 07:21:31",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "vidar",
            "anonymous": 0,
            "reporter": "crep1x"
        }
    ],
    "1817704": [
        {
            "ioc_value": "151.236.20.3:8080",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-05-23 19:43:35",
            "last_seen_utc": "2026-08-31 07:43:54",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1817663": [
        {
            "ioc_value": "101.126.10.34:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-05-23 14:56:56",
            "last_seen_utc": "2026-08-31 07:48:21",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-666666666",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1817238": [
        {
            "ioc_value": "54.187.35.128:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-05-22 09:45:08",
            "last_seen_utc": "2026-08-31 07:47:29",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1817159": [
        {
            "ioc_value": "143.14.9.56:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-05-22 08:11:29",
            "last_seen_utc": "2026-08-31 07:43:48",
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "adaptix_v1.2,adaptixc2,c2,panel",
            "anonymous": 0,
            "reporter": "Lenny_3BO"
        }
    ],
    "1817055": [
        {
            "ioc_value": "42.121.150.29:4506",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.deimos_c2",
            "malware_alias": null,
            "malware_printable": "DeimosC2",
            "first_seen_utc": "2026-05-21 19:45:14",
            "last_seen_utc": "2026-08-31 07:47:00",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "Deimos,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1817054": [
        {
            "ioc_value": "34.61.52.162:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-05-21 19:45:07",
            "last_seen_utc": "2026-08-31 07:46:52",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1816737": [
        {
            "ioc_value": "221.207.101.175:4506",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.deimos_c2",
            "malware_alias": null,
            "malware_printable": "DeimosC2",
            "first_seen_utc": "2026-05-20 19:44:32",
            "last_seen_utc": "2026-08-31 07:46:38",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "Deimos,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1816735": [
        {
            "ioc_value": "167.17.47.118:4321",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-05-20 19:43:30",
            "last_seen_utc": "2026-08-31 07:44:15",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1816585": [
        {
            "ioc_value": "51.15.8.6:9998",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.sliver",
            "malware_alias": null,
            "malware_printable": "Sliver",
            "first_seen_utc": "2026-05-20 09:45:05",
            "last_seen_utc": "2026-08-31 07:47:27",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Sliver",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1816581": [
        {
            "ioc_value": "178.212.13.29:4321",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-05-20 09:43:39",
            "last_seen_utc": "2026-08-31 07:44:36",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1816569": [
        {
            "ioc_value": "lambdauyamna.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.netsupportmanager_rat",
            "malware_alias": "NetSupport",
            "malware_printable": "NetSupportManager RAT",
            "first_seen_utc": "2026-05-20 08:08:13",
            "last_seen_utc": "2026-08-30 00:06:12",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://bazaar.abuse.ch/sample/9dc129be20fa669fc730b8364b83ecad913acd1ad1706b9deb670dbe104fde12/",
            "tags": "NetSupport,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1816570": [
        {
            "ioc_value": "mokitomaccito.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.netsupportmanager_rat",
            "malware_alias": "NetSupport",
            "malware_printable": "NetSupportManager RAT",
            "first_seen_utc": "2026-05-20 08:08:13",
            "last_seen_utc": "2026-08-30 00:06:12",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://bazaar.abuse.ch/sample/9dc129be20fa669fc730b8364b83ecad913acd1ad1706b9deb670dbe104fde12/",
            "tags": "NetSupport,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1816568": [
        {
            "ioc_value": "djkmgndkjfgndfg.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.netsupportmanager_rat",
            "malware_alias": "NetSupport",
            "malware_printable": "NetSupportManager RAT",
            "first_seen_utc": "2026-05-20 08:07:08",
            "last_seen_utc": "2026-08-30 00:06:12",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://bazaar.abuse.ch/sample/9dc129be20fa669fc730b8364b83ecad913acd1ad1706b9deb670dbe104fde12/",
            "tags": "NetSupport,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1816481": [
        {
            "ioc_value": "114.134.187.38:8080",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-05-20 05:25:02",
            "last_seen_utc": "2026-08-31 07:48:26",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "cobaltstrike",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1816445": [
        {
            "ioc_value": "43.142.137.169:18443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-05-19 20:46:09",
            "last_seen_utc": "2026-08-31 07:48:48",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1816431": [
        {
            "ioc_value": "91.202.233.214:44123",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-05-19 19:45:18",
            "last_seen_utc": "2026-08-31 07:47:57",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1816427": [
        {
            "ioc_value": "31.57.184.154:2502",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-05-19 19:44:36",
            "last_seen_utc": "2026-08-31 07:46:46",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1816296": [
        {
            "ioc_value": "176.120.22.127:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.poshc2",
            "malware_alias": null,
            "malware_printable": "PoshC2",
            "first_seen_utc": "2026-05-19 09:43:37",
            "last_seen_utc": "2026-08-31 07:44:30",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PoshC2",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1816294": [
        {
            "ioc_value": "142.93.165.129:3334",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.evilginx",
            "malware_alias": null,
            "malware_printable": "Evilginx",
            "first_seen_utc": "2026-05-19 09:43:19",
            "last_seen_utc": "2026-08-31 07:43:47",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Evilginx,EvilGoPhish",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1816167": [
        {
            "ioc_value": "48.202.58.22:2055",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-05-19 05:16:08",
            "last_seen_utc": "2026-08-31 07:47:24",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": null,
            "tags": "8075,asyncrat,c2,censys",
            "anonymous": 0,
            "reporter": "sojubear"
        }
    ],
    "1816106": [
        {
            "ioc_value": "89.125.255.29:4321",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-05-18 19:45:01",
            "last_seen_utc": "2026-08-31 07:47:54",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1816100": [
        {
            "ioc_value": "38.147.189.199:9001",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pupy",
            "malware_alias": "Patpoopy",
            "malware_printable": "pupy",
            "first_seen_utc": "2026-05-18 19:44:31",
            "last_seen_utc": "2026-08-31 07:46:56",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PupyRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1815927": [
        {
            "ioc_value": "163.181.46.56:4506",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.deimos_c2",
            "malware_alias": null,
            "malware_printable": "DeimosC2",
            "first_seen_utc": "2026-05-18 09:43:30",
            "last_seen_utc": "2026-08-31 07:44:13",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "Deimos,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1815397": [
        {
            "ioc_value": "45.155.69.153:43345",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-05-16 19:45:35",
            "last_seen_utc": "2026-08-31 07:47:10",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1815392": [
        {
            "ioc_value": "103.219.153.200:7707",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-05-16 19:43:06",
            "last_seen_utc": "2026-08-31 07:43:09",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1815393": [
        {
            "ioc_value": "103.219.153.200:8808",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-05-16 19:43:06",
            "last_seen_utc": "2026-08-31 07:43:09",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1815391": [
        {
            "ioc_value": "103.219.153.200:6606",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-05-16 19:43:05",
            "last_seen_utc": "2026-08-31 07:43:09",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1815137": [
        {
            "ioc_value": "95.231.168.143:4483",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.netsupportmanager_rat",
            "malware_alias": "NetSupport",
            "malware_printable": "NetSupportManager RAT",
            "first_seen_utc": "2026-05-15 19:44:50",
            "last_seen_utc": "2026-08-31 07:48:12",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,NetSupport,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1815133": [
        {
            "ioc_value": "34.69.130.10:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.chaos",
            "malware_alias": "FakeRyuk,RyukJoke,Yashma",
            "malware_printable": "Chaos",
            "first_seen_utc": "2026-05-15 19:44:19",
            "last_seen_utc": "2026-08-31 07:46:52",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CHAOS,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1815073": [
        {
            "ioc_value": "pgo.fatherchrismas.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-05-15 16:00:12",
            "last_seen_utc": "2026-08-31 07:21:10",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "vidar",
            "anonymous": 0,
            "reporter": "crep1x"
        }
    ],
    "1815074": [
        {
            "ioc_value": "https://pgo.fatherchrismas.com/",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-05-15 16:00:12",
            "last_seen_utc": "2026-08-31 07:21:09",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "vidar",
            "anonymous": 0,
            "reporter": "crep1x"
        }
    ],
    "1812073": [
        {
            "ioc_value": "87.120.107.68:7777",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.dcrat",
            "malware_alias": "DarkCrystal RAT",
            "malware_printable": "DCRat",
            "first_seen_utc": "2026-05-14 12:34:22",
            "last_seen_utc": "2026-08-31 07:47:52",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "dcrat",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1812126": [
        {
            "ioc_value": "84.46.251.62:4321",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-05-14 09:51:34",
            "last_seen_utc": "2026-08-31 07:47:49",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1811187": [
        {
            "ioc_value": "mpd.pegasus-77.biz.id",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-05-11 23:00:12",
            "last_seen_utc": "2026-08-31 07:20:48",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "vidar",
            "anonymous": 0,
            "reporter": "crep1x"
        }
    ],
    "1811188": [
        {
            "ioc_value": "https://mpd.pegasus-77.biz.id/",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-05-11 23:00:12",
            "last_seen_utc": "2026-08-31 07:20:48",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "vidar",
            "anonymous": 0,
            "reporter": "crep1x"
        }
    ],
    "1811186": [
        {
            "ioc_value": "117.50.184.221:10080",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-05-11 22:45:16",
            "last_seen_utc": "2026-08-31 07:48:27",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1811129": [
        {
            "ioc_value": "64.199.252.59:3333",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.evilginx",
            "malware_alias": null,
            "malware_printable": "Evilginx",
            "first_seen_utc": "2026-05-11 19:45:07",
            "last_seen_utc": "2026-08-31 07:47:34",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Evilginx,EvilGoPhish",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1811128": [
        {
            "ioc_value": "51.77.54.76:6769",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-05-11 19:45:01",
            "last_seen_utc": "2026-08-31 07:47:27",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1811126": [
        {
            "ioc_value": "45.77.89.29:4321",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-05-11 19:44:49",
            "last_seen_utc": "2026-08-31 07:47:18",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1811118": [
        {
            "ioc_value": "109.73.193.242:10140",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-05-11 19:43:08",
            "last_seen_utc": "2026-08-31 07:43:28",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1810965": [
        {
            "ioc_value": "89.42.134.220:7707",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-05-11 09:45:15",
            "last_seen_utc": "2026-08-31 07:47:56",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1810959": [
        {
            "ioc_value": "31.57.184.154:7007",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-05-11 09:44:29",
            "last_seen_utc": "2026-08-31 07:46:47",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1810955": [
        {
            "ioc_value": "185.242.245.27:44875",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-05-11 09:43:35",
            "last_seen_utc": "2026-08-31 07:44:49",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1810414": [
        {
            "ioc_value": "31.57.184.154:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-05-10 19:44:31",
            "last_seen_utc": "2026-08-31 07:46:47",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1810410": [
        {
            "ioc_value": "195.123.240.236:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.ransomhub",
            "malware_alias": null,
            "malware_printable": "RansomHub",
            "first_seen_utc": "2026-05-10 19:43:45",
            "last_seen_utc": "2026-08-31 07:45:23",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RansomHub",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1810411": [
        {
            "ioc_value": "195.123.240.236:8274",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.ransomhub",
            "malware_alias": null,
            "malware_printable": "RansomHub",
            "first_seen_utc": "2026-05-10 19:43:45",
            "last_seen_utc": "2026-08-31 07:45:23",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RansomHub",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1810408": [
        {
            "ioc_value": "189.34.188.6:5406",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.netsupportmanager_rat",
            "malware_alias": "NetSupport",
            "malware_printable": "NetSupportManager RAT",
            "first_seen_utc": "2026-05-10 19:43:39",
            "last_seen_utc": "2026-08-31 07:45:01",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,NetSupport,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1810409": [
        {
            "ioc_value": "189.34.188.6:5407",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.netsupportmanager_rat",
            "malware_alias": "NetSupport",
            "malware_printable": "NetSupportManager RAT",
            "first_seen_utc": "2026-05-10 19:43:39",
            "last_seen_utc": "2026-08-31 07:45:01",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,NetSupport,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1810170": [
        {
            "ioc_value": "57.158.27.132:8080",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.sliver",
            "malware_alias": null,
            "malware_printable": "Sliver",
            "first_seen_utc": "2026-05-10 09:44:56",
            "last_seen_utc": "2026-08-31 07:47:32",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Sliver",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1809754": [
        {
            "ioc_value": "213.130.25.141:44333",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.netsupportmanager_rat",
            "malware_alias": "NetSupport",
            "malware_printable": "NetSupportManager RAT",
            "first_seen_utc": "2026-05-09 19:43:46",
            "last_seen_utc": "2026-08-31 07:45:50",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,NetSupport,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1809750": [
        {
            "ioc_value": "168.144.89.48:8443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-05-09 19:43:24",
            "last_seen_utc": "2026-08-31 07:44:17",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1809038": [
        {
            "ioc_value": "193.42.24.165:4848",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-05-08 19:43:36",
            "last_seen_utc": "2026-08-31 07:45:15",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1809033": [
        {
            "ioc_value": "180.97.214.70:4506",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.deimos_c2",
            "malware_alias": null,
            "malware_printable": "DeimosC2",
            "first_seen_utc": "2026-05-08 19:43:28",
            "last_seen_utc": "2026-08-31 07:44:38",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "Deimos,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1808650": [
        {
            "ioc_value": "45.56.91.55:2005",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-05-08 08:43:45",
            "last_seen_utc": "2026-08-31 07:47:15",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "Covenant,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1808637": [
        {
            "ioc_value": "178.104.186.90:4321",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-05-08 08:43:13",
            "last_seen_utc": "2026-08-31 07:44:33",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1808628": [
        {
            "ioc_value": "113.31.118.180:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-05-08 08:43:05",
            "last_seen_utc": "2026-08-31 07:43:31",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1808623": [
        {
            "ioc_value": "104.243.248.63:1802",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-05-08 08:43:04",
            "last_seen_utc": "2026-08-30 18:43:13",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1808286": [
        {
            "ioc_value": "101.33.225.32:8011",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-05-07 20:44:32",
            "last_seen_utc": "2026-08-31 07:48:22",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1807906": [
        {
            "ioc_value": "45.207.192.190:30078",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-05-06 20:45:39",
            "last_seen_utc": "2026-08-31 07:48:49",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1807842": [
        {
            "ioc_value": "154.18.238.18:8848",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.dcrat",
            "malware_alias": "DarkCrystal RAT",
            "malware_printable": "DCRat",
            "first_seen_utc": "2026-05-06 18:43:14",
            "last_seen_utc": "2026-08-31 07:43:56",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DCRat,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1807538": [
        {
            "ioc_value": "31.57.184.154:7707",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-05-06 08:43:54",
            "last_seen_utc": "2026-08-31 07:46:47",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1806228": [
        {
            "ioc_value": "154.219.115.123:61443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-05-04 20:44:43",
            "last_seen_utc": "2026-08-31 07:48:35",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1806227": [
        {
            "ioc_value": "119.29.198.193:8555",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-05-04 20:44:36",
            "last_seen_utc": "2026-08-31 07:48:30",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1805815": [
        {
            "ioc_value": "45.66.248.82:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.ransomhub",
            "malware_alias": null,
            "malware_printable": "RansomHub",
            "first_seen_utc": "2026-05-04 10:43:59",
            "last_seen_utc": "2026-08-31 07:47:17",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RansomHub",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1805816": [
        {
            "ioc_value": "45.66.248.82:53802",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.ransomhub",
            "malware_alias": null,
            "malware_printable": "RansomHub",
            "first_seen_utc": "2026-05-04 10:43:59",
            "last_seen_utc": "2026-08-31 07:47:17",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RansomHub",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1805766": [
        {
            "ioc_value": "82.165.79.60:31337",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.sliver",
            "malware_alias": null,
            "malware_printable": "Sliver",
            "first_seen_utc": "2026-05-04 08:44:13",
            "last_seen_utc": "2026-08-31 07:47:47",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Sliver",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1805765": [
        {
            "ioc_value": "82.165.79.60:1337",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.sliver",
            "malware_alias": null,
            "malware_printable": "Sliver",
            "first_seen_utc": "2026-05-04 08:44:12",
            "last_seen_utc": "2026-08-31 07:47:47",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Sliver",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1805757": [
        {
            "ioc_value": "163.181.45.55:4506",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.deimos_c2",
            "malware_alias": null,
            "malware_printable": "DeimosC2",
            "first_seen_utc": "2026-05-04 08:43:16",
            "last_seen_utc": "2026-08-31 07:44:13",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "Deimos,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1805268": [
        {
            "ioc_value": "151.245.90.45:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-05-03 12:44:29",
            "last_seen_utc": "2026-08-29 18:47:21",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1805267": [
        {
            "ioc_value": "ap.johamp.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-05-03 12:44:08",
            "last_seen_utc": "2026-08-29 18:47:05",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1804968": [
        {
            "ioc_value": "203.160.54.22:8443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-05-02 20:44:31",
            "last_seen_utc": "2026-08-31 07:48:43",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1804965": [
        {
            "ioc_value": "h67as5d5x.m6p3wca1.cc",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-05-02 20:44:06",
            "last_seen_utc": "2026-08-31 07:48:17",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1804928": [
        {
            "ioc_value": "38.147.173.24:8562",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-05-02 18:43:44",
            "last_seen_utc": "2026-08-31 07:46:56",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1804853": [
        {
            "ioc_value": "47.101.172.178:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-05-02 14:44:30",
            "last_seen_utc": "2026-08-29 18:47:34",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1804732": [
        {
            "ioc_value": "8.160.216.91:4506",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.deimos_c2",
            "malware_alias": null,
            "malware_printable": "DeimosC2",
            "first_seen_utc": "2026-05-02 08:43:53",
            "last_seen_utc": "2026-08-31 07:47:43",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "Deimos,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1804719": [
        {
            "ioc_value": "124.95.172.200:4506",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.deimos_c2",
            "malware_alias": null,
            "malware_printable": "DeimosC2",
            "first_seen_utc": "2026-05-02 08:43:06",
            "last_seen_utc": "2026-08-31 07:43:36",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "Deimos,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1803956": [
        {
            "ioc_value": "https://arsimonopa.com/live/",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.latrodectus",
            "malware_alias": "BLACKWIDOW,IceNova,Latrodectus,Lotus",
            "malware_printable": "Latrodectus",
            "first_seen_utc": "2026-05-02 05:24:17",
            "last_seen_utc": "2026-08-31 08:14:41",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "c2,Latrodectus",
            "anonymous": 0,
            "reporter": "Bitsight"
        }
    ],
    "1803960": [
        {
            "ioc_value": "https://lemonimonakio.com/live/",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.latrodectus",
            "malware_alias": "BLACKWIDOW,IceNova,Latrodectus,Lotus",
            "malware_printable": "Latrodectus",
            "first_seen_utc": "2026-05-02 05:24:15",
            "last_seen_utc": "2026-08-31 08:03:59",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "c2,Latrodectus",
            "anonymous": 0,
            "reporter": "Bitsight"
        }
    ],
    "1803894": [
        {
            "ioc_value": "59.152.212.164:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.bianlian",
            "malware_alias": null,
            "malware_printable": "BianLian",
            "first_seen_utc": "2026-05-01 18:43:53",
            "last_seen_utc": "2026-08-31 07:47:32",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "Bianlian,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1803881": [
        {
            "ioc_value": "45.10.164.177:45123",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-05-01 18:43:45",
            "last_seen_utc": "2026-08-31 07:47:06",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1803874": [
        {
            "ioc_value": "31.57.184.154:6606",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-05-01 18:43:41",
            "last_seen_utc": "2026-08-31 07:46:47",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1803866": [
        {
            "ioc_value": "195.88.191.41:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.ransomhub",
            "malware_alias": null,
            "malware_printable": "RansomHub",
            "first_seen_utc": "2026-05-01 18:43:24",
            "last_seen_utc": "2026-08-31 07:45:28",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RansomHub",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1803867": [
        {
            "ioc_value": "195.88.191.41:7666",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.ransomhub",
            "malware_alias": null,
            "malware_printable": "RansomHub",
            "first_seen_utc": "2026-05-01 18:43:24",
            "last_seen_utc": "2026-08-31 07:45:28",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RansomHub",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1803858": [
        {
            "ioc_value": "185.212.128.80:9000",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.evilginx",
            "malware_alias": null,
            "malware_printable": "Evilginx",
            "first_seen_utc": "2026-05-01 18:43:19",
            "last_seen_utc": "2026-08-31 07:44:46",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Evilginx,EvilGoPhish",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1803841": [
        {
            "ioc_value": "103.79.79.105:9001",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pupy",
            "malware_alias": "Patpoopy",
            "malware_printable": "pupy",
            "first_seen_utc": "2026-05-01 18:43:03",
            "last_seen_utc": "2026-08-31 07:43:12",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PupyRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1803670": [
        {
            "ioc_value": "frr.ambil-disini.web.id",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-05-01 14:30:24",
            "last_seen_utc": "2026-08-31 07:20:27",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "vidar",
            "anonymous": 0,
            "reporter": "crep1x"
        }
    ],
    "1803671": [
        {
            "ioc_value": "https://frr.ambil-disini.web.id/",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-05-01 14:30:24",
            "last_seen_utc": "2026-08-31 07:20:27",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "vidar",
            "anonymous": 0,
            "reporter": "crep1x"
        }
    ],
    "1803513": [
        {
            "ioc_value": "64.89.163.114:6606",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-05-01 08:43:48",
            "last_seen_utc": "2026-08-31 07:47:37",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1803500": [
        {
            "ioc_value": "47.103.106.26:2333",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-05-01 08:43:44",
            "last_seen_utc": "2026-08-31 07:47:23",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1803486": [
        {
            "ioc_value": "20.2.83.254:3333",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.evilginx",
            "malware_alias": null,
            "malware_printable": "Evilginx",
            "first_seen_utc": "2026-05-01 08:43:23",
            "last_seen_utc": "2026-08-31 07:45:38",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Evilginx,EvilGoPhish",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1803387": [
        {
            "ioc_value": "203.160.54.22:8080",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-05-01 07:08:49",
            "last_seen_utc": "2026-08-31 07:48:43",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-987654321",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1803279": [
        {
            "ioc_value": "91.202.233.153:43555",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-05-01 02:43:31",
            "last_seen_utc": "2026-08-31 07:47:57",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1803276": [
        {
            "ioc_value": "85.155.186.2:3821",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-05-01 02:43:30",
            "last_seen_utc": "2026-08-31 07:47:50",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1803262": [
        {
            "ioc_value": "79.135.160.20:9999",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-05-01 02:43:28",
            "last_seen_utc": "2026-08-31 07:47:42",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1803246": [
        {
            "ioc_value": "46.101.77.223:3333",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.evilginx",
            "malware_alias": null,
            "malware_printable": "Evilginx",
            "first_seen_utc": "2026-05-01 02:43:25",
            "last_seen_utc": "2026-08-31 07:47:20",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Evilginx,EvilGoPhish",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1803239": [
        {
            "ioc_value": "45.155.69.175:42455",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-05-01 02:43:24",
            "last_seen_utc": "2026-08-31 07:47:10",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1803240": [
        {
            "ioc_value": "45.56.91.55:2003",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-05-01 02:43:24",
            "last_seen_utc": "2026-08-31 07:47:14",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "Covenant,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1803235": [
        {
            "ioc_value": "45.125.67.171:8443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-05-01 02:43:23",
            "last_seen_utc": "2026-08-31 07:47:07",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1803232": [
        {
            "ioc_value": "43.142.77.170:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.chaos",
            "malware_alias": "FakeRyuk,RyukJoke,Yashma",
            "malware_printable": "Chaos",
            "first_seen_utc": "2026-05-01 02:43:22",
            "last_seen_utc": "2026-08-31 07:47:04",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CHAOS,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1803233": [
        {
            "ioc_value": "43.142.77.170:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.chaos",
            "malware_alias": "FakeRyuk,RyukJoke,Yashma",
            "malware_printable": "Chaos",
            "first_seen_utc": "2026-05-01 02:43:22",
            "last_seen_utc": "2026-08-31 07:47:04",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CHAOS,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1803234": [
        {
            "ioc_value": "43.160.225.40:39001",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-05-01 02:43:22",
            "last_seen_utc": "2026-08-31 07:47:04",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1803218": [
        {
            "ioc_value": "222.255.100.119:8080",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.chaos",
            "malware_alias": "FakeRyuk,RyukJoke,Yashma",
            "malware_printable": "Chaos",
            "first_seen_utc": "2026-05-01 02:43:20",
            "last_seen_utc": "2026-08-31 07:46:39",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CHAOS,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1803219": [
        {
            "ioc_value": "23.227.203.6:42235",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-05-01 02:43:20",
            "last_seen_utc": "2026-08-31 07:46:40",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1803222": [
        {
            "ioc_value": "31.57.184.154:8808",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-05-01 02:43:20",
            "last_seen_utc": "2026-08-31 07:46:47",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1803211": [
        {
            "ioc_value": "216.107.208.250:10444",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.bianlian",
            "malware_alias": null,
            "malware_printable": "BianLian",
            "first_seen_utc": "2026-05-01 02:43:19",
            "last_seen_utc": "2026-08-31 07:45:52",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "Bianlian,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1803215": [
        {
            "ioc_value": "219.142.15.101:4353",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.danabot",
            "malware_alias": "DanaTools",
            "malware_printable": "DanaBot",
            "first_seen_utc": "2026-05-01 02:43:19",
            "last_seen_utc": "2026-08-31 07:46:37",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DanBot,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1803216": [
        {
            "ioc_value": "220.231.47.163:4353",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.danabot",
            "malware_alias": "DanaTools",
            "malware_printable": "DanaBot",
            "first_seen_utc": "2026-05-01 02:43:19",
            "last_seen_utc": "2026-08-31 07:46:38",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DanBot,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1803217": [
        {
            "ioc_value": "221.130.42.19:4353",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.danabot",
            "malware_alias": "DanaTools",
            "malware_printable": "DanaBot",
            "first_seen_utc": "2026-05-01 02:43:19",
            "last_seen_utc": "2026-08-31 07:46:38",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DanBot,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1803205": [
        {
            "ioc_value": "208.249.244.20:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.bianlian",
            "malware_alias": null,
            "malware_printable": "BianLian",
            "first_seen_utc": "2026-05-01 02:43:18",
            "last_seen_utc": "2026-08-31 07:45:46",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "Bianlian,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1803206": [
        {
            "ioc_value": "209.151.145.164:8443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.deimos_c2",
            "malware_alias": null,
            "malware_printable": "DeimosC2",
            "first_seen_utc": "2026-05-01 02:43:18",
            "last_seen_utc": "2026-08-31 07:45:46",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "Deimos,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1803202": [
        {
            "ioc_value": "202.95.17.188:4321",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-05-01 02:43:17",
            "last_seen_utc": "2026-08-31 07:45:40",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1803203": [
        {
            "ioc_value": "206.189.40.107:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.havoc",
            "malware_alias": "Havokiz",
            "malware_printable": "Havoc",
            "first_seen_utc": "2026-05-01 02:43:17",
            "last_seen_utc": "2026-08-31 07:45:43",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Havoc",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1803173": [
        {
            "ioc_value": "185.212.128.81:9000",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.evilginx",
            "malware_alias": null,
            "malware_printable": "Evilginx",
            "first_seen_utc": "2026-05-01 02:43:13",
            "last_seen_utc": "2026-08-31 07:44:46",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Evilginx,EvilGoPhish",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1803174": [
        {
            "ioc_value": "185.212.129.23:9000",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.evilginx",
            "malware_alias": null,
            "malware_printable": "Evilginx",
            "first_seen_utc": "2026-05-01 02:43:13",
            "last_seen_utc": "2026-08-31 07:44:47",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Evilginx,EvilGoPhish",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1803178": [
        {
            "ioc_value": "185.213.20.250:4321",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-05-01 02:43:13",
            "last_seen_utc": "2026-08-31 07:44:48",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1803179": [
        {
            "ioc_value": "185.242.245.120:42534",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-05-01 02:43:13",
            "last_seen_utc": "2026-08-31 07:44:49",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1803166": [
        {
            "ioc_value": "180.184.29.135:8080",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-05-01 02:43:12",
            "last_seen_utc": "2026-08-31 07:44:38",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1803167": [
        {
            "ioc_value": "182.255.45.114:4848",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-05-01 02:43:12",
            "last_seen_utc": "2026-08-31 07:44:39",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1803162": [
        {
            "ioc_value": "178.16.52.22:8396",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-05-01 02:43:11",
            "last_seen_utc": "2026-08-31 07:44:33",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1803152": [
        {
            "ioc_value": "172.111.162.252:3030",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-05-01 02:43:09",
            "last_seen_utc": "2026-08-29 08:44:08",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1803153": [
        {
            "ioc_value": "172.9.165.216:8096",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.chaos",
            "malware_alias": "FakeRyuk,RyukJoke,Yashma",
            "malware_printable": "Chaos",
            "first_seen_utc": "2026-05-01 02:43:09",
            "last_seen_utc": "2026-08-31 07:44:27",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CHAOS,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1803141": [
        {
            "ioc_value": "154.219.115.123:60001",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-05-01 02:43:08",
            "last_seen_utc": "2026-08-31 07:43:58",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1803145": [
        {
            "ioc_value": "161.248.179.92:1111",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-05-01 02:43:08",
            "last_seen_utc": "2026-08-31 07:44:10",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1803146": [
        {
            "ioc_value": "161.248.179.92:9999",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-05-01 02:43:08",
            "last_seen_utc": "2026-08-31 07:44:11",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1803147": [
        {
            "ioc_value": "162.14.124.25:4321",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-05-01 02:43:08",
            "last_seen_utc": "2026-08-31 07:44:11",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1803134": [
        {
            "ioc_value": "149.104.28.204:3656",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-05-01 02:43:07",
            "last_seen_utc": "2026-08-31 07:43:52",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1803127": [
        {
            "ioc_value": "142.93.88.220:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.havoc",
            "malware_alias": "Havokiz",
            "malware_printable": "Havoc",
            "first_seen_utc": "2026-05-01 02:43:06",
            "last_seen_utc": "2026-08-31 07:43:48",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Havoc",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1803124": [
        {
            "ioc_value": "138.124.113.131:4211",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-05-01 02:43:05",
            "last_seen_utc": "2026-08-31 07:43:45",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1803114": [
        {
            "ioc_value": "115.42.60.122:5440",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.dcrat",
            "malware_alias": "DarkCrystal RAT",
            "malware_printable": "DCRat",
            "first_seen_utc": "2026-05-01 02:43:04",
            "last_seen_utc": "2026-08-31 07:43:32",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DCRat,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1803115": [
        {
            "ioc_value": "117.72.101.55:9520",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.chaos",
            "malware_alias": "FakeRyuk,RyukJoke,Yashma",
            "malware_printable": "Chaos",
            "first_seen_utc": "2026-05-01 02:43:04",
            "last_seen_utc": "2026-08-31 07:43:32",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CHAOS,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1803109": [
        {
            "ioc_value": "103.75.190.47:54630",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.dcrat",
            "malware_alias": "DarkCrystal RAT",
            "malware_printable": "DCRat",
            "first_seen_utc": "2026-05-01 02:43:03",
            "last_seen_utc": "2026-08-31 07:43:12",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DCRat,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1803110": [
        {
            "ioc_value": "104.234.174.93:57712",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-05-01 02:43:03",
            "last_seen_utc": "2026-08-31 07:43:14",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1803113": [
        {
            "ioc_value": "115.190.247.97:4321",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-05-01 02:43:03",
            "last_seen_utc": "2026-08-31 07:43:31",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1802897": [
        {
            "ioc_value": "82.156.219.31:8443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-04-30 18:43:45",
            "last_seen_utc": "2026-08-31 07:48:58",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1800528": [
        {
            "ioc_value": "http://pillow.riverbridge.site",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-04-26 19:14:08",
            "last_seen_utc": "2026-08-31 07:20:06",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "ipocalur,Vidar",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1800513": [
        {
            "ioc_value": "91.92.242.236:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.amadey",
            "malware_alias": null,
            "malware_printable": "Amadey",
            "first_seen_utc": "2026-04-26 18:36:03",
            "last_seen_utc": "2026-08-31 07:58:48",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": "https://tracker.viriback.com/index.php?q=91.92.242.236",
            "tags": "Amadey,ViriBack",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1800509": [
        {
            "ioc_value": "pillow.riverbridge.site",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-04-26 18:19:19",
            "last_seen_utc": "2026-08-31 07:20:06",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://bazaar.abuse.ch/sample/2199baf11d50dd10555f8aec122178e03b62570fc0d4614a8e928978dc547154/",
            "tags": "ipocalur,Vidar",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1800411": [
        {
            "ioc_value": "http://91.92.242.236/oPvjr94jfe/index.php",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.amadey",
            "malware_alias": null,
            "malware_printable": "Amadey",
            "first_seen_utc": "2026-04-26 18:11:00",
            "last_seen_utc": "2026-08-31 08:14:21",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "54e64e,amadey,c2",
            "anonymous": 0,
            "reporter": "Bitsight"
        }
    ],
    "1797248": [
        {
            "ioc_value": "psy.flise-mesteren.dk",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-04-24 15:18:06",
            "last_seen_utc": "2026-08-31 07:19:40",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "r88vry,Vidar",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1797247": [
        {
            "ioc_value": "https://psy.flise-mesteren.dk/",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-04-24 15:18:01",
            "last_seen_utc": "2026-08-31 07:19:40",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "r88vry,Vidar",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1796426": [
        {
            "ioc_value": "http://196.251.107.248/kont2rt/index.php",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.amadey",
            "malware_alias": null,
            "malware_printable": "Amadey",
            "first_seen_utc": "2026-04-23 04:45:34",
            "last_seen_utc": "2026-08-31 08:12:13",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "Amadey",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1796097": [
        {
            "ioc_value": "47.94.162.43:2222",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-04-22 14:30:19",
            "last_seen_utc": "2026-08-29 18:47:37",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "Agentemis,BEACON,Cobalt Strike,CobaltStrike,cobeacon",
            "anonymous": 0,
            "reporter": "whoamix302"
        }
    ],
    "1796068": [
        {
            "ioc_value": "wrath.bottlevacuum.shop",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-04-22 11:17:13",
            "last_seen_utc": "2026-08-31 07:19:50",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "opiusra,Vidar",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1796067": [
        {
            "ioc_value": "http://wrath.bottlevacuum.shop",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-04-22 11:17:09",
            "last_seen_utc": "2026-08-31 07:19:50",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "opiusra,Vidar",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1794638": [
        {
            "ioc_value": "http://213.5.130.87",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-04-19 18:25:29",
            "last_seen_utc": "2026-08-31 06:01:32",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "c2,REMPROXY",
            "anonymous": 0,
            "reporter": "BlackLotusLabs"
        }
    ],
    "1794023": [
        {
            "ioc_value": "ostlomtophamchese.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.netsupportmanager_rat",
            "malware_alias": "NetSupport",
            "malware_printable": "NetSupportManager RAT",
            "first_seen_utc": "2026-04-18 11:31:56",
            "last_seen_utc": "2026-08-30 00:06:13",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://x.com/JAMESWT_WT/status/2045449296871321937",
            "tags": "NetSupport,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1794024": [
        {
            "ioc_value": "lomtophamchese.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.netsupportmanager_rat",
            "malware_alias": "NetSupport",
            "malware_printable": "NetSupportManager RAT",
            "first_seen_utc": "2026-04-18 11:31:56",
            "last_seen_utc": "2026-08-30 00:06:12",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://x.com/JAMESWT_WT/status/2045449296871321937",
            "tags": "NetSupport,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1794019": [
        {
            "ioc_value": "kislosflfkcjdj.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.netsupportmanager_rat",
            "malware_alias": "NetSupport",
            "malware_printable": "NetSupportManager RAT",
            "first_seen_utc": "2026-04-18 11:30:53",
            "last_seen_utc": "2026-08-30 00:06:12",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://x.com/JAMESWT_WT/status/2045449296871321937",
            "tags": "NetSupport,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1793645": [
        {
            "ioc_value": "http://213.5.130.147",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-04-17 18:15:06",
            "last_seen_utc": "2026-08-31 06:01:34",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "c2,REMPROXY",
            "anonymous": 0,
            "reporter": "BlackLotusLabs"
        }
    ],
    "1793617": [
        {
            "ioc_value": "ask.shurimaster.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-04-17 17:13:27",
            "last_seen_utc": "2026-08-31 06:18:59",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "a10fsw,Vidar",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1793616": [
        {
            "ioc_value": "https://ask.shurimaster.com/",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-04-17 17:13:25",
            "last_seen_utc": "2026-08-31 06:18:58",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "a10fsw,Vidar",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1792850": [
        {
            "ioc_value": "pir.rapidphonebuyer.co.uk",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-04-16 16:13:58",
            "last_seen_utc": "2026-08-31 07:16:41",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "d0b0p,Vidar",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1792849": [
        {
            "ioc_value": "https://pir.rapidphonebuyer.co.uk/",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-04-16 16:13:56",
            "last_seen_utc": "2026-08-31 07:16:41",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "d0b0p,Vidar",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1792719": [
        {
            "ioc_value": "gusto.brothbridge.space",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-04-16 11:16:20",
            "last_seen_utc": "2026-08-31 07:19:19",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "odiznrio,Vidar",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1792718": [
        {
            "ioc_value": "http://gusto.brothbridge.space",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-04-16 11:16:17",
            "last_seen_utc": "2026-08-31 07:19:19",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "odiznrio,Vidar",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1792707": [
        {
            "ioc_value": "43.167.177.224:7778",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-04-16 10:56:58",
            "last_seen_utc": "2026-08-31 07:48:49",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1792532": [
        {
            "ioc_value": "bxx2rghe05kng.cfc-execute.bj.baidubce.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-04-16 02:43:39",
            "last_seen_utc": "2026-08-31 07:48:14",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1791747": [
        {
            "ioc_value": "http://107.189.24.190:80",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-04-15 11:43:19",
            "last_seen_utc": "2026-08-31 08:13:56",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "gr00n1,Vidar",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1791738": [
        {
            "ioc_value": "139.224.23.63:8866",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-04-15 11:39:45",
            "last_seen_utc": "2026-08-31 07:48:33",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "Agentemis,BEACON,Cobalt Strike,CobaltStrike,cobeacon",
            "anonymous": 0,
            "reporter": "whoamix302"
        }
    ],
    "1791688": [
        {
            "ioc_value": "venom.summertunnel.shop",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-04-15 08:15:17",
            "last_seen_utc": "2026-08-31 07:19:08",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "ozpifus,Vidar",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1791687": [
        {
            "ioc_value": "http://venom.summertunnel.shop",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-04-15 08:15:13",
            "last_seen_utc": "2026-08-31 07:19:08",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "ozpifus,Vidar",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1790171": [
        {
            "ioc_value": "dzodu.sparklingideas.space",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-04-14 14:11:23",
            "last_seen_utc": "2026-08-31 07:18:27",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "odzdkzo,Vidar",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1790170": [
        {
            "ioc_value": "http://dzodu.sparklingideas.space",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-04-14 14:11:18",
            "last_seen_utc": "2026-08-31 07:18:27",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "odzdkzo,Vidar",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1790169": [
        {
            "ioc_value": "http://kdije.weirdthings.site",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-04-14 14:10:11",
            "last_seen_utc": "2026-08-31 07:15:38",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "okfueh,Vidar",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1785064": [
        {
            "ioc_value": "pre.hifive.net.au",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-04-13 07:47:21",
            "last_seen_utc": "2026-08-31 07:18:06",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "Vidar",
            "anonymous": 0,
            "reporter": "crep1x"
        }
    ],
    "1785049": [
        {
            "ioc_value": "https://pre.hifive.net.au/",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-04-13 07:46:34",
            "last_seen_utc": "2026-08-31 07:18:06",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "Vidar",
            "anonymous": 0,
            "reporter": "crep1x"
        }
    ],
    "1784558": [
        {
            "ioc_value": "47.104.248.7:8884",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-04-12 06:34:43",
            "last_seen_utc": "2026-08-31 07:48:50",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "Agentemis,BEACON,C2,Cobalt Strike,CobaltStrike,cobeacon",
            "anonymous": 0,
            "reporter": "whoamix302"
        }
    ],
    "1783375": [
        {
            "ioc_value": "39.102.125.11:4435",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-04-09 14:48:47",
            "last_seen_utc": "2026-08-31 07:48:47",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1783061": [
        {
            "ioc_value": "fucismarjiaff.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.netsupportmanager_rat",
            "malware_alias": "NetSupport",
            "malware_printable": "NetSupportManager RAT",
            "first_seen_utc": "2026-04-09 05:17:46",
            "last_seen_utc": "2026-08-30 00:06:12",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "ClickFix,FakeCaptcha,NetSupport,PowerShell,RAT",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1782524": [
        {
            "ioc_value": "82.165.179.9:6606",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-04-07 23:06:40",
            "last_seen_utc": "2026-08-31 07:47:47",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://bazaar.abuse.ch/sample/4c3b97c157d08ee298edb5d30fa86a3b90b04fedfbe517e7e0307b6013eacbf0/",
            "tags": "asyncrat",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1782522": [
        {
            "ioc_value": "82.165.179.9:8808",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-04-07 23:00:12",
            "last_seen_utc": "2026-08-31 07:47:47",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1782182": [
        {
            "ioc_value": "dzdi.serendipityhub.space",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-04-07 07:46:05",
            "last_seen_utc": "2026-08-31 07:17:55",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "Vidar",
            "anonymous": 0,
            "reporter": "crep1x"
        }
    ],
    "1782152": [
        {
            "ioc_value": "http://dzdi.serendipityhub.space/",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-04-07 07:43:55",
            "last_seen_utc": "2026-08-31 07:17:55",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "Vidar",
            "anonymous": 0,
            "reporter": "crep1x"
        }
    ],
    "1782124": [
        {
            "ioc_value": "1.15.76.39:8443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-04-07 07:17:26",
            "last_seen_utc": "2026-08-31 07:48:21",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-987654321",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1781907": [
        {
            "ioc_value": "43.139.108.161:8192",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-04-06 18:49:49",
            "last_seen_utc": "2026-08-31 07:48:48",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "Agentemis,BEACON,C2,Cobalt Strike,CobaltStrike,cobeacon",
            "anonymous": 0,
            "reporter": "whoamix302"
        }
    ],
    "1781717": [
        {
            "ioc_value": "omarinjakuzzii.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.netsupportmanager_rat",
            "malware_alias": "NetSupport",
            "malware_printable": "NetSupportManager RAT",
            "first_seen_utc": "2026-04-06 12:08:36",
            "last_seen_utc": "2026-08-30 00:06:13",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "NetSupport,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1781702": [
        {
            "ioc_value": "176.65.144.30:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.netsupportmanager_rat",
            "malware_alias": "NetSupport",
            "malware_printable": "NetSupportManager RAT",
            "first_seen_utc": "2026-04-06 11:55:15",
            "last_seen_utc": "2026-08-30 00:06:13",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "NetSupport",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1781225": [
        {
            "ioc_value": "111.230.217.36:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-04-04 20:44:05",
            "last_seen_utc": "2026-08-31 07:48:25",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1781224": [
        {
            "ioc_value": "109.244.130.113:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-04-04 20:44:01",
            "last_seen_utc": "2026-08-31 07:48:24",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1780720": [
        {
            "ioc_value": "hor.kaitorinihon.jp",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-04-03 16:13:22",
            "last_seen_utc": "2026-08-31 07:17:03",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "Vidar",
            "anonymous": 0,
            "reporter": "crep1x"
        }
    ],
    "1780716": [
        {
            "ioc_value": "https://hor.kaitorinihon.jp/",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-04-03 16:12:59",
            "last_seen_utc": "2026-08-31 07:17:03",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "Vidar",
            "anonymous": 0,
            "reporter": "crep1x"
        }
    ],
    "1777607": [
        {
            "ioc_value": "pn2.skfilmsint.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-03-27 21:24:29",
            "last_seen_utc": "2026-08-31 07:15:49",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "Vidar",
            "anonymous": 0,
            "reporter": "crep1x"
        }
    ],
    "1777609": [
        {
            "ioc_value": "gre.syslicense.net",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-03-27 21:24:29",
            "last_seen_utc": "2026-08-31 08:15:15",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "Vidar",
            "anonymous": 0,
            "reporter": "crep1x"
        }
    ],
    "1777611": [
        {
            "ioc_value": "fefeo.iknowthat.space",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-03-27 21:24:29",
            "last_seen_utc": "2026-08-31 07:16:10",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "Vidar",
            "anonymous": 0,
            "reporter": "crep1x"
        }
    ],
    "1777601": [
        {
            "ioc_value": "https://pn2.skfilmsint.com/",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-03-27 21:24:17",
            "last_seen_utc": "2026-08-31 07:15:49",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "Vidar",
            "anonymous": 0,
            "reporter": "crep1x"
        }
    ],
    "1777603": [
        {
            "ioc_value": "https://gre.syslicense.net/",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-03-27 21:24:17",
            "last_seen_utc": "2026-08-31 08:15:15",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "Vidar",
            "anonymous": 0,
            "reporter": "crep1x"
        }
    ],
    "1777605": [
        {
            "ioc_value": "http://fefeo.iknowthat.space/",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-03-27 21:24:17",
            "last_seen_utc": "2026-08-31 07:16:10",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "Vidar",
            "anonymous": 0,
            "reporter": "crep1x"
        }
    ],
    "1774903": [
        {
            "ioc_value": "37.72.172.58:7707",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-03-24 12:01:13",
            "last_seen_utc": "2026-08-31 07:46:55",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/37.72.172.58",
            "tags": "AS29802,AsyncRAT,C2,censys,HVC-AS,RAT",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1774898": [
        {
            "ioc_value": "47.92.208.27:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-03-24 12:00:35",
            "last_seen_utc": "2026-08-31 07:48:53",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/47.92.208.27",
            "tags": "ALIBABA-CN-NET,AS37963,C2,censys,CobaltStrike,cs-watermark-666666666",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1774595": [
        {
            "ioc_value": "154.83.12.132:53",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-03-23 21:06:09",
            "last_seen_utc": "2026-08-31 07:48:36",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1774355": [
        {
            "ioc_value": "kdije.weirdthings.site",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-03-23 13:42:00",
            "last_seen_utc": "2026-08-31 07:15:39",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "Vidar",
            "anonymous": 0,
            "reporter": "crep1x"
        }
    ],
    "1774216": [
        {
            "ioc_value": "msi.swadeshcomputer.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-03-23 08:02:27",
            "last_seen_utc": "2026-08-31 08:14:38",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "Vidar",
            "anonymous": 0,
            "reporter": "crep1x"
        }
    ],
    "1774200": [
        {
            "ioc_value": "https://msi.swadeshcomputer.com/",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-03-23 08:01:55",
            "last_seen_utc": "2026-08-31 08:14:38",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "Vidar",
            "anonymous": 0,
            "reporter": "crep1x"
        }
    ],
    "1774088": [
        {
            "ioc_value": "23.227.199.67:42215",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-03-23 04:01:28",
            "last_seen_utc": "2026-08-31 07:46:40",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/23.227.199.67",
            "tags": "AdaptixC2,AS29802,C2,censys,HVC-AS",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1773536": [
        {
            "ioc_value": "156.239.252.191:448",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-03-22 18:02:20",
            "last_seen_utc": "2026-08-31 07:48:37",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "BEACON,C2,CobaltStrike,Shodan",
            "anonymous": 0,
            "reporter": "whoamix302"
        }
    ],
    "1773754": [
        {
            "ioc_value": "138.226.236.52:13212",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-03-22 12:01:29",
            "last_seen_utc": "2026-08-31 07:43:46",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/138.226.236.52",
            "tags": "AdaptixC2,AS205775,C2,censys,NEONCORENETWORKS",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1772372": [
        {
            "ioc_value": "pr2.codetohaven.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-03-20 13:59:59",
            "last_seen_utc": "2026-08-31 08:14:27",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "Vidar",
            "anonymous": 0,
            "reporter": "crep1x"
        }
    ],
    "1772370": [
        {
            "ioc_value": "https://pr2.codetohaven.com/",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-03-20 13:59:49",
            "last_seen_utc": "2026-08-31 08:14:27",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "Vidar",
            "anonymous": 0,
            "reporter": "crep1x"
        }
    ],
    "1771846": [
        {
            "ioc_value": "51.222.87.16:433",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-03-20 04:19:09",
            "last_seen_utc": "2026-08-31 07:48:54",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1771843": [
        {
            "ioc_value": "cdn.sys-update.online",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-03-20 04:08:17",
            "last_seen_utc": "2026-08-31 07:48:15",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1771791": [
        {
            "ioc_value": "8.136.13.87:7001",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-03-20 00:02:12",
            "last_seen_utc": "2026-08-31 07:47:42",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/8.136.13.87",
            "tags": "AdaptixC2,ALIBABA-CN-NET,AS37963,C2,censys",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1771713": [
        {
            "ioc_value": "167.17.47.121:4321",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-03-19 20:02:47",
            "last_seen_utc": "2026-08-31 07:44:15",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/167.17.47.121",
            "tags": "AdaptixC2,AS43180,C2,censys,TRUNKNETWORKS-AS",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1771456": [
        {
            "ioc_value": "dhzuadd.hellothere.sbs",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-03-19 13:11:25",
            "last_seen_utc": "2026-08-31 08:15:04",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drkfiz,Vidar",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1771455": [
        {
            "ioc_value": "https://dhzuadd.hellothere.sbs",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-03-19 13:11:20",
            "last_seen_utc": "2026-08-31 08:15:04",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drkfiz,Vidar",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1768644": [
        {
            "ioc_value": "35.179.229.71:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.havoc",
            "malware_alias": "Havokiz",
            "malware_printable": "Havoc",
            "first_seen_utc": "2026-03-16 20:01:10",
            "last_seen_utc": "2026-08-31 07:46:53",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/35.179.229.71",
            "tags": "AMAZON-02,AS16509,C2,censys,Havoc",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1768638": [
        {
            "ioc_value": "64.227.105.70:8080",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-03-16 20:01:02",
            "last_seen_utc": "2026-08-31 07:47:35",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/64.227.105.70",
            "tags": "AS14061,C2,censys,DIGITALOCEAN-ASN,Mythic",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1767990": [
        {
            "ioc_value": "43.155.169.245:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-03-16 12:00:11",
            "last_seen_utc": "2026-08-31 07:48:49",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/43.155.169.245",
            "tags": "AS132203,C2,censys,CobaltStrike,cs-watermark-987654321,TENCENT-NET-AP-CN",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1767077": [
        {
            "ioc_value": "185.242.3.83:5505",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-03-15 16:00:41",
            "last_seen_utc": "2026-08-31 07:44:49",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/185.242.3.83",
            "tags": "AS60223,AsyncRAT,C2,censys,NETIFACE-AS,RAT",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1766764": [
        {
            "ioc_value": "202.191.67.71:50003",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-03-15 04:01:14",
            "last_seen_utc": "2026-08-31 07:45:40",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/202.191.67.71",
            "tags": "AdaptixC2,AS131262,C2,censys,KELNET-AS-AP",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1765444": [
        {
            "ioc_value": "pan.paihost.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-03-13 15:06:16",
            "last_seen_utc": "2026-08-31 08:13:45",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "Vidar",
            "anonymous": 0,
            "reporter": "crep1x"
        }
    ],
    "1765442": [
        {
            "ioc_value": "https://pan.paihost.com/",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-03-13 15:05:58",
            "last_seen_utc": "2026-08-31 08:13:45",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "Vidar",
            "anonymous": 0,
            "reporter": "crep1x"
        }
    ],
    "1764276": [
        {
            "ioc_value": "46.151.182.205:6606",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-03-13 04:01:11",
            "last_seen_utc": "2026-08-31 07:47:21",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/46.151.182.205",
            "tags": "AS205759,AsyncRAT,C2,censys,GHOSTYNETWORKS,RAT",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1763737": [
        {
            "ioc_value": "130.12.182.209:9456",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.quasar_rat",
            "malware_alias": "CinaRAT,QuasarRAT,Yggdrasil",
            "malware_printable": "Quasar RAT",
            "first_seen_utc": "2026-03-11 23:00:21",
            "last_seen_utc": "2026-08-31 07:43:40",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://tria.ge/260311-zw3w6adw5k",
            "tags": "quasar",
            "anonymous": 0,
            "reporter": "dyingbreeds_"
        }
    ],
    "1763170": [
        {
            "ioc_value": "60.247.206.23:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-03-11 07:03:38",
            "last_seen_utc": "2026-08-31 07:48:54",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-391144938",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1763116": [
        {
            "ioc_value": "118.25.10.65:65010",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-03-11 04:00:36",
            "last_seen_utc": "2026-08-31 07:48:29",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/118.25.10.65",
            "tags": "AS45090,C2,censys,CobaltStrike,cs-watermark-666666666,TENCENT-NET-AP",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1762899": [
        {
            "ioc_value": "https://nonobody123.com",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.stealc",
            "malware_alias": null,
            "malware_printable": "Stealc",
            "first_seen_utc": "2026-03-10 18:04:42",
            "last_seen_utc": "2026-08-31 07:58:40",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://tria.ge/260310-t5ja8aew7y",
            "tags": "C2,stealc,stealer,triage",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1762492": [
        {
            "ioc_value": "107.172.3.15:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-03-10 00:01:13",
            "last_seen_utc": "2026-08-31 07:43:22",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/107.172.3.15",
            "tags": "AS-COLOCROSSING,AS36352,C2,censys,Mythic",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1762153": [
        {
            "ioc_value": "ooe.myserver.com.bd",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-03-09 09:29:37",
            "last_seen_utc": "2026-08-31 08:13:34",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "Vidar",
            "anonymous": 0,
            "reporter": "crep1x"
        }
    ],
    "1762131": [
        {
            "ioc_value": "https://ooe.myserver.com.bd/",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-03-09 09:29:17",
            "last_seen_utc": "2026-08-31 08:13:34",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "Vidar",
            "anonymous": 0,
            "reporter": "crep1x"
        }
    ],
    "1759331": [
        {
            "ioc_value": "194.36.178.53:4321",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-03-06 00:01:40",
            "last_seen_utc": "2026-08-31 07:45:17",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/194.36.178.53",
            "tags": "AdaptixC2,AS200740,C2,censys,FIRST-SERVER-EU-AS",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1758456": [
        {
            "ioc_value": "http://213.5.130.197",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-03-05 06:17:58",
            "last_seen_utc": "2026-08-31 06:01:32",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "c2,REMPROXY",
            "anonymous": 0,
            "reporter": "BlackLotusLabs"
        }
    ],
    "1758457": [
        {
            "ioc_value": "http://213.5.130.154",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-03-05 06:17:57",
            "last_seen_utc": "2026-08-31 06:01:33",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "c2,REMPROXY",
            "anonymous": 0,
            "reporter": "BlackLotusLabs"
        }
    ],
    "1758458": [
        {
            "ioc_value": "http://213.5.130.200",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-03-05 06:17:56",
            "last_seen_utc": "2026-08-31 06:01:32",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "c2,REMPROXY",
            "anonymous": 0,
            "reporter": "BlackLotusLabs"
        }
    ],
    "1758459": [
        {
            "ioc_value": "http://213.5.130.131",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-03-05 06:17:55",
            "last_seen_utc": "2026-08-31 06:01:31",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "c2,REMPROXY",
            "anonymous": 0,
            "reporter": "BlackLotusLabs"
        }
    ],
    "1758460": [
        {
            "ioc_value": "http://213.5.130.179",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-03-05 06:17:54",
            "last_seen_utc": "2026-08-31 06:01:33",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "c2,REMPROXY",
            "anonymous": 0,
            "reporter": "BlackLotusLabs"
        }
    ],
    "1758461": [
        {
            "ioc_value": "http://213.5.130.189",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-03-05 06:17:54",
            "last_seen_utc": "2026-08-31 06:01:34",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "c2,REMPROXY",
            "anonymous": 0,
            "reporter": "BlackLotusLabs"
        }
    ],
    "1758006": [
        {
            "ioc_value": "70.153.18.45:10002",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-03-04 04:01:12",
            "last_seen_utc": "2026-08-31 07:47:40",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/70.153.18.45",
            "tags": "AS8075,censys,EvilGoPhish,MICROSOFT-CORP-MSN-AS-BLOCK,panel,Phishing",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1756955": [
        {
            "ioc_value": "104.243.248.63:1801",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-03-02 15:30:09",
            "last_seen_utc": "2026-08-31 07:43:16",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1754813": [
        {
            "ioc_value": "47.120.20.86:8888",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-02-25 20:02:24",
            "last_seen_utc": "2026-08-31 07:48:51",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/47.120.20.86",
            "tags": "ALIBABA-CN-NET,AS37963,C2,censys,CobaltStrike,cs-watermark-987654321",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1754671": [
        {
            "ioc_value": "115.190.250.28:5521",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-02-25 19:01:08",
            "last_seen_utc": "2026-08-31 07:48:26",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/115.190.250.28",
            "tags": "AS137718,C2,censys",
            "anonymous": 0,
            "reporter": "dyingbreeds_"
        }
    ],
    "1754344": [
        {
            "ioc_value": "23.88.110.42:8443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.poshc2",
            "malware_alias": null,
            "malware_printable": "PoshC2",
            "first_seen_utc": "2026-02-24 23:00:43",
            "last_seen_utc": "2026-08-31 07:46:41",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/23.88.110.42",
            "tags": "AS24940,C2,censys,HETZNER-AS",
            "anonymous": 0,
            "reporter": "dyingbreeds_"
        }
    ],
    "1754178": [
        {
            "ioc_value": "169.40.135.36:8888",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-02-24 12:02:30",
            "last_seen_utc": "2026-08-31 07:44:18",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/169.40.135.36",
            "tags": "AdaptixC2,AS209274,C2,censys,KRAKEN-NETWORK-ISP",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1753847": [
        {
            "ioc_value": "49.232.135.25:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-02-23 23:00:09",
            "last_seen_utc": "2026-08-31 07:47:24",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/49.232.135.25",
            "tags": "AS45090,C2,censys",
            "anonymous": 0,
            "reporter": "dyingbreeds_"
        }
    ],
    "1753846": [
        {
            "ioc_value": "64.89.161.183:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-02-23 23:00:07",
            "last_seen_utc": "2026-08-31 07:48:54",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/64.89.161.183",
            "tags": "AS205759,C2,censys,GHOSTYNETWORKS",
            "anonymous": 0,
            "reporter": "dyingbreeds_"
        }
    ],
    "1751453": [
        {
            "ioc_value": "47.104.159.246:18443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-02-21 03:00:07",
            "last_seen_utc": "2026-08-29 18:47:34",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/47.104.159.246",
            "tags": "AS37963,C2,censys",
            "anonymous": 0,
            "reporter": "dyingbreeds_"
        }
    ],
    "1751104": [
        {
            "ioc_value": "107.172.217.220:12096",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-02-20 11:00:06",
            "last_seen_utc": "2026-08-31 07:48:24",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/107.172.217.220",
            "tags": "AS36352,C2,censys",
            "anonymous": 0,
            "reporter": "dyingbreeds_"
        }
    ],
    "1751083": [
        {
            "ioc_value": "185.180.198.3:2025",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.ransomhub",
            "malware_alias": null,
            "malware_printable": "RansomHub",
            "first_seen_utc": "2026-02-20 08:47:26",
            "last_seen_utc": "2026-08-31 07:44:44",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RansomHub",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1751084": [
        {
            "ioc_value": "185.180.198.3:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.ransomhub",
            "malware_alias": null,
            "malware_printable": "RansomHub",
            "first_seen_utc": "2026-02-20 08:47:26",
            "last_seen_utc": "2026-08-31 07:44:44",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RansomHub",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1751080": [
        {
            "ioc_value": "163.181.208.79:4506",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.deimos_c2",
            "malware_alias": null,
            "malware_printable": "DeimosC2",
            "first_seen_utc": "2026-02-20 08:46:17",
            "last_seen_utc": "2026-08-31 07:44:13",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "Deimos,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1749217": [
        {
            "ioc_value": "111.228.4.54:4455",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-02-16 09:05:30",
            "last_seen_utc": "2026-08-31 07:48:25",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": "https://www.shodan.io/host/111.228.4.54#4455",
            "tags": "c2,cobaltstrike,cs-watermark-987654321,shodan",
            "anonymous": 0,
            "reporter": "juroots"
        }
    ],
    "1748256": [
        {
            "ioc_value": "101.200.193.211:8086",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-02-14 15:11:17",
            "last_seen_utc": "2026-08-31 07:48:21",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-987654321",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1747540": [
        {
            "ioc_value": "gor.emiraride.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-02-13 14:01:35",
            "last_seen_utc": "2026-08-31 08:13:02",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "Vidar",
            "anonymous": 0,
            "reporter": "crep1x"
        }
    ],
    "1747538": [
        {
            "ioc_value": "https://gor.emiraride.com/",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-02-13 14:01:02",
            "last_seen_utc": "2026-08-31 08:13:02",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "Vidar",
            "anonymous": 0,
            "reporter": "crep1x"
        }
    ],
    "1747121": [
        {
            "ioc_value": "117.72.191.140:8028",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-02-13 06:59:13",
            "last_seen_utc": "2026-08-31 07:48:28",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": "https://www.shodan.io/host/117.72.191.140#8028",
            "tags": "c2,cobaltstrike,cs-watermark-391144938,shodan",
            "anonymous": 0,
            "reporter": "juroots"
        }
    ],
    "1746911": [
        {
            "ioc_value": "175.192.75.105:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.netsupportmanager_rat",
            "malware_alias": "NetSupport",
            "malware_printable": "NetSupportManager RAT",
            "first_seen_utc": "2026-02-12 16:01:27",
            "last_seen_utc": "2026-08-31 07:44:29",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/175.192.75.105",
            "tags": "AS4766,C2,censys,KIXS-AS-KR,Netsupport,RAT",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1743594": [
        {
            "ioc_value": "15.204.14.143:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.havoc",
            "malware_alias": "Havokiz",
            "malware_printable": "Havoc",
            "first_seen_utc": "2026-02-09 11:00:33",
            "last_seen_utc": "2026-08-31 07:43:53",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/15.204.14.143",
            "tags": "AS16276,C2,censys,OVH",
            "anonymous": 0,
            "reporter": "dyingbreeds_"
        }
    ],
    "1743395": [
        {
            "ioc_value": "1.15.25.148:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-02-08 15:42:41",
            "last_seen_utc": "2026-08-31 08:00:49",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1743391": [
        {
            "ioc_value": "106.52.208.143:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-02-08 15:42:40",
            "last_seen_utc": "2026-08-31 08:00:48",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1743392": [
        {
            "ioc_value": "106.13.137.229:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-02-08 15:42:40",
            "last_seen_utc": "2026-08-31 08:00:48",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1743393": [
        {
            "ioc_value": "101.43.2.116:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-02-08 15:42:40",
            "last_seen_utc": "2026-08-31 08:00:48",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1743394": [
        {
            "ioc_value": "101.133.148.66:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-02-08 15:42:40",
            "last_seen_utc": "2026-08-31 08:00:49",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1743388": [
        {
            "ioc_value": "115.190.178.249:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-02-08 15:42:39",
            "last_seen_utc": "2026-08-31 08:00:47",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1743389": [
        {
            "ioc_value": "114.132.150.96:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-02-08 15:42:39",
            "last_seen_utc": "2026-08-31 08:00:47",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1743390": [
        {
            "ioc_value": "110.40.176.194:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-02-08 15:42:39",
            "last_seen_utc": "2026-08-31 08:00:47",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1743386": [
        {
            "ioc_value": "120.48.50.33:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-02-08 15:42:37",
            "last_seen_utc": "2026-08-31 08:00:46",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1743387": [
        {
            "ioc_value": "117.72.214.50:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-02-08 15:42:37",
            "last_seen_utc": "2026-08-31 08:00:46",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1743381": [
        {
            "ioc_value": "124.223.199.39:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-02-08 15:42:36",
            "last_seen_utc": "2026-08-31 08:00:45",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1743382": [
        {
            "ioc_value": "124.221.32.87:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-02-08 15:42:36",
            "last_seen_utc": "2026-08-31 08:00:45",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1743383": [
        {
            "ioc_value": "124.220.48.168:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-02-08 15:42:36",
            "last_seen_utc": "2026-08-31 08:00:45",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1743384": [
        {
            "ioc_value": "124.220.164.98:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-02-08 15:42:36",
            "last_seen_utc": "2026-08-31 08:00:46",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1743385": [
        {
            "ioc_value": "121.41.167.80:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-02-08 15:42:36",
            "last_seen_utc": "2026-08-31 08:00:46",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1743378": [
        {
            "ioc_value": "152.136.139.105:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-02-08 15:42:35",
            "last_seen_utc": "2026-08-31 08:00:44",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1743379": [
        {
            "ioc_value": "129.204.103.151:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-02-08 15:42:35",
            "last_seen_utc": "2026-08-31 08:00:45",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1743380": [
        {
            "ioc_value": "124.223.47.219:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-02-08 15:42:35",
            "last_seen_utc": "2026-08-31 08:00:45",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1743374": [
        {
            "ioc_value": "172.245.215.43:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-02-08 15:42:34",
            "last_seen_utc": "2026-08-31 08:00:44",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1743375": [
        {
            "ioc_value": "165.154.125.212:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-02-08 15:42:34",
            "last_seen_utc": "2026-08-31 08:00:44",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1743376": [
        {
            "ioc_value": "156.233.233.134:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-02-08 15:42:34",
            "last_seen_utc": "2026-08-31 08:00:44",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1743377": [
        {
            "ioc_value": "154.201.91.224:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-02-08 15:42:34",
            "last_seen_utc": "2026-08-31 08:00:44",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1743370": [
        {
            "ioc_value": "38.190.224.63:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-02-08 15:42:33",
            "last_seen_utc": "2026-08-31 08:00:43",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1743371": [
        {
            "ioc_value": "222.255.214.236:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-02-08 15:42:33",
            "last_seen_utc": "2026-08-31 08:00:43",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1743372": [
        {
            "ioc_value": "192.252.187.60:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-02-08 15:42:33",
            "last_seen_utc": "2026-08-31 08:00:43",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1743373": [
        {
            "ioc_value": "178.16.52.194:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-02-08 15:42:33",
            "last_seen_utc": "2026-08-31 08:00:43",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1743365": [
        {
            "ioc_value": "43.139.146.100:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-02-08 15:42:32",
            "last_seen_utc": "2026-08-31 08:00:42",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1743366": [
        {
            "ioc_value": "43.133.41.106:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-02-08 15:42:32",
            "last_seen_utc": "2026-08-31 08:00:42",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1743367": [
        {
            "ioc_value": "42.192.49.72:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-02-08 15:42:32",
            "last_seen_utc": "2026-08-31 08:00:42",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1743368": [
        {
            "ioc_value": "39.107.85.83:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-02-08 15:42:32",
            "last_seen_utc": "2026-08-31 08:00:42",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1743369": [
        {
            "ioc_value": "39.106.144.162:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-02-08 15:42:32",
            "last_seen_utc": "2026-08-31 08:00:42",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1743363": [
        {
            "ioc_value": "47.100.168.4:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-02-08 15:42:31",
            "last_seen_utc": "2026-08-31 08:00:41",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1743364": [
        {
            "ioc_value": "43.139.169.60:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-02-08 15:42:31",
            "last_seen_utc": "2026-08-31 08:00:42",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1743362": [
        {
            "ioc_value": "47.111.146.110:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-02-08 15:42:30",
            "last_seen_utc": "2026-08-31 08:00:41",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1743358": [
        {
            "ioc_value": "47.243.175.24:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-02-08 15:42:29",
            "last_seen_utc": "2026-08-31 08:00:40",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1743359": [
        {
            "ioc_value": "47.239.188.48:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-02-08 15:42:29",
            "last_seen_utc": "2026-08-31 08:00:40",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1743360": [
        {
            "ioc_value": "47.122.30.177:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-02-08 15:42:29",
            "last_seen_utc": "2026-08-31 08:00:40",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1743361": [
        {
            "ioc_value": "47.122.1.243:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-02-08 15:42:29",
            "last_seen_utc": "2026-08-31 08:00:40",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1743356": [
        {
            "ioc_value": "61.166.154.109:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-02-08 15:42:28",
            "last_seen_utc": "2026-08-31 08:00:39",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1743357": [
        {
            "ioc_value": "49.235.177.231:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-02-08 15:42:28",
            "last_seen_utc": "2026-08-31 08:00:39",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1743353": [
        {
            "ioc_value": "81.70.255.195:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-02-08 15:42:27",
            "last_seen_utc": "2026-08-31 08:00:38",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1743354": [
        {
            "ioc_value": "81.69.98.230:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-02-08 15:42:27",
            "last_seen_utc": "2026-08-31 08:00:38",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1743355": [
        {
            "ioc_value": "8.210.78.137:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-02-08 15:42:27",
            "last_seen_utc": "2026-08-31 08:00:38",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1743351": [
        {
            "ioc_value": "83.229.126.65:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-02-08 15:42:26",
            "last_seen_utc": "2026-08-31 08:00:38",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1743352": [
        {
            "ioc_value": "81.71.159.99:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-02-08 15:42:26",
            "last_seen_utc": "2026-08-31 08:00:38",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1743349": [
        {
            "ioc_value": "83.229.123.61:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-02-08 15:42:15",
            "last_seen_utc": "2026-08-31 08:00:25",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1743350": [
        {
            "ioc_value": "83.229.126.183:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-02-08 15:42:15",
            "last_seen_utc": "2026-08-31 08:00:25",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1743348": [
        {
            "ioc_value": "8.153.205.30:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-02-08 15:42:14",
            "last_seen_utc": "2026-08-31 08:00:39",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1743347": [
        {
            "ioc_value": "8.137.149.67:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-02-08 15:42:13",
            "last_seen_utc": "2026-08-31 08:00:23",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1743344": [
        {
            "ioc_value": "47.93.28.103:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-02-08 15:42:12",
            "last_seen_utc": "2026-08-31 08:00:40",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1743345": [
        {
            "ioc_value": "60.205.139.210:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-02-08 15:42:12",
            "last_seen_utc": "2026-08-31 08:00:21",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1743346": [
        {
            "ioc_value": "lcowpowerlite.italynorth.cloudapp.azure.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-02-08 15:42:12",
            "last_seen_utc": "2026-08-31 08:00:22",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1743340": [
        {
            "ioc_value": "47.109.198.8:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-02-08 15:42:11",
            "last_seen_utc": "2026-08-31 08:00:18",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1743341": [
        {
            "ioc_value": "47.120.70.161:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-02-08 15:42:11",
            "last_seen_utc": "2026-08-31 08:00:40",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1743342": [
        {
            "ioc_value": "47.121.137.8:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-02-08 15:42:11",
            "last_seen_utc": "2026-08-31 08:00:40",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1743343": [
        {
            "ioc_value": "47.121.29.60:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-02-08 15:42:11",
            "last_seen_utc": "2026-08-31 08:00:20",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1743336": [
        {
            "ioc_value": "45.115.236.152:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-02-08 15:42:10",
            "last_seen_utc": "2026-08-31 08:00:42",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1743338": [
        {
            "ioc_value": "47.107.136.106:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-02-08 15:42:10",
            "last_seen_utc": "2026-08-31 08:00:41",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1743339": [
        {
            "ioc_value": "47.109.145.121:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-02-08 15:42:10",
            "last_seen_utc": "2026-08-31 08:00:41",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1743333": [
        {
            "ioc_value": "192.140.176.79:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-02-08 15:42:09",
            "last_seen_utc": "2026-08-31 08:00:16",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1743334": [
        {
            "ioc_value": "36.140.162.173:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-02-08 15:42:09",
            "last_seen_utc": "2026-08-31 08:00:16",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1743335": [
        {
            "ioc_value": "39.105.165.37:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-02-08 15:42:09",
            "last_seen_utc": "2026-08-31 08:00:43",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1743330": [
        {
            "ioc_value": "152.32.251.78:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-02-08 15:42:08",
            "last_seen_utc": "2026-08-31 08:00:44",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1743331": [
        {
            "ioc_value": "154.201.74.112:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-02-08 15:42:08",
            "last_seen_utc": "2026-08-31 08:00:44",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1743332": [
        {
            "ioc_value": "179.43.186.214:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-02-08 15:42:08",
            "last_seen_utc": "2026-08-31 08:00:15",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1743326": [
        {
            "ioc_value": "139.196.41.201:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-02-08 15:42:07",
            "last_seen_utc": "2026-08-31 08:00:13",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1743327": [
        {
            "ioc_value": "139.224.16.185:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-02-08 15:42:07",
            "last_seen_utc": "2026-08-31 08:00:13",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1743328": [
        {
            "ioc_value": "14.103.175.50:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-02-08 15:42:07",
            "last_seen_utc": "2026-08-31 08:00:13",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1743329": [
        {
            "ioc_value": "150.187.25.242:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-02-08 15:42:07",
            "last_seen_utc": "2026-08-31 08:00:14",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1743322": [
        {
            "ioc_value": "120.48.168.57:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-02-08 15:42:06",
            "last_seen_utc": "2026-08-31 08:00:11",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1743323": [
        {
            "ioc_value": "121.40.18.128:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-02-08 15:42:06",
            "last_seen_utc": "2026-08-31 08:00:46",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1743324": [
        {
            "ioc_value": "122.51.93.94:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-02-08 15:42:06",
            "last_seen_utc": "2026-08-31 08:00:12",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1743325": [
        {
            "ioc_value": "134.122.140.185:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-02-08 15:42:06",
            "last_seen_utc": "2026-08-31 08:00:45",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1743320": [
        {
            "ioc_value": "117.72.102.110:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-02-08 15:42:05",
            "last_seen_utc": "2026-08-31 08:00:47",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1743321": [
        {
            "ioc_value": "117.72.242.9:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-02-08 15:42:05",
            "last_seen_utc": "2026-08-31 08:00:11",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1743318": [
        {
            "ioc_value": "113.44.67.52:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-02-08 15:42:04",
            "last_seen_utc": "2026-08-31 08:00:09",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1743319": [
        {
            "ioc_value": "115.190.161.178:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-02-08 15:42:04",
            "last_seen_utc": "2026-08-31 08:00:10",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1743314": [
        {
            "ioc_value": "106.38.201.95:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-02-08 15:42:03",
            "last_seen_utc": "2026-08-31 08:00:07",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1743315": [
        {
            "ioc_value": "106.75.162.108:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-02-08 15:42:03",
            "last_seen_utc": "2026-08-31 08:00:07",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1743316": [
        {
            "ioc_value": "106.75.215.96:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-02-08 15:42:03",
            "last_seen_utc": "2026-08-31 08:00:48",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1743317": [
        {
            "ioc_value": "106.75.224.31:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-02-08 15:42:03",
            "last_seen_utc": "2026-08-31 08:00:48",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1743312": [
        {
            "ioc_value": "106.12.219.245:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-02-08 15:42:02",
            "last_seen_utc": "2026-08-31 08:00:06",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1743313": [
        {
            "ioc_value": "106.13.29.104:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-02-08 15:42:02",
            "last_seen_utc": "2026-08-31 08:00:07",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1743209": [
        {
            "ioc_value": "15.204.95.228:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.havoc",
            "malware_alias": "Havokiz",
            "malware_printable": "Havoc",
            "first_seen_utc": "2026-02-08 04:00:55",
            "last_seen_utc": "2026-08-31 07:43:53",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/15.204.95.228",
            "tags": "AS16276,C2,censys,Havoc,OVH",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1742595": [
        {
            "ioc_value": "174.138.86.141:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-02-07 03:00:18",
            "last_seen_utc": "2026-08-31 07:44:29",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/174.138.86.141",
            "tags": "AS14061,C2,censys,Mythic",
            "anonymous": 0,
            "reporter": "dyingbreeds_"
        }
    ],
    "1741587": [
        {
            "ioc_value": "57.158.27.132:31337",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.sliver",
            "malware_alias": null,
            "malware_printable": "Sliver",
            "first_seen_utc": "2026-02-05 13:01:59",
            "last_seen_utc": "2026-08-31 07:47:31",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": "https://www.shodan.io/host/57.158.27.132#31337",
            "tags": "c2,shodan,sliver",
            "anonymous": 0,
            "reporter": "juroots"
        }
    ],
    "1741376": [
        {
            "ioc_value": "104.243.248.63:85",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-02-05 06:34:38",
            "last_seen_utc": "2026-08-31 07:43:17",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "",
            "tags": "AS3223,asyncrat,c2,fofa,RAT,VOXILITY",
            "anonymous": 0,
            "reporter": "oxygen28"
        }
    ],
    "1741375": [
        {
            "ioc_value": "37.72.172.58:6066",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-02-05 06:34:37",
            "last_seen_utc": "2026-08-31 07:46:54",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "",
            "tags": "AS29802,asyncrat,c2,fofa,RAT",
            "anonymous": 0,
            "reporter": "oxygen28"
        }
    ],
    "1741222": [
        {
            "ioc_value": "3.121.234.29:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-02-04 15:54:23",
            "last_seen_utc": "2026-08-31 07:46:44",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/3.121.234.29",
            "tags": "AS16509,C2,censys,Mythic",
            "anonymous": 0,
            "reporter": "dyingbreeds_"
        }
    ],
    "1741132": [
        {
            "ioc_value": "172.174.234.34:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-02-04 11:00:54",
            "last_seen_utc": "2026-08-31 07:44:21",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/172.174.234.34",
            "tags": "AS8075,C2,censys,Mythic",
            "anonymous": 0,
            "reporter": "dyingbreeds_"
        }
    ],
    "1740953": [
        {
            "ioc_value": "188.166.244.201:4321",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-02-04 00:02:27",
            "last_seen_utc": "2026-08-31 07:44:59",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/188.166.244.201",
            "tags": "AdaptixC2,AS14061,C2,censys,DIGITALOCEAN-ASN",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1740000": [
        {
            "ioc_value": "146.70.49.42:7080",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-02-02 18:00:52",
            "last_seen_utc": "2026-08-31 07:43:51",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://tria.ge/260202-r1f9ysbx8f",
            "tags": "AS9009,asyncrat,C2,rat,triage",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1739277": [
        {
            "ioc_value": "101.37.236.20:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-01-31 04:00:10",
            "last_seen_utc": "2026-08-31 07:48:22",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/101.37.236.20",
            "tags": "ALIBABA-CN-NET,AS37963,C2,censys,CobaltStrike,cs-watermark-100000",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1739209": [
        {
            "ioc_value": "47.115.193.52:4506",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.deimos_c2",
            "malware_alias": null,
            "malware_printable": "DeimosC2",
            "first_seen_utc": "2026-01-30 18:54:11",
            "last_seen_utc": "2026-08-31 07:47:24",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "Deimos,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1739163": [
        {
            "ioc_value": "107.150.105.91:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-01-30 16:04:48",
            "last_seen_utc": "2026-08-31 08:00:08",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/107.150.105.91",
            "tags": "AS135377,C2,censys,CobaltStrike,cs-watermark-666666666,UCLOUD-HK-AS-AP",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1739009": [
        {
            "ioc_value": "111.92.243.40:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-01-30 08:04:49",
            "last_seen_utc": "2026-08-31 08:00:09",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/111.92.243.40",
            "tags": "AS401696,C2,censys,CobaltStrike,COGNETCLOUD,cs-watermark-666666666",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1738921": [
        {
            "ioc_value": "45.82.85.50:13063",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.ransomhub",
            "malware_alias": null,
            "malware_printable": "RansomHub",
            "first_seen_utc": "2026-01-30 02:55:25",
            "last_seen_utc": "2026-08-31 07:47:18",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RansomHub",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1738855": [
        {
            "ioc_value": "209.145.63.3:33330",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-01-29 18:55:17",
            "last_seen_utc": "2026-08-31 07:45:46",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1737790": [
        {
            "ioc_value": "47.120.46.230:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-01-26 23:00:09",
            "last_seen_utc": "2026-08-31 08:00:19",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/47.120.46.230",
            "tags": "AS37963,C2,censys",
            "anonymous": 0,
            "reporter": "dyingbreeds_"
        }
    ],
    "1737664": [
        {
            "ioc_value": "https://fluraresto.me/live/",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.latrodectus",
            "malware_alias": "BLACKWIDOW,IceNova,Latrodectus,Lotus",
            "malware_printable": "Latrodectus",
            "first_seen_utc": "2026-01-26 13:57:13",
            "last_seen_utc": "2026-08-31 08:03:46",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "c2,Latrodectus",
            "anonymous": 0,
            "reporter": "Bitsight"
        }
    ],
    "1737665": [
        {
            "ioc_value": "https://mastralakkot.live/live/",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.latrodectus",
            "malware_alias": "BLACKWIDOW,IceNova,Latrodectus,Lotus",
            "malware_printable": "Latrodectus",
            "first_seen_utc": "2026-01-26 13:57:13",
            "last_seen_utc": "2026-08-31 08:12:48",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "c2,Latrodectus",
            "anonymous": 0,
            "reporter": "Bitsight"
        }
    ],
    "1736034": [
        {
            "ioc_value": "158.158.8.193:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.bianlian",
            "malware_alias": null,
            "malware_printable": "BianLian",
            "first_seen_utc": "2026-01-23 08:45:57",
            "last_seen_utc": "2026-08-31 07:44:06",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "Bianlian,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1736014": [
        {
            "ioc_value": "47.120.32.72:8075",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-01-23 08:04:06",
            "last_seen_utc": "2026-08-31 07:48:51",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/47.120.32.72",
            "tags": "ALIBABA-CN-NET,AS37963,C2,censys,CobaltStrike,cs-watermark-666666666",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1735921": [
        {
            "ioc_value": "104.243.248.63:103",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-01-23 00:04:39",
            "last_seen_utc": "2026-08-31 07:43:16",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/104.243.248.63",
            "tags": "AS3223,AsyncRAT,C2,censys,RAT,VOXILITY",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1735523": [
        {
            "ioc_value": "104.243.248.63:81",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-01-22 12:04:41",
            "last_seen_utc": "2026-08-31 07:43:17",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/104.243.248.63",
            "tags": "AS3223,AsyncRAT,C2,censys,RAT,VOXILITY",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1735522": [
        {
            "ioc_value": "176.31.71.168:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pupy",
            "malware_alias": "Patpoopy",
            "malware_printable": "pupy",
            "first_seen_utc": "2026-01-22 12:04:28",
            "last_seen_utc": "2026-08-31 07:44:30",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/176.31.71.168",
            "tags": "AS16276,C2,censys,OVH,Pupy,RAT",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1735412": [
        {
            "ioc_value": "34.64.98.201:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pupy",
            "malware_alias": "Patpoopy",
            "malware_printable": "pupy",
            "first_seen_utc": "2026-01-22 04:04:19",
            "last_seen_utc": "2026-08-31 07:46:52",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/34.64.98.201",
            "tags": "AS396982,C2,censys,GOOGLE-CLOUD-PLATFORM,Pupy,RAT",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1735387": [
        {
            "ioc_value": "34.64.98.201:8443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pupy",
            "malware_alias": "Patpoopy",
            "malware_printable": "pupy",
            "first_seen_utc": "2026-01-22 00:04:16",
            "last_seen_utc": "2026-08-31 07:46:52",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/34.64.98.201",
            "tags": "AS396982,C2,censys,GOOGLE-CLOUD-PLATFORM,Pupy,RAT",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1735342": [
        {
            "ioc_value": "54.145.56.188:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-01-21 20:04:36",
            "last_seen_utc": "2026-08-31 07:47:29",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/54.145.56.188",
            "tags": "AMAZON-AES,AS14618,C2,censys,Mythic",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1734935": [
        {
            "ioc_value": "37.72.168.189:42334",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-01-20 20:05:01",
            "last_seen_utc": "2026-08-31 07:46:54",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/37.72.168.189",
            "tags": "AdaptixC2,AS29802,C2,censys,HVC-AS",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1734893": [
        {
            "ioc_value": "136.24.173.249:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-01-20 16:04:24",
            "last_seen_utc": "2026-08-31 07:43:44",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/136.24.173.249",
            "tags": "AS19165,C2,censys,Mythic,WEBPASS",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1734787": [
        {
            "ioc_value": "104.243.248.63:83",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-01-20 08:04:17",
            "last_seen_utc": "2026-08-31 07:43:17",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/104.243.248.63",
            "tags": "AS3223,AsyncRAT,C2,censys,RAT,VOXILITY",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1734788": [
        {
            "ioc_value": "104.243.248.63:102",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-01-20 08:04:17",
            "last_seen_utc": "2026-08-31 07:43:15",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/104.243.248.63",
            "tags": "AS3223,AsyncRAT,C2,censys,RAT,VOXILITY",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1734081": [
        {
            "ioc_value": "103.79.79.105:8444",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pupy",
            "malware_alias": "Patpoopy",
            "malware_printable": "pupy",
            "first_seen_utc": "2026-01-18 00:03:59",
            "last_seen_utc": "2026-08-31 07:43:12",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/103.79.79.105",
            "tags": "AS199959,C2,censys,CROWNCLOUD,Pupy,RAT",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1733584": [
        {
            "ioc_value": "101.37.236.20:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-01-16 14:56:41",
            "last_seen_utc": "2026-08-31 07:48:22",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1733583": [
        {
            "ioc_value": "test.dnslogger.site",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-01-16 14:56:19",
            "last_seen_utc": "2026-08-31 07:48:20",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1731532": [
        {
            "ioc_value": "54.38.94.225:8881",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.eye_pyramid",
            "malware_alias": null,
            "malware_printable": "Eye Pyramid",
            "first_seen_utc": "2026-01-13 08:52:00",
            "last_seen_utc": "2026-08-31 07:47:29",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,EyePyramid",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1700820": [
        {
            "ioc_value": "102.117.170.125:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-01-11 11:00:48",
            "last_seen_utc": "2026-08-31 07:43:05",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/102.117.170.125",
            "tags": "AS23889,C2,censys,MauritiusTelecom,Mythic",
            "anonymous": 0,
            "reporter": "dyingbreeds_"
        }
    ],
    "1693365": [
        {
            "ioc_value": "117.72.178.246:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-01-08 23:00:12",
            "last_seen_utc": "2026-08-31 08:00:11",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/117.72.178.246",
            "tags": "AS141679,C2,censys",
            "anonymous": 0,
            "reporter": "dyingbreeds_"
        }
    ],
    "1693357": [
        {
            "ioc_value": "172.94.18.103:191",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-01-08 22:50:04",
            "last_seen_utc": "2026-08-31 07:44:28",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1692743": [
        {
            "ioc_value": "38.49.57.15:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-01-07 20:02:36",
            "last_seen_utc": "2026-08-31 08:00:16",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/38.49.57.15",
            "tags": "AS8796,C2,censys,CobaltStrike,cs-watermark-666666666,FD-298-8796",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1691952": [
        {
            "ioc_value": "115.190.233.79:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-01-06 08:02:23",
            "last_seen_utc": "2026-08-31 08:00:10",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/115.190.233.79",
            "tags": "AS137718,C2,censys,CobaltStrike,cs-watermark-987654321,VOLCANO-ENGINE",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1691605": [
        {
            "ioc_value": "http://213.5.130.122",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-01-05 13:21:42",
            "last_seen_utc": "2026-08-31 06:01:32",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "c2,REMPROXY",
            "anonymous": 0,
            "reporter": "BlackLotusLabs"
        }
    ],
    "1691603": [
        {
            "ioc_value": "http://213.5.130.151",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-01-05 13:21:41",
            "last_seen_utc": "2026-08-31 06:01:32",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "c2,REMPROXY",
            "anonymous": 0,
            "reporter": "BlackLotusLabs"
        }
    ],
    "1691604": [
        {
            "ioc_value": "http://213.5.130.124",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-01-05 13:21:40",
            "last_seen_utc": "2026-08-31 06:01:34",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "c2,REMPROXY",
            "anonymous": 0,
            "reporter": "BlackLotusLabs"
        }
    ],
    "1691606": [
        {
            "ioc_value": "http://213.5.130.187",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-01-05 13:21:40",
            "last_seen_utc": "2026-08-31 06:01:32",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "c2,REMPROXY",
            "anonymous": 0,
            "reporter": "BlackLotusLabs"
        }
    ],
    "1689798": [
        {
            "ioc_value": "157.245.54.75:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pupy",
            "malware_alias": "Patpoopy",
            "malware_printable": "pupy",
            "first_seen_utc": "2026-01-02 04:03:37",
            "last_seen_utc": "2026-08-30 18:43:50",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/157.245.54.75",
            "tags": "AS14061,C2,censys,DIGITALOCEAN-ASN,Pupy,RAT",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1689290": [
        {
            "ioc_value": "182.92.117.223:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-01-01 07:01:03",
            "last_seen_utc": "2026-08-31 07:48:40",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-987654321",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1688739": [
        {
            "ioc_value": "101.34.205.214:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-12-30 16:21:16",
            "last_seen_utc": "2026-08-31 08:00:37",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1688738": [
        {
            "ioc_value": "103.171.35.66:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-12-30 16:21:15",
            "last_seen_utc": "2026-08-31 08:00:36",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1688737": [
        {
            "ioc_value": "107.149.192.54:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-12-30 16:21:14",
            "last_seen_utc": "2026-08-31 08:00:36",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1688734": [
        {
            "ioc_value": "124.222.218.20:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-12-30 16:21:13",
            "last_seen_utc": "2026-08-31 08:00:35",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1688735": [
        {
            "ioc_value": "124.221.255.78:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-12-30 16:21:13",
            "last_seen_utc": "2026-08-31 08:00:35",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1688736": [
        {
            "ioc_value": "123.56.78.220:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-12-30 16:21:13",
            "last_seen_utc": "2026-08-31 08:00:35",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1688732": [
        {
            "ioc_value": "152.32.202.240:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-12-30 16:21:12",
            "last_seen_utc": "2026-08-31 08:00:34",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1688733": [
        {
            "ioc_value": "150.158.119.242:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-12-30 16:21:12",
            "last_seen_utc": "2026-08-31 08:00:34",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1688730": [
        {
            "ioc_value": "165.154.244.73:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-12-30 16:21:11",
            "last_seen_utc": "2026-08-31 08:00:33",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1688731": [
        {
            "ioc_value": "156.225.20.77:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-12-30 16:21:11",
            "last_seen_utc": "2026-08-31 08:00:34",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1688729": [
        {
            "ioc_value": "182.92.239.94:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-12-30 16:21:10",
            "last_seen_utc": "2026-08-31 08:00:33",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1688726": [
        {
            "ioc_value": "39.105.160.175:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-12-30 16:21:08",
            "last_seen_utc": "2026-08-31 08:00:31",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1688727": [
        {
            "ioc_value": "38.38.250.99:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-12-30 16:21:08",
            "last_seen_utc": "2026-08-31 08:00:31",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1688728": [
        {
            "ioc_value": "211.184.175.246:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-12-30 16:21:08",
            "last_seen_utc": "2026-08-31 08:00:31",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1688725": [
        {
            "ioc_value": "45.58.56.34:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-12-30 16:21:07",
            "last_seen_utc": "2026-08-31 08:00:42",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1688723": [
        {
            "ioc_value": "8.130.80.145:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-12-30 16:21:05",
            "last_seen_utc": "2026-08-31 08:00:28",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1688724": [
        {
            "ioc_value": "8.130.26.216:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-12-30 16:21:05",
            "last_seen_utc": "2026-08-31 08:00:28",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1688721": [
        {
            "ioc_value": "94.74.164.177:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-12-30 16:21:03",
            "last_seen_utc": "2026-08-31 08:00:26",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1688722": [
        {
            "ioc_value": "87.251.67.85:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-12-30 16:21:03",
            "last_seen_utc": "2026-08-31 08:00:26",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1688694": [
        {
            "ioc_value": "16.171.13.191:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2025-12-30 16:04:05",
            "last_seen_utc": "2026-08-31 07:44:10",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/16.171.13.191",
            "tags": "AMAZON-02,AS16509,C2,censys,Covenant",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1687948": [
        {
            "ioc_value": "222.186.17.103:4506",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.deimos_c2",
            "malware_alias": null,
            "malware_printable": "DeimosC2",
            "first_seen_utc": "2025-12-29 08:46:57",
            "last_seen_utc": "2026-08-31 07:46:39",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "Deimos,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1687807": [
        {
            "ioc_value": "163.181.213.114:4506",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.deimos_c2",
            "malware_alias": null,
            "malware_printable": "DeimosC2",
            "first_seen_utc": "2025-12-28 18:44:20",
            "last_seen_utc": "2026-08-31 07:44:13",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "Deimos,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1687327": [
        {
            "ioc_value": "37.72.172.58:8088",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2025-12-28 07:41:32",
            "last_seen_utc": "2026-08-31 07:46:55",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/37.72.172.58",
            "tags": "AS29802,C2,censys,HVC-AS,RAT",
            "anonymous": 0,
            "reporter": "dyingbreeds_"
        }
    ],
    "1687170": [
        {
            "ioc_value": "37.72.172.58:8808",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2025-12-27 16:02:33",
            "last_seen_utc": "2026-08-31 07:46:55",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/37.72.172.58",
            "tags": "AS29802,AsyncRAT,C2,censys,HVC-AS,RAT",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1686405": [
        {
            "ioc_value": "155.102.62.60:4506",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.deimos_c2",
            "malware_alias": null,
            "malware_printable": "DeimosC2",
            "first_seen_utc": "2025-12-25 18:44:15",
            "last_seen_utc": "2026-08-31 07:44:00",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "Deimos,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1686010": [
        {
            "ioc_value": "139.196.223.82:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-12-25 07:52:31",
            "last_seen_utc": "2026-08-31 08:00:12",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/139.196.223.82",
            "tags": "AS37963,C2,censys",
            "anonymous": 0,
            "reporter": "dyingbreeds_"
        }
    ],
    "1685856": [
        {
            "ioc_value": "helpremote.cc",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-12-24 12:48:51",
            "last_seen_utc": "2026-08-31 08:00:25",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1685596": [
        {
            "ioc_value": "172.94.18.103:190",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2025-12-23 22:45:05",
            "last_seen_utc": "2026-08-31 07:44:27",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1685256": [
        {
            "ioc_value": "115.190.160.206:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-12-23 20:01:06",
            "last_seen_utc": "2026-08-31 08:00:09",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/115.190.160.206",
            "tags": "AS137718,C2,censys,CobaltStrike,cs-watermark-987654321,VOLCANO-ENGINE",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1684938": [
        {
            "ioc_value": "8.159.146.72:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-12-23 03:00:34",
            "last_seen_utc": "2026-08-31 08:00:24",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1684936": [
        {
            "ioc_value": "missmovie.lol",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-12-23 02:54:49",
            "last_seen_utc": "2026-08-31 07:48:17",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1684826": [
        {
            "ioc_value": "179.43.186.214:7889",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-12-22 20:01:00",
            "last_seen_utc": "2026-08-31 07:48:39",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/179.43.186.214",
            "tags": "AS51852,C2,censys,CobaltStrike,cs-watermark-987654321,PLI-AS",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1682522": [
        {
            "ioc_value": "155.102.133.61:4506",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.deimos_c2",
            "malware_alias": null,
            "malware_printable": "DeimosC2",
            "first_seen_utc": "2025-12-18 18:44:36",
            "last_seen_utc": "2026-08-31 07:44:00",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "Deimos,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1680395": [
        {
            "ioc_value": "119.45.160.160:8889",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-12-16 06:49:03",
            "last_seen_utc": "2026-08-31 07:48:30",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": "https://www.shodan.io/host/119.45.160.160#8889",
            "tags": "c2,cobaltstrike,cs-watermark-987654321,shodan",
            "anonymous": 0,
            "reporter": "juroots"
        }
    ],
    "1680210": [
        {
            "ioc_value": "39.105.200.188:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-12-15 20:00:23",
            "last_seen_utc": "2026-08-31 07:48:47",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/39.105.200.188",
            "tags": "ALIBABA-CN-NET,AS37963,C2,censys,CobaltStrike,cs-watermark-987654321",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1676363": [
        {
            "ioc_value": "67.219.102.244:53",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-12-12 02:50:28",
            "last_seen_utc": "2026-08-31 07:48:54",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1673817": [
        {
            "ioc_value": "106.14.16.18:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-12-09 20:01:49",
            "last_seen_utc": "2026-08-31 07:48:23",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/106.14.16.18",
            "tags": "ALIBABA-CN-NET,AS37963,C2,censys,CobaltStrike,cs-watermark-987654321",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1670887": [
        {
            "ioc_value": "20.157.116.151:8000",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2025-12-08 14:58:40",
            "last_seen_utc": "2026-08-31 07:45:37",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/20.157.116.151",
            "tags": "AdaptixC2,AS8069,C2,censys,MICROSOFT-CORP-MSN-AS-BLOCK",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1668967": [
        {
            "ioc_value": "180.76.141.175:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-12-07 16:01:37",
            "last_seen_utc": "2026-08-31 08:00:15",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/180.76.141.175",
            "tags": "AS38365,BAIDU,C2,censys,CobaltStrike,cs-watermark-391144938",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1667182": [
        {
            "ioc_value": "216.238.89.173:4321",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2025-12-04 00:03:19",
            "last_seen_utc": "2026-08-31 07:46:32",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/216.238.89.173",
            "tags": "AdaptixC2,AS-VULTR,AS20473,C2,censys",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1667105": [
        {
            "ioc_value": "115.190.161.178:1234",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-12-03 20:01:15",
            "last_seen_utc": "2026-08-31 07:48:26",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/115.190.161.178",
            "tags": "AS137718,C2,censys,CobaltStrike,cs-watermark-987654321,VOLCANO-ENGINE",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1666137": [
        {
            "ioc_value": "8.137.149.67:8091",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-12-02 12:51:03",
            "last_seen_utc": "2026-08-31 07:48:56",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1665523": [
        {
            "ioc_value": "http://213.5.130.104",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2025-12-01 14:57:52",
            "last_seen_utc": "2026-08-31 06:01:31",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "c2,REMPROXY",
            "anonymous": 0,
            "reporter": "BlackLotusLabs"
        }
    ],
    "1665524": [
        {
            "ioc_value": "http://213.5.130.180",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2025-12-01 14:57:52",
            "last_seen_utc": "2026-08-31 06:01:34",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "c2,REMPROXY",
            "anonymous": 0,
            "reporter": "BlackLotusLabs"
        }
    ],
    "1665525": [
        {
            "ioc_value": "http://213.5.130.106",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2025-12-01 14:57:50",
            "last_seen_utc": "2026-08-31 06:01:31",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "c2,REMPROXY",
            "anonymous": 0,
            "reporter": "BlackLotusLabs"
        }
    ],
    "1665527": [
        {
            "ioc_value": "http://213.5.130.152",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2025-12-01 14:57:49",
            "last_seen_utc": "2026-08-31 06:01:33",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "c2,REMPROXY",
            "anonymous": 0,
            "reporter": "BlackLotusLabs"
        }
    ],
    "1665528": [
        {
            "ioc_value": "http://213.5.130.107",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2025-12-01 14:57:49",
            "last_seen_utc": "2026-08-31 06:01:34",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "c2,REMPROXY",
            "anonymous": 0,
            "reporter": "BlackLotusLabs"
        }
    ],
    "1665529": [
        {
            "ioc_value": "http://213.5.130.153",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2025-12-01 14:57:49",
            "last_seen_utc": "2026-08-31 06:01:32",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "c2,REMPROXY",
            "anonymous": 0,
            "reporter": "BlackLotusLabs"
        }
    ],
    "1665530": [
        {
            "ioc_value": "http://213.5.130.100",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2025-12-01 14:57:48",
            "last_seen_utc": "2026-08-31 06:01:32",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "c2,REMPROXY",
            "anonymous": 0,
            "reporter": "BlackLotusLabs"
        }
    ],
    "1665531": [
        {
            "ioc_value": "http://213.5.130.182",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2025-12-01 14:57:48",
            "last_seen_utc": "2026-08-31 06:01:33",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "c2,REMPROXY",
            "anonymous": 0,
            "reporter": "BlackLotusLabs"
        }
    ],
    "1663012": [
        {
            "ioc_value": "47.236.56.15:4445",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-11-29 12:00:52",
            "last_seen_utc": "2026-08-31 07:48:52",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/47.236.56.15",
            "tags": "ALIBABA-CN-NET,AS45102,C2,censys,CobaltStrike,cs-watermark-0",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1650889": [
        {
            "ioc_value": "job.itechno.cc",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-11-26 12:50:54",
            "last_seen_utc": "2026-08-31 07:48:17",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1650040": [
        {
            "ioc_value": "156.245.248.173:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-11-25 10:49:55",
            "last_seen_utc": "2026-08-31 08:00:44",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1649775": [
        {
            "ioc_value": "http://213.5.130.84",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2025-11-25 06:01:37",
            "last_seen_utc": "2026-08-31 06:01:32",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "c2,REMPROXY",
            "anonymous": 0,
            "reporter": "BlackLotusLabs"
        }
    ],
    "1649776": [
        {
            "ioc_value": "http://213.5.130.96",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2025-11-25 06:01:36",
            "last_seen_utc": "2026-08-31 06:01:33",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "c2,REMPROXY",
            "anonymous": 0,
            "reporter": "BlackLotusLabs"
        }
    ],
    "1649777": [
        {
            "ioc_value": "http://213.5.130.98",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2025-11-25 06:01:36",
            "last_seen_utc": "2026-08-31 06:01:33",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "c2,REMPROXY",
            "anonymous": 0,
            "reporter": "BlackLotusLabs"
        }
    ],
    "1649778": [
        {
            "ioc_value": "http://213.5.130.160",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2025-11-25 06:01:35",
            "last_seen_utc": "2026-08-31 06:01:33",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "c2,REMPROXY",
            "anonymous": 0,
            "reporter": "BlackLotusLabs"
        }
    ],
    "1647575": [
        {
            "ioc_value": "123.58.64.57:34567",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-11-21 00:02:05",
            "last_seen_utc": "2026-08-31 07:48:32",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/123.58.64.57",
            "tags": "AS17623,C2,censys,CNCGROUP-SZ,CobaltStrike,cs-watermark-987654321",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1645785": [
        {
            "ioc_value": "47.236.149.142:46832",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-11-17 23:00:18",
            "last_seen_utc": "2026-08-31 07:48:52",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/47.236.149.142",
            "tags": "AS45102,C2,censys",
            "anonymous": 0,
            "reporter": "dyingbreeds_"
        }
    ],
    "1645519": [
        {
            "ioc_value": "http://185.132.133.127",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2025-11-17 13:58:09",
            "last_seen_utc": "2026-08-31 06:01:32",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "c2,REMPROXY",
            "anonymous": 0,
            "reporter": "BlackLotusLabs"
        }
    ],
    "1645520": [
        {
            "ioc_value": "http://185.132.133.140",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2025-11-17 13:58:09",
            "last_seen_utc": "2026-08-31 06:01:31",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "c2,REMPROXY",
            "anonymous": 0,
            "reporter": "BlackLotusLabs"
        }
    ],
    "1641582": [
        {
            "ioc_value": "62.4.0.66:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2025-11-15 08:48:18",
            "last_seen_utc": "2026-08-31 07:47:33",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1639703": [
        {
            "ioc_value": "62.60.226.183:483",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.tofsee",
            "malware_alias": "Gheg",
            "malware_printable": "Tofsee",
            "first_seen_utc": "2025-11-13 04:54:17",
            "last_seen_utc": "2026-08-31 07:24:56",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "c2,Tofsee",
            "anonymous": 0,
            "reporter": "Bitsight"
        }
    ],
    "1639719": [
        {
            "ioc_value": "45.76.190.68:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2025-11-13 04:54:12",
            "last_seen_utc": "2026-08-31 07:47:18",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/45.76.190.68",
            "tags": "AS-VULTR,AS20473,C2,censys,Mythic",
            "anonymous": 0,
            "reporter": "dyingbreeds_"
        }
    ],
    "1639434": [
        {
            "ioc_value": "62.4.0.66:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2025-11-12 16:02:00",
            "last_seen_utc": "2026-08-31 07:47:33",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/62.4.0.66",
            "tags": "AS12876,C2,censys,Mythic,Online",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1638854": [
        {
            "ioc_value": "54.165.230.182:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2025-11-12 04:02:31",
            "last_seen_utc": "2026-08-31 07:47:29",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/54.165.230.182",
            "tags": "AMAZON-AES,AS14618,C2,censys,Covenant",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1638662": [
        {
            "ioc_value": "208.87.129.112:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2025-11-11 12:01:51",
            "last_seen_utc": "2026-08-31 07:45:46",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/208.87.129.112",
            "tags": "AS29802,C2,censys,HVC-AS,Mythic",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1638590": [
        {
            "ioc_value": "45.76.190.68:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2025-11-11 08:02:54",
            "last_seen_utc": "2026-08-31 07:47:17",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/45.76.190.68",
            "tags": "AS-VULTR,AS20473,C2,censys,Mythic",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1638274": [
        {
            "ioc_value": "38.242.212.5:4321",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2025-11-10 18:47:41",
            "last_seen_utc": "2026-08-31 07:46:58",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1638236": [
        {
            "ioc_value": "154.205.145.109:2096",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.havoc",
            "malware_alias": "Havokiz",
            "malware_printable": "Havoc",
            "first_seen_utc": "2025-11-10 16:02:55",
            "last_seen_utc": "2026-08-31 07:43:58",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/154.205.145.109",
            "tags": "AS138915,C2,censys,Havoc,KAOPU-HK",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1636099": [
        {
            "ioc_value": "111.228.55.96:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-11-07 23:00:12",
            "last_seen_utc": "2026-08-31 08:00:09",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/111.228.55.96",
            "tags": "AS141679,C2,censys",
            "anonymous": 0,
            "reporter": "dyingbreeds_"
        }
    ],
    "1634744": [
        {
            "ioc_value": "165.154.225.239:8443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-11-07 02:49:37",
            "last_seen_utc": "2026-08-31 07:48:38",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1634389": [
        {
            "ioc_value": "139.196.111.118:8088",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-11-06 07:26:25",
            "last_seen_utc": "2026-08-31 07:48:33",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-666666666",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1633501": [
        {
            "ioc_value": "59.110.28.230:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-11-04 20:01:04",
            "last_seen_utc": "2026-08-31 08:00:21",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/59.110.28.230",
            "tags": "ALIBABA-CN-NET,AS37963,C2,censys,CobaltStrike,cs-watermark-987654321",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1633194": [
        {
            "ioc_value": "51.15.8.6:31337",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.sliver",
            "malware_alias": null,
            "malware_printable": "Sliver",
            "first_seen_utc": "2025-11-04 08:00:54",
            "last_seen_utc": "2026-08-31 07:47:27",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/51.15.8.6",
            "tags": "AS12876,C2,censys,Online,Sliver",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1633063": [
        {
            "ioc_value": "192.253.227.88:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-11-04 02:49:22",
            "last_seen_utc": "2026-08-31 08:00:32",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1633061": [
        {
            "ioc_value": "167.88.168.76:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-11-04 02:49:14",
            "last_seen_utc": "2026-08-31 08:00:33",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1631753": [
        {
            "ioc_value": "117.72.175.125:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.vshell",
            "malware_alias": null,
            "malware_printable": "VShell",
            "first_seen_utc": "2025-11-03 12:08:57",
            "last_seen_utc": "2026-08-31 08:00:47",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://www.nviso.eu/blog",
            "tags": "C2,NVISO,VShell",
            "anonymous": 0,
            "reporter": "0xThiebaut"
        }
    ],
    "1631367": [
        {
            "ioc_value": "117.72.242.9:9999",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-11-03 09:03:04",
            "last_seen_utc": "2026-08-31 07:48:28",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/117.72.242.9",
            "tags": "AS141679,C2,censys",
            "anonymous": 0,
            "reporter": "dyingbreeds_"
        }
    ],
    "1631471": [
        {
            "ioc_value": "119.42.148.186:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-11-03 07:01:12",
            "last_seen_utc": "2026-08-31 08:00:35",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": "https://www.shodan.io/host/119.42.148.186#443",
            "tags": "c2,cobaltstrike,cs-watermark-666666666,shodan",
            "anonymous": 0,
            "reporter": "juroots"
        }
    ],
    "1630704": [
        {
            "ioc_value": "117.72.175.125:8087",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-11-01 12:31:38",
            "last_seen_utc": "2026-08-29 18:47:16",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": "https://www.shodan.io/host/117.72.175.125#8087",
            "tags": "c2,cobaltstrike,cs-watermark-391144938,shodan",
            "anonymous": 0,
            "reporter": "juroots"
        }
    ],
    "1629384": [
        {
            "ioc_value": "103.149.93.146:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-10-30 04:00:42",
            "last_seen_utc": "2026-08-31 08:00:37",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/103.149.93.146",
            "tags": "AS401696,C2,censys,CobaltStrike,COGNETCLOUD,cs-watermark-666666666",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1628814": [
        {
            "ioc_value": "179.43.186.214:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-10-29 09:23:45",
            "last_seen_utc": "2026-08-31 07:48:39",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-987654321",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1628691": [
        {
            "ioc_value": "8.17.56.128:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-10-29 02:49:59",
            "last_seen_utc": "2026-08-31 07:48:57",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1628076": [
        {
            "ioc_value": "8.137.149.67:8060",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-10-28 12:28:01",
            "last_seen_utc": "2026-08-31 07:48:56",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-987654321",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1627925": [
        {
            "ioc_value": "182.254.155.23:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-10-28 04:00:27",
            "last_seen_utc": "2026-08-31 08:00:33",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/182.254.155.23",
            "tags": "AS45090,C2,censys,CobaltStrike,cs-watermark-987654321,TENCENT-NET-AP",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1627719": [
        {
            "ioc_value": "182.16.98.83:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-10-28 02:49:21",
            "last_seen_utc": "2026-08-31 08:00:43",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1627659": [
        {
            "ioc_value": "182.16.98.84:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-10-27 20:50:01",
            "last_seen_utc": "2026-08-31 08:00:43",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1626705": [
        {
            "ioc_value": "196.251.83.89:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-10-26 07:39:14",
            "last_seen_utc": "2026-08-31 08:00:32",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/196.251.83.89",
            "tags": "AS401120,C2,censys,CHEAPY-HOST",
            "anonymous": 0,
            "reporter": "dyingbreeds_"
        }
    ],
    "1626312": [
        {
            "ioc_value": "173.212.216.226:8080",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.chaos",
            "malware_alias": "FakeRyuk,RyukJoke,Yashma",
            "malware_printable": "Chaos",
            "first_seen_utc": "2025-10-25 04:02:07",
            "last_seen_utc": "2026-08-31 07:44:29",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/173.212.216.226",
            "tags": "AS51167,censys,Chaos,CONTABO,panel",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1626300": [
        {
            "ioc_value": "47.121.135.201:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-10-25 04:00:11",
            "last_seen_utc": "2026-08-31 08:00:29",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/47.121.135.201",
            "tags": "ALIBABA-CN-NET,AS37963,C2,censys,CobaltStrike,cs-watermark-987654321",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1626112": [
        {
            "ioc_value": "140.143.194.253:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-10-24 16:00:08",
            "last_seen_utc": "2026-08-31 08:00:45",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/140.143.194.253",
            "tags": "AS45090,C2,censys,CobaltStrike,cs-watermark-987654321,TENCENT-NET-AP",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1625642": [
        {
            "ioc_value": "maelootp.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-10-23 16:48:58",
            "last_seen_utc": "2026-08-31 08:00:37",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1625564": [
        {
            "ioc_value": "evil.ritademo.io.vn",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-10-23 12:50:22",
            "last_seen_utc": "2026-08-31 08:00:38",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1625277": [
        {
            "ioc_value": "91.92.240.57:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.latrodectus",
            "malware_alias": "BLACKWIDOW,IceNova,Latrodectus,Lotus",
            "malware_printable": "Latrodectus",
            "first_seen_utc": "2025-10-23 04:02:14",
            "last_seen_utc": "2026-08-31 07:47:58",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/91.92.240.57",
            "tags": "AS214943,C2,censys,Latrodectus,RAILNET",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1624905": [
        {
            "ioc_value": "116.62.226.163:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-10-22 15:43:44",
            "last_seen_utc": "2026-08-31 08:00:47",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": null,
            "tags": "c2,censys,cobalt strike",
            "anonymous": 0,
            "reporter": "sojubear"
        }
    ],
    "1624300": [
        {
            "ioc_value": "47.110.67.64:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-10-21 20:01:59",
            "last_seen_utc": "2026-08-31 08:00:41",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/47.110.67.64",
            "tags": "ALIBABA-CN-NET,AS37963,C2,censys,CobaltStrike,cs-watermark-987654321",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1624166": [
        {
            "ioc_value": "http://213.5.130.75",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2025-10-21 13:19:24",
            "last_seen_utc": "2026-08-31 06:01:34",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "c2,REMPROXY",
            "anonymous": 0,
            "reporter": "BlackLotusLabs"
        }
    ],
    "1624167": [
        {
            "ioc_value": "http://213.5.130.10",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2025-10-21 13:19:23",
            "last_seen_utc": "2026-08-31 06:01:34",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "c2,REMPROXY",
            "anonymous": 0,
            "reporter": "BlackLotusLabs"
        }
    ],
    "1624169": [
        {
            "ioc_value": "http://213.5.130.90",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2025-10-21 13:19:22",
            "last_seen_utc": "2026-08-31 06:01:33",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "c2,REMPROXY",
            "anonymous": 0,
            "reporter": "BlackLotusLabs"
        }
    ],
    "1624170": [
        {
            "ioc_value": "http://213.5.130.89",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2025-10-21 13:19:22",
            "last_seen_utc": "2026-08-31 06:01:33",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "c2,REMPROXY",
            "anonymous": 0,
            "reporter": "BlackLotusLabs"
        }
    ],
    "1618877": [
        {
            "ioc_value": "115.29.202.62:92",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-10-21 02:49:57",
            "last_seen_utc": "2026-08-31 07:48:27",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1618876": [
        {
            "ioc_value": "www.salesf0rce.club",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-10-21 02:49:37",
            "last_seen_utc": "2026-08-31 08:00:26",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1617285": [
        {
            "ioc_value": "5.152.16.189:8443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.netsupportmanager_rat",
            "malware_alias": "NetSupport",
            "malware_printable": "NetSupportManager RAT",
            "first_seen_utc": "2025-10-17 12:02:17",
            "last_seen_utc": "2026-08-31 07:47:25",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/5.152.16.189",
            "tags": "AS35805,C2,censys,Netsupport,RAT,SILKNET-AS",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1616729": [
        {
            "ioc_value": "47.129.2.130:53",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-10-16 22:50:54",
            "last_seen_utc": "2026-08-31 07:48:52",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1616728": [
        {
            "ioc_value": "ns1.gygiuh.online",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-10-16 22:49:04",
            "last_seen_utc": "2026-08-31 07:48:18",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1615761": [
        {
            "ioc_value": "89.58.30.49:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2025-10-14 20:02:48",
            "last_seen_utc": "2026-08-31 07:47:56",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/89.58.30.49",
            "tags": "AS197540,C2,censys,Covenant,NETCUP-AS",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1608986": [
        {
            "ioc_value": "45.138.16.162:4321",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2025-10-07 20:02:30",
            "last_seen_utc": "2026-08-31 07:47:08",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/45.138.16.162",
            "tags": "AdaptixC2,AS210558,C2,censys,SERVICES-1337-GMBH",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1604523": [
        {
            "ioc_value": "18.219.51.236:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2025-09-30 04:00:23",
            "last_seen_utc": "2026-08-29 08:44:23",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/18.219.51.236",
            "tags": "AMAZON-02,AS16509,C2,censys,Mythic",
            "anonymous": 0,
            "reporter": "dyingbreeds_"
        }
    ],
    "1604499": [
        {
            "ioc_value": "149.50.135.215:49152",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2025-09-30 00:02:15",
            "last_seen_utc": "2026-08-31 07:43:53",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/149.50.135.215",
            "tags": "AdaptixC2,AS27823,C2,censys,Dattatec.com",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1603281": [
        {
            "ioc_value": "154.92.15.229:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-09-28 15:48:32",
            "last_seen_utc": "2026-08-31 08:00:34",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": null,
            "tags": "c2,censys,cobalt strike",
            "anonymous": 0,
            "reporter": "sojubear"
        }
    ],
    "1602679": [
        {
            "ioc_value": "43.166.246.26:8001",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-09-27 05:44:59",
            "last_seen_utc": "2026-08-31 07:48:49",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-426352781",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1601556": [
        {
            "ioc_value": "115.120.245.134:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-09-25 20:00:39",
            "last_seen_utc": "2026-08-31 08:00:09",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/115.120.245.134",
            "tags": "AS55990,C2,censys,CobaltStrike,cs-watermark-987654321,HWCSNET",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1601359": [
        {
            "ioc_value": "196.251.69.253:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-09-25 12:51:01",
            "last_seen_utc": "2026-08-31 08:00:32",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1599651": [
        {
            "ioc_value": "47.113.186.138:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-09-24 20:00:10",
            "last_seen_utc": "2026-08-31 08:00:41",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/47.113.186.138",
            "tags": "ALIBABA-CN-NET,AS37963,C2,censys,CobaltStrike,cs-watermark-987654321",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1599442": [
        {
            "ioc_value": "43.162.114.240:4000",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2025-09-24 08:02:13",
            "last_seen_utc": "2026-08-31 07:47:05",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/43.162.114.240",
            "tags": "AS132203,censys,EvilGinx,panel,Phishing,TENCENT-NET-AP-CN",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1599436": [
        {
            "ioc_value": "113.44.89.172:9999",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-09-24 08:00:08",
            "last_seen_utc": "2026-08-31 07:48:25",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/113.44.89.172",
            "tags": "AS55990,C2,censys,CobaltStrike,cs-watermark-987654321,HWCSNET",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1599090": [
        {
            "ioc_value": "46.21.153.148:43211",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2025-09-23 20:01:59",
            "last_seen_utc": "2026-08-29 08:46:37",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/46.21.153.148",
            "tags": "AdaptixC2,AS29802,C2,censys,HVC-AS",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1599091": [
        {
            "ioc_value": "46.21.153.146:43211",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2025-09-23 20:01:59",
            "last_seen_utc": "2026-08-31 07:47:22",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/46.21.153.146",
            "tags": "AdaptixC2,AS29802,C2,censys,HVC-AS",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1598300": [
        {
            "ioc_value": "43.162.114.107:4000",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2025-09-23 04:00:59",
            "last_seen_utc": "2026-08-31 07:47:04",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/43.162.114.107",
            "tags": "AS132203,censys,EvilGinx,Phishing",
            "anonymous": 0,
            "reporter": "dyingbreeds_"
        }
    ],
    "1598102": [
        {
            "ioc_value": "159.75.211.248:53",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-09-22 14:51:05",
            "last_seen_utc": "2026-08-31 07:48:37",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1598100": [
        {
            "ioc_value": "cstest.mucfc.store",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-09-22 14:49:30",
            "last_seen_utc": "2026-08-31 07:48:16",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1597898": [
        {
            "ioc_value": "ns2.cryptwechat.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-09-22 08:49:38",
            "last_seen_utc": "2026-08-31 07:48:19",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1597894": [
        {
            "ioc_value": "ns1.cryptwechat.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-09-22 08:49:35",
            "last_seen_utc": "2026-08-31 07:48:18",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1596535": [
        {
            "ioc_value": "43.162.108.133:4000",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2025-09-21 16:01:22",
            "last_seen_utc": "2026-08-31 07:47:04",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/43.162.108.133",
            "tags": "AS132203,censys,EvilGinx,panel,Phishing,TENCENT-NET-AP-CN",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1589068": [
        {
            "ioc_value": "18.167.174.198:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pupy",
            "malware_alias": "Patpoopy",
            "malware_printable": "pupy",
            "first_seen_utc": "2025-09-13 04:01:58",
            "last_seen_utc": "2026-08-31 07:44:37",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/18.167.174.198",
            "tags": "AMAZON-02,AS16509,C2,censys,Pupy,RAT",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1588133": [
        {
            "ioc_value": "195.178.110.135:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-09-11 20:01:36",
            "last_seen_utc": "2026-08-31 08:00:32",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/195.178.110.135",
            "tags": "AS48090,C2,censys,CobaltStrike,cs-watermark-426352781,DMZHOST",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1588128": [
        {
            "ioc_value": "150.158.170.241:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-09-11 20:01:30",
            "last_seen_utc": "2026-08-31 08:00:34",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/150.158.170.241",
            "tags": "AS45090,C2,censys,CobaltStrike,cs-watermark-987654321,TENCENT-NET-AP",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1587773": [
        {
            "ioc_value": "106.12.111.209:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-09-11 06:43:14",
            "last_seen_utc": "2026-08-31 08:00:36",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-1234567890",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1587441": [
        {
            "ioc_value": "101.32.109.112:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-09-10 20:01:24",
            "last_seen_utc": "2026-08-31 08:00:37",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/101.32.109.112",
            "tags": "AS132203,C2,censys,CobaltStrike,cs-watermark-987654321,TENCENT-NET-AP-CN",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1583496": [
        {
            "ioc_value": "43.225.157.146:8808",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2025-09-07 20:02:05",
            "last_seen_utc": "2026-08-31 07:47:06",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/43.225.157.146",
            "tags": "AS142403,AsyncRAT,C2,censys,RAT,YISUCLOUDLTD-HK",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1582910": [
        {
            "ioc_value": "8.138.222.215:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-09-06 20:01:18",
            "last_seen_utc": "2026-08-31 08:00:27",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/8.138.222.215",
            "tags": "ALIBABA-CN-NET,AS37963,C2,censys,CobaltStrike,cs-watermark-666666666",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1582784": [
        {
            "ioc_value": "103.236.70.158:8000",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.dcrat",
            "malware_alias": "DarkCrystal RAT",
            "malware_printable": "DCRat",
            "first_seen_utc": "2025-09-06 12:01:48",
            "last_seen_utc": "2026-08-31 07:43:09",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/103.236.70.158",
            "tags": "AS134768,C2,censys,CHINANET-SHAANXI-CLOUD-BASE,DcRAT,RAT",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1581557": [
        {
            "ioc_value": "8.148.194.157:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-09-04 07:40:17",
            "last_seen_utc": "2026-08-31 08:00:27",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": "https://www.shodan.io/host/8.148.194.157#443",
            "tags": "c2,cobaltstrike,cs-watermark-666666666,shodan",
            "anonymous": 0,
            "reporter": "juroots"
        }
    ],
    "1580723": [
        {
            "ioc_value": "47.236.159.248:53",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-09-02 18:52:55",
            "last_seen_utc": "2026-08-31 07:48:52",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1580721": [
        {
            "ioc_value": "ns2.microoosoft.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-09-02 18:50:45",
            "last_seen_utc": "2026-08-31 07:48:19",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1580720": [
        {
            "ioc_value": "ns1.microoosoft.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-09-02 18:50:42",
            "last_seen_utc": "2026-08-31 07:48:18",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1580257": [
        {
            "ioc_value": "47.121.137.8:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-09-02 05:43:42",
            "last_seen_utc": "2026-08-31 07:48:51",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": "https://www.shodan.io/host/47.121.137.8#80",
            "tags": "c2,cobaltstrike,cs-watermark-666666666,shodan",
            "anonymous": 0,
            "reporter": "juroots"
        }
    ],
    "1580237": [
        {
            "ioc_value": "47.99.196.178:7001",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2025-09-02 04:01:38",
            "last_seen_utc": "2026-08-31 07:47:24",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/47.99.196.178",
            "tags": "AdaptixC2,ALIBABA-CN-NET,AS37963,C2,censys",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1578921": [
        {
            "ioc_value": "109.205.181.248:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2025-09-01 00:01:11",
            "last_seen_utc": "2026-08-31 07:43:27",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/109.205.181.248",
            "tags": "AS51167,C2,censys,CONTABO,Mythic",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1578899": [
        {
            "ioc_value": "103.73.66.43:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-08-31 20:50:07",
            "last_seen_utc": "2026-08-31 08:00:48",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1578379": [
        {
            "ioc_value": "109.205.181.248:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2025-08-31 04:00:27",
            "last_seen_utc": "2026-08-31 07:43:27",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/109.205.181.248",
            "tags": "AS51167,C2,censys,CONTABO,Mythic",
            "anonymous": 0,
            "reporter": "dyingbreeds_"
        }
    ],
    "1577783": [
        {
            "ioc_value": "43.199.78.142:53",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-08-29 22:50:45",
            "last_seen_utc": "2026-08-31 07:48:49",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1577775": [
        {
            "ioc_value": "n1.google-analytcis.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-08-29 22:49:03",
            "last_seen_utc": "2026-08-31 07:48:17",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1577776": [
        {
            "ioc_value": "n2.google-analytcis.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-08-29 22:49:03",
            "last_seen_utc": "2026-08-31 07:48:18",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1577777": [
        {
            "ioc_value": "n3.google-analytcis.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-08-29 22:49:03",
            "last_seen_utc": "2026-08-31 07:48:18",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1577774": [
        {
            "ioc_value": "lab.google-analytcis.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-08-29 22:49:01",
            "last_seen_utc": "2026-08-31 07:48:17",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1576432": [
        {
            "ioc_value": "46.246.82.10:2003",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.dcrat",
            "malware_alias": "DarkCrystal RAT",
            "malware_printable": "DCRat",
            "first_seen_utc": "2025-08-28 20:01:21",
            "last_seen_utc": "2026-08-31 07:47:23",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/46.246.82.10",
            "tags": "AS42708,C2,censys,DcRAT,GLESYS,RAT",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1574099": [
        {
            "ioc_value": "89.216.98.17:3085",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.netsupportmanager_rat",
            "malware_alias": "NetSupport",
            "malware_printable": "NetSupportManager RAT",
            "first_seen_utc": "2025-08-25 08:14:17",
            "last_seen_utc": "2026-08-31 07:47:55",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": "https://www.shodan.io/host/89.216.98.17#3085",
            "tags": "c2,netsupport,shodan",
            "anonymous": 0,
            "reporter": "juroots"
        }
    ],
    "1573705": [
        {
            "ioc_value": "43.163.112.217:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-08-25 00:00:27",
            "last_seen_utc": "2026-08-31 08:00:30",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/43.163.112.217",
            "tags": "AS132203,C2,censys,CobaltStrike,cs-watermark-987654321,TENCENT-NET-AP-CN",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1573112": [
        {
            "ioc_value": "3.24.114.211:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2025-08-23 16:00:59",
            "last_seen_utc": "2026-08-31 07:46:45",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/3.24.114.211",
            "tags": "AMAZON-02,AS16509,C2,censys,Mythic",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1571607": [
        {
            "ioc_value": "178.16.55.53:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-08-20 08:02:12",
            "last_seen_utc": "2026-08-31 08:00:43",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/178.16.55.53",
            "tags": "C2,censys,CobaltStrike,cs-watermark-666666666",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1570775": [
        {
            "ioc_value": "116.203.31.207:9999",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-08-18 20:01:59",
            "last_seen_utc": "2026-08-31 07:48:27",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/116.203.31.207",
            "tags": "AS24940,C2,censys,CobaltStrike,cs-watermark-987654321,HETZNER-AS",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1570558": [
        {
            "ioc_value": "150.187.25.242:9999",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-08-17 20:01:54",
            "last_seen_utc": "2026-08-31 07:48:34",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/150.187.25.242",
            "tags": "AS20312,C2,censys,CobaltStrike,cs-watermark-987654321,Fundacion",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1569825": [
        {
            "ioc_value": "8.138.167.123:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-08-16 15:22:26",
            "last_seen_utc": "2026-08-31 08:00:27",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": "https://www.shodan.io/host/8.138.167.123#443",
            "tags": "c2,cobaltstrike,shodan",
            "anonymous": 0,
            "reporter": "juroots"
        }
    ],
    "1569780": [
        {
            "ioc_value": "119.29.231.118:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-08-16 08:01:47",
            "last_seen_utc": "2026-08-31 08:00:35",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/119.29.231.118",
            "tags": "AS45090,C2,censys,CobaltStrike,cs-watermark-666666666,TENCENT-NET-AP",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1569167": [
        {
            "ioc_value": "116.198.233.179:6666",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-08-15 21:57:45",
            "last_seen_utc": "2026-08-31 07:48:27",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": "https://www.shodan.io/host/116.198.233.179#6666",
            "tags": "c2,cobaltstrike,cs-watermark-987654321,shodan",
            "anonymous": 0,
            "reporter": "juroots"
        }
    ],
    "1568713": [
        {
            "ioc_value": "117.72.184.172:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-08-15 06:21:34",
            "last_seen_utc": "2026-08-31 08:00:47",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/117.72.184.172",
            "tags": "AS141679,C2,censys",
            "anonymous": 0,
            "reporter": "dyingbreeds_"
        }
    ],
    "1567756": [
        {
            "ioc_value": "116.198.233.179:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-08-12 20:01:25",
            "last_seen_utc": "2026-08-31 08:00:47",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/116.198.233.179",
            "tags": "AS137699,C2,censys,CHINATELECOM-JIANGSU-SUQIAN-IDC,CobaltStrike,cs-watermark-987654321",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1567668": [
        {
            "ioc_value": "62.117.98.115:8001",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2025-08-12 12:01:59",
            "last_seen_utc": "2026-08-31 07:47:32",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/62.117.98.115",
            "tags": "AS8732,C2,censys,COMCOR-AS,Mythic",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1567648": [
        {
            "ioc_value": "107.174.115.43:53",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-08-12 10:50:19",
            "last_seen_utc": "2026-08-31 07:48:24",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1567316": [
        {
            "ioc_value": "209.250.227.127:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pupy",
            "malware_alias": "Patpoopy",
            "malware_printable": "pupy",
            "first_seen_utc": "2025-08-11 20:01:43",
            "last_seen_utc": "2026-08-31 07:45:46",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/209.250.227.127",
            "tags": "AS-VULTR,AS20473,C2,censys,Pupy,RAT",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1567234": [
        {
            "ioc_value": "45.204.216.24:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-08-11 08:01:15",
            "last_seen_utc": "2026-08-31 08:00:30",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/45.204.216.24",
            "tags": "AS62468,C2,censys,CobaltStrike,cs-watermark-987654321,HKCLOUDX",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1565164": [
        {
            "ioc_value": "8.219.76.168:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-08-06 12:54:26",
            "last_seen_utc": "2026-08-31 08:00:25",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1565159": [
        {
            "ioc_value": "101.133.229.117:8443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-08-06 12:51:48",
            "last_seen_utc": "2026-08-31 07:48:21",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1564535": [
        {
            "ioc_value": "www.chinagasholdings.space",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-08-05 12:51:41",
            "last_seen_utc": "2026-08-31 07:48:20",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1564496": [
        {
            "ioc_value": "47.105.36.109:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-08-05 08:53:36",
            "last_seen_utc": "2026-08-31 08:00:30",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1564345": [
        {
            "ioc_value": "185.233.166.124:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.ransomhub",
            "malware_alias": null,
            "malware_printable": "RansomHub",
            "first_seen_utc": "2025-08-04 20:45:44",
            "last_seen_utc": "2026-08-31 07:44:49",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RansomHub",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1564346": [
        {
            "ioc_value": "185.233.166.124:9702",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.ransomhub",
            "malware_alias": null,
            "malware_printable": "RansomHub",
            "first_seen_utc": "2025-08-04 20:45:44",
            "last_seen_utc": "2026-08-31 07:44:49",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RansomHub",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1563211": [
        {
            "ioc_value": "89.197.168.150:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2025-08-01 20:01:06",
            "last_seen_utc": "2026-08-31 07:47:55",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/89.197.168.150",
            "tags": "AS47474,C2,censys,Mythic,VIRTUAL1",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1562605": [
        {
            "ioc_value": "172.233.97.159:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2025-07-30 20:01:06",
            "last_seen_utc": "2026-08-31 07:44:22",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/172.233.97.159",
            "tags": "AKAMAI-LINODE-AP,AS63949,C2,censys,Mythic",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1561181": [
        {
            "ioc_value": "117.72.181.104:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-07-27 16:00:55",
            "last_seen_utc": "2026-08-31 08:00:36",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/117.72.181.104",
            "tags": "AS141679,C2,censys,CHINATELECOM-IDC-BTHBD-AP,CobaltStrike,cs-watermark-666666",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1560617": [
        {
            "ioc_value": "47.236.130.154:53",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-07-25 10:51:18",
            "last_seen_utc": "2026-08-31 07:48:52",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1559594": [
        {
            "ioc_value": "158.255.213.22:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.ransomhub",
            "malware_alias": null,
            "malware_printable": "RansomHub",
            "first_seen_utc": "2025-07-22 20:44:22",
            "last_seen_utc": "2026-08-31 07:44:07",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RansomHub",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1559595": [
        {
            "ioc_value": "158.255.213.22:63421",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.ransomhub",
            "malware_alias": null,
            "malware_printable": "RansomHub",
            "first_seen_utc": "2025-07-22 20:44:22",
            "last_seen_utc": "2026-08-31 07:44:07",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RansomHub",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1558329": [
        {
            "ioc_value": "103.125.248.109:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-07-19 12:49:30",
            "last_seen_utc": "2026-08-31 08:00:37",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1558066": [
        {
            "ioc_value": "193.112.84.248:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-07-18 12:51:20",
            "last_seen_utc": "2026-08-31 08:00:32",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1557619": [
        {
            "ioc_value": "ns3.nsebseshop.cloud",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-07-16 22:49:04",
            "last_seen_utc": "2026-08-31 07:48:19",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1557618": [
        {
            "ioc_value": "ns2.nsebseshop.cloud",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-07-16 22:49:03",
            "last_seen_utc": "2026-08-31 07:48:19",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1557617": [
        {
            "ioc_value": "ns1.nsebseshop.cloud",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-07-16 22:49:02",
            "last_seen_utc": "2026-08-31 07:48:18",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1556749": [
        {
            "ioc_value": "118.31.18.77:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-07-14 20:45:17",
            "last_seen_utc": "2026-08-31 07:48:29",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/118.31.18.77",
            "tags": "ALIBABA-CN-NET,AS37963,C2,censys,CobaltStrike,cs-watermark-987654321",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1556099": [
        {
            "ioc_value": "51.81.171.234:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.havoc",
            "malware_alias": "Havokiz",
            "malware_printable": "Havoc",
            "first_seen_utc": "2025-07-12 00:01:36",
            "last_seen_utc": "2026-08-31 07:47:28",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/51.81.171.234",
            "tags": "AS16276,C2,censys,Havoc,OVH",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1554340": [
        {
            "ioc_value": "88.129.147.201:8080",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.deimos_c2",
            "malware_alias": null,
            "malware_printable": "DeimosC2",
            "first_seen_utc": "2025-07-07 20:54:20",
            "last_seen_utc": "2026-08-31 07:47:53",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "Deimos,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1554064": [
        {
            "ioc_value": "8.152.99.85:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-07-06 20:00:32",
            "last_seen_utc": "2026-08-31 08:00:27",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/8.152.99.85",
            "tags": "ALIBABA-CN-NET,AS37963,C2,censys,CobaltStrike,cs-watermark-666666666",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1553070": [
        {
            "ioc_value": "112.125.19.107:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-07-03 20:00:15",
            "last_seen_utc": "2026-08-31 07:48:25",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/112.125.19.107",
            "tags": "ALIBABA-CN-NET,AS37963,C2,censys,CobaltStrike,cs-watermark-1234567890",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1552208": [
        {
            "ioc_value": "146.70.87.96:43211",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2025-07-02 04:02:12",
            "last_seen_utc": "2026-08-31 07:43:51",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/146.70.87.96",
            "tags": "AdaptixC2,AS9009,C2,censys,M247",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1551843": [
        {
            "ioc_value": "38.132.122.141:43211",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2025-07-01 04:02:16",
            "last_seen_utc": "2026-08-31 07:46:55",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/38.132.122.141",
            "tags": "AdaptixC2,AS9009,C2,censys,M247",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1550785": [
        {
            "ioc_value": "43.139.50.42:53",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-06-28 10:56:20",
            "last_seen_utc": "2026-08-29 18:47:32",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1550784": [
        {
            "ioc_value": "116.205.143.204:53",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-06-28 10:54:22",
            "last_seen_utc": "2026-08-31 07:48:27",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1550783": [
        {
            "ioc_value": "dns1.globalcdn.autos",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-06-28 10:53:12",
            "last_seen_utc": "2026-08-31 07:48:17",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1550284": [
        {
            "ioc_value": "54.38.94.225:8886",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.eye_pyramid",
            "malware_alias": null,
            "malware_printable": "Eye Pyramid",
            "first_seen_utc": "2025-06-28 08:51:18",
            "last_seen_utc": "2026-08-31 07:47:30",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,EyePyramid",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1549030": [
        {
            "ioc_value": "156.227.233.153:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-06-25 04:00:19",
            "last_seen_utc": "2026-08-31 08:00:34",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/156.227.233.153",
            "tags": "AS138152,C2,censys",
            "anonymous": 0,
            "reporter": "dyingbreeds_"
        }
    ],
    "1548104": [
        {
            "ioc_value": "158.158.0.196:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2025-06-20 20:02:50",
            "last_seen_utc": "2026-08-31 07:44:06",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/158.158.0.196",
            "tags": "AS8075,C2,censys,MICROSOFT-CORP-MSN-AS-BLOCK,Mythic",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1547925": [
        {
            "ioc_value": "82.156.156.160:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-06-20 06:01:32",
            "last_seen_utc": "2026-08-31 08:00:26",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-666666666",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1546420": [
        {
            "ioc_value": "158.158.0.196:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2025-06-19 00:02:44",
            "last_seen_utc": "2026-08-31 07:44:06",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/158.158.0.196",
            "tags": "AS8075,C2,censys,MICROSOFT-CORP-MSN-AS-BLOCK,Mythic",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1546246": [
        {
            "ioc_value": "191.93.118.254:9000",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2025-06-18 08:02:37",
            "last_seen_utc": "2026-08-31 07:45:02",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://bazaar.abuse.ch/sample/9265a6e0b26a240f1f8bffddf3b36d0e533919d0c894bd66839a90e351961464/",
            "tags": "AsyncRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1546232": [
        {
            "ioc_value": "191.93.118.254:8848",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2025-06-18 07:58:54",
            "last_seen_utc": "2026-08-31 07:45:01",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://bazaar.abuse.ch/sample/6ecbf71d231e9b9e7459b97c97d94aed467481b5b4f22af288bbaea5945c1af4/",
            "tags": "AsyncRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1545615": [
        {
            "ioc_value": "8.147.128.54:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-06-17 03:12:25",
            "last_seen_utc": "2026-08-31 08:00:27",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1545348": [
        {
            "ioc_value": "8.137.149.67:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-06-16 12:01:46",
            "last_seen_utc": "2026-08-31 07:48:56",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/8.137.149.67",
            "tags": "ALIBABA-CN-NET,AS37963,C2,censys,CobaltStrike,cs-watermark-987654321",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1544612": [
        {
            "ioc_value": "47.109.48.57:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-06-13 20:01:30",
            "last_seen_utc": "2026-08-31 08:00:29",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/47.109.48.57",
            "tags": "ALIBABA-CN-NET,AS37963,C2,censys,CobaltStrike,cs-watermark-987654321",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1544039": [
        {
            "ioc_value": "39.104.78.25:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-06-12 08:56:19",
            "last_seen_utc": "2026-08-31 08:00:31",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/39.104.78.25",
            "tags": "AS37963,C2,censys",
            "anonymous": 0,
            "reporter": "dyingbreeds_"
        }
    ],
    "1543390": [
        {
            "ioc_value": "8.155.0.238:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-06-10 16:01:13",
            "last_seen_utc": "2026-08-31 08:00:26",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/8.155.0.238",
            "tags": "ALIBABA-CN-NET,AS37963,C2,censys,CobaltStrike,cs-watermark-987654321",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1542804": [
        {
            "ioc_value": "23.227.203.191:43211",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2025-06-08 21:18:37",
            "last_seen_utc": "2026-08-31 07:46:40",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/23.227.203.191",
            "tags": "AdaptixC2,AS29802,C2,censys,HVC-AS",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1542784": [
        {
            "ioc_value": "162.248.224.223:7882",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.ransomhub",
            "malware_alias": null,
            "malware_printable": "RansomHub",
            "first_seen_utc": "2025-06-08 20:45:49",
            "last_seen_utc": "2026-08-31 07:44:12",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RansomHub",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1542783": [
        {
            "ioc_value": "162.248.224.223:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.ransomhub",
            "malware_alias": null,
            "malware_printable": "RansomHub",
            "first_seen_utc": "2025-06-08 20:45:48",
            "last_seen_utc": "2026-08-31 07:44:12",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RansomHub",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1542759": [
        {
            "ioc_value": "119.45.29.172:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-06-08 20:01:01",
            "last_seen_utc": "2026-08-31 08:00:46",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/119.45.29.172",
            "tags": "AS45090,C2,censys,CobaltStrike,cs-watermark-987654321,TENCENT-NET-AP",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1541652": [
        {
            "ioc_value": "68.64.176.42:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-06-06 16:00:50",
            "last_seen_utc": "2026-08-31 08:00:28",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/68.64.176.42",
            "tags": "AS139659,C2,censys,CobaltStrike,cs-watermark-391144938,LUCID-AS-AP",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1538881": [
        {
            "ioc_value": "193.239.85.15:2083",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.havoc",
            "malware_alias": "Havokiz",
            "malware_printable": "Havoc",
            "first_seen_utc": "2025-06-02 12:01:04",
            "last_seen_utc": "2026-08-31 07:45:14",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/193.239.85.15",
            "tags": "AS9009,C2,censys,Havoc,M247",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1538799": [
        {
            "ioc_value": "47.109.198.8:6000",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-06-02 05:47:28",
            "last_seen_utc": "2026-08-31 07:48:51",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": "https://www.shodan.io/host/47.109.198.8#6000",
            "tags": "c2,cobaltstrike,cs-watermark-987654321,shodan",
            "anonymous": 0,
            "reporter": "juroots"
        }
    ],
    "1538358": [
        {
            "ioc_value": "54.38.94.225:8885",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.eye_pyramid",
            "malware_alias": null,
            "malware_printable": "Eye Pyramid",
            "first_seen_utc": "2025-06-01 08:52:56",
            "last_seen_utc": "2026-08-31 07:47:30",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,EyePyramid",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1537676": [
        {
            "ioc_value": "101.43.91.156:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-05-31 07:45:39",
            "last_seen_utc": "2026-08-31 08:00:48",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://x.com/abodovic1",
            "tags": "c2,censys,CobaltStrike",
            "anonymous": 0,
            "reporter": "Abodovic"
        }
    ],
    "1537678": [
        {
            "ioc_value": "59.110.7.32:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-05-31 07:45:38",
            "last_seen_utc": "2026-08-31 08:00:39",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://x.com/abodovic1",
            "tags": "c2,censys,CobaltStrike",
            "anonymous": 0,
            "reporter": "Abodovic"
        }
    ],
    "1536850": [
        {
            "ioc_value": "99.112.198.249:8080",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.deimos_c2",
            "malware_alias": null,
            "malware_printable": "DeimosC2",
            "first_seen_utc": "2025-05-30 08:53:21",
            "last_seen_utc": "2026-08-31 07:48:12",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "Deimos,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1536831": [
        {
            "ioc_value": "129.28.85.210:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-05-30 08:00:11",
            "last_seen_utc": "2026-08-31 08:00:35",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/129.28.85.210",
            "tags": "AS45090,C2,censys,CobaltStrike,cs-watermark-666666666,TENCENT-NET-AP",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1536730": [
        {
            "ioc_value": "111.229.4.108:2096",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-05-30 02:55:17",
            "last_seen_utc": "2026-08-31 07:48:25",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1536683": [
        {
            "ioc_value": "161.35.176.231:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.havoc",
            "malware_alias": "Havokiz",
            "malware_printable": "Havoc",
            "first_seen_utc": "2025-05-29 22:26:34",
            "last_seen_utc": "2026-08-31 07:44:11",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/161.35.176.231",
            "tags": "AS14061,C2,censys,DIGITALOCEAN-ASN,Havoc",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1534703": [
        {
            "ioc_value": "38.54.23.241:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pupy",
            "malware_alias": "Patpoopy",
            "malware_printable": "pupy",
            "first_seen_utc": "2025-05-26 06:29:51",
            "last_seen_utc": "2026-08-31 07:46:58",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/38.54.23.241",
            "tags": "AS138915,C2,censys,KAOPU-HK,Pupy,RAT",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1533613": [
        {
            "ioc_value": "221.132.29.137:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2025-05-24 20:01:31",
            "last_seen_utc": "2026-08-31 07:46:38",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/221.132.29.137",
            "tags": "AS45899,C2,censys,Mythic,VNPT-AS-VN",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1533071": [
        {
            "ioc_value": "1.15.174.189:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-05-24 11:13:44",
            "last_seen_utc": "2026-08-31 08:00:37",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://x.com/abodovic1",
            "tags": "c2,censys,CobaltStrike",
            "anonymous": 0,
            "reporter": "Abodovic"
        }
    ],
    "1532332": [
        {
            "ioc_value": "8.140.239.162:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-05-23 05:34:51",
            "last_seen_utc": "2026-08-31 08:00:39",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://x.com/abodovic1",
            "tags": "c2,censys,CobaltStrike",
            "anonymous": 0,
            "reporter": "Abodovic"
        }
    ],
    "1527752": [
        {
            "ioc_value": "117.72.206.39:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-05-21 08:00:35",
            "last_seen_utc": "2026-08-31 08:00:47",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/117.72.206.39",
            "tags": "AS141679,C2,censys,CHINATELECOM-IDC-BTHBD-AP,CobaltStrike,cs-watermark-666666666",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1526357": [
        {
            "ioc_value": "106.54.61.188:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-05-20 06:37:42",
            "last_seen_utc": "2026-08-31 08:00:36",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-987654321",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1525250": [
        {
            "ioc_value": "124.223.114.203:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-05-18 15:34:22",
            "last_seen_utc": "2026-08-31 08:00:35",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://intelinsights.substack.com/p/from-939-to-85-hunting-cobalt-strike",
            "tags": "censys,cobaltstrike",
            "anonymous": 0,
            "reporter": "orlof_v"
        }
    ],
    "1524773": [
        {
            "ioc_value": "167.99.51.2:31337",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.sliver",
            "malware_alias": null,
            "malware_printable": "Sliver",
            "first_seen_utc": "2025-05-17 14:42:08",
            "last_seen_utc": "2026-08-31 07:44:16",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": "https://www.shodan.io/host/167.99.51.2#31337",
            "tags": "c2,shodan,sliver",
            "anonymous": 0,
            "reporter": "juroots"
        }
    ],
    "1524641": [
        {
            "ioc_value": "167.99.51.2:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.sliver",
            "malware_alias": null,
            "malware_printable": "Sliver",
            "first_seen_utc": "2025-05-17 08:00:32",
            "last_seen_utc": "2026-08-31 07:44:17",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/167.99.51.2",
            "tags": "AS14061,C2,censys,DIGITALOCEAN-ASN,Sliver",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1524319": [
        {
            "ioc_value": "101.35.109.246:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-05-17 06:26:23",
            "last_seen_utc": "2026-08-31 08:00:37",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": "https://www.shodan.io/host/101.35.109.246#443",
            "tags": "c2,cobaltstrike,cs-watermark-987654321,shodan",
            "anonymous": 0,
            "reporter": "juroots"
        }
    ],
    "1523466": [
        {
            "ioc_value": "103.171.35.26:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-05-15 21:14:57",
            "last_seen_utc": "2026-08-31 08:00:37",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://x.com/abodovic1",
            "tags": "c2,censys,cobalt_strike",
            "anonymous": 0,
            "reporter": "Abodovic"
        }
    ],
    "1523462": [
        {
            "ioc_value": "60.204.169.16:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-05-15 21:14:47",
            "last_seen_utc": "2026-08-31 08:00:39",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://x.com/abodovic1",
            "tags": "c2,censys,cobalt_strike",
            "anonymous": 0,
            "reporter": "Abodovic"
        }
    ],
    "1523434": [
        {
            "ioc_value": "179.43.186.223:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-05-15 21:13:56",
            "last_seen_utc": "2026-08-31 08:00:33",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://x.com/abodovic1",
            "tags": "c2,censys,cobalt_strike",
            "anonymous": 0,
            "reporter": "Abodovic"
        }
    ],
    "1523280": [
        {
            "ioc_value": "45.133.180.138:6432",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2025-05-15 06:10:52",
            "last_seen_utc": "2026-08-31 07:47:07",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://bazaar.abuse.ch/sample/b6185d4054c5a08141db4c3fb5e43369ea21af5892d8ba47628e23f37f79250d/",
            "tags": "asyncrat",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1520343": [
        {
            "ioc_value": "38.54.112.234:53",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-05-12 20:58:42",
            "last_seen_utc": "2026-08-31 07:48:46",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1520342": [
        {
            "ioc_value": "asusupdateserver.asuscomm.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-05-12 20:55:40",
            "last_seen_utc": "2026-08-31 07:48:14",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1519438": [
        {
            "ioc_value": "47.109.190.151:60000",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2025-05-11 06:11:06",
            "last_seen_utc": "2026-08-31 07:47:24",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/47.109.190.151",
            "tags": "AS37963,censys,Viper",
            "anonymous": 0,
            "reporter": "dyingbreeds_"
        }
    ],
    "1519451": [
        {
            "ioc_value": "https://lofiramegi.com/test/",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.latrodectus",
            "malware_alias": "BLACKWIDOW,IceNova,Latrodectus,Lotus",
            "malware_printable": "Latrodectus",
            "first_seen_utc": "2025-05-11 05:00:18",
            "last_seen_utc": "2026-08-31 08:14:11",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": null,
            "anonymous": 0,
            "reporter": "Rony"
        }
    ],
    "1519450": [
        {
            "ioc_value": "https://topguningit.com/test/",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.latrodectus",
            "malware_alias": "BLACKWIDOW,IceNova,Latrodectus,Lotus",
            "malware_printable": "Latrodectus",
            "first_seen_utc": "2025-05-11 05:00:17",
            "last_seen_utc": "2026-08-31 08:04:08",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": null,
            "anonymous": 0,
            "reporter": "Rony"
        }
    ],
    "1518529": [
        {
            "ioc_value": "47.108.140.10:60000",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2025-05-09 05:36:03",
            "last_seen_utc": "2026-08-31 07:47:24",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/47.108.140.10",
            "tags": "AS37963,censys,Viper",
            "anonymous": 0,
            "reporter": "dyingbreeds_"
        }
    ],
    "1518023": [
        {
            "ioc_value": "106.52.207.50:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-05-07 13:00:19",
            "last_seen_utc": "2026-08-31 07:48:24",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1513590": [
        {
            "ioc_value": "54.38.94.225:8882",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.eye_pyramid",
            "malware_alias": null,
            "malware_printable": "Eye Pyramid",
            "first_seen_utc": "2025-04-29 08:53:29",
            "last_seen_utc": "2026-08-31 07:47:30",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,EyePyramid",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1513585": [
        {
            "ioc_value": "107.143.144.154:8080",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.deimos_c2",
            "malware_alias": null,
            "malware_printable": "DeimosC2",
            "first_seen_utc": "2025-04-29 08:43:42",
            "last_seen_utc": "2026-08-31 07:43:21",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "Deimos,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1511917": [
        {
            "ioc_value": "181.206.158.190:1000",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.dcrat",
            "malware_alias": "DarkCrystal RAT",
            "malware_printable": "DCRat",
            "first_seen_utc": "2025-04-26 20:01:51",
            "last_seen_utc": "2026-08-31 07:44:38",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/181.206.158.190",
            "tags": "AS27831,C2,censys,Colombia,DcRAT,RAT",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1509966": [
        {
            "ioc_value": "167.71.13.103:31337",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.sliver",
            "malware_alias": null,
            "malware_printable": "Sliver",
            "first_seen_utc": "2025-04-22 12:21:47",
            "last_seen_utc": "2026-08-31 07:44:16",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": "https://www.shodan.io/host/167.71.13.103#31337",
            "tags": "c2,shodan,sliver",
            "anonymous": 0,
            "reporter": "juroots"
        }
    ],
    "1493521": [
        {
            "ioc_value": "77.73.129.82:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2025-04-18 08:02:32",
            "last_seen_utc": "2026-08-31 07:47:41",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/77.73.129.82",
            "tags": "AS201814,C2,censys,MEVSPACE,Mythic",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1492480": [
        {
            "ioc_value": "113.45.253.80:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-04-16 16:01:35",
            "last_seen_utc": "2026-08-31 07:48:26",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/113.45.253.80",
            "tags": "AS55990,C2,censys,CobaltStrike,cs-watermark-666666666,HWCSNET",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1492012": [
        {
            "ioc_value": "47.83.134.97:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.havoc",
            "malware_alias": "Havokiz",
            "malware_printable": "Havoc",
            "first_seen_utc": "2025-04-15 16:02:30",
            "last_seen_utc": "2026-08-31 07:47:24",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/47.83.134.97",
            "tags": "ALIBABA-CN-NET,AS45102,C2,censys,Havoc",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1486437": [
        {
            "ioc_value": "167.71.13.103:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.sliver",
            "malware_alias": null,
            "malware_printable": "Sliver",
            "first_seen_utc": "2025-04-10 05:55:49",
            "last_seen_utc": "2026-08-31 07:44:16",
            "confidence_level": 90,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/167.71.13.103",
            "tags": "AS14061,C2,censys,DIGITALOCEAN-ASN",
            "anonymous": 0,
            "reporter": "dyingbreeds_"
        }
    ],
    "1463173": [
        {
            "ioc_value": "38.46.218.36:9999",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "apk.vo1d",
            "malware_alias": null,
            "malware_printable": "vo1d",
            "first_seen_utc": "2025-04-02 10:08:14",
            "last_seen_utc": "2026-08-31 07:19:55",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "Vo1d",
            "anonymous": 0,
            "reporter": "Bitsight"
        }
    ],
    "1463174": [
        {
            "ioc_value": "38.46.218.38:9999",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "apk.vo1d",
            "malware_alias": null,
            "malware_printable": "vo1d",
            "first_seen_utc": "2025-04-02 10:08:13",
            "last_seen_utc": "2026-08-31 06:19:53",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "Vo1d",
            "anonymous": 0,
            "reporter": "Bitsight"
        }
    ],
    "1463176": [
        {
            "ioc_value": "38.46.218.39:9999",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "apk.vo1d",
            "malware_alias": null,
            "malware_printable": "vo1d",
            "first_seen_utc": "2025-04-02 10:08:12",
            "last_seen_utc": "2026-08-31 07:50:56",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "Vo1d",
            "anonymous": 0,
            "reporter": "Bitsight"
        }
    ],
    "1463152": [
        {
            "ioc_value": "200.107.126.227:3085",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.netsupportmanager_rat",
            "malware_alias": "NetSupport",
            "malware_printable": "NetSupportManager RAT",
            "first_seen_utc": "2025-04-02 08:01:26",
            "last_seen_utc": "2026-08-31 07:45:39",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/200.107.126.227",
            "tags": "AS14754,C2,censys,Netsupport,RAT,TELECOMUNICACIONES",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1462468": [
        {
            "ioc_value": "43.143.229.126:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-04-01 10:24:30",
            "last_seen_utc": "2026-08-31 08:00:31",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-666666666",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1458716": [
        {
            "ioc_value": "ehchq7m7rpvdr.cfc-execute.bj.baidubce.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-03-25 22:53:24",
            "last_seen_utc": "2026-08-31 08:00:26",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1457513": [
        {
            "ioc_value": "103.142.147.17:60000",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2025-03-24 06:29:33",
            "last_seen_utc": "2026-08-31 07:43:06",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/103.142.147.17",
            "tags": "AS135581,censys,Viper",
            "anonymous": 0,
            "reporter": "dyingbreeds_"
        }
    ],
    "1454148": [
        {
            "ioc_value": "103.142.147.18:60000",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2025-03-22 20:43:16",
            "last_seen_utc": "2026-08-31 07:43:07",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1454149": [
        {
            "ioc_value": "103.142.147.19:60000",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2025-03-22 20:43:16",
            "last_seen_utc": "2026-08-31 07:43:07",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1452404": [
        {
            "ioc_value": "47.116.208.81:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-03-20 12:01:27",
            "last_seen_utc": "2026-08-31 08:00:41",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/47.116.208.81",
            "tags": "ALIBABA-CN-NET,AS37963,C2,censys,CobaltStrike,cs-watermark-666666666",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1446559": [
        {
            "ioc_value": "www.dyshop.online",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-03-12 02:47:28",
            "last_seen_utc": "2026-08-31 07:48:20",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1446149": [
        {
            "ioc_value": "210.2.169.213:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.havoc",
            "malware_alias": "Havokiz",
            "malware_printable": "Havoc",
            "first_seen_utc": "2025-03-11 12:01:13",
            "last_seen_utc": "2026-08-31 07:45:49",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/210.2.169.213",
            "tags": "AS23966,C2,censys,Havoc,LDN-AS-PK",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1444156": [
        {
            "ioc_value": "47.100.16.83:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-03-09 04:00:17",
            "last_seen_utc": "2026-08-31 07:48:50",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/47.100.16.83",
            "tags": "ALIBABA-CN-NET,AS37963,C2,censys,CobaltStrike,cs-watermark-391144938",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1441769": [
        {
            "ioc_value": "51.81.171.234:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.havoc",
            "malware_alias": "Havokiz",
            "malware_printable": "Havoc",
            "first_seen_utc": "2025-03-06 04:01:35",
            "last_seen_utc": "2026-08-31 07:47:28",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/51.81.171.234",
            "tags": "AS16276,C2,censys,Havoc,OVH",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1440087": [
        {
            "ioc_value": "15.204.95.228:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.havoc",
            "malware_alias": "Havokiz",
            "malware_printable": "Havoc",
            "first_seen_utc": "2025-03-03 12:01:16",
            "last_seen_utc": "2026-08-31 07:43:53",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/15.204.95.228",
            "tags": "AS16276,C2,censys,Havoc,OVH",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1439776": [
        {
            "ioc_value": "150.5.174.231:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2025-03-02 20:01:03",
            "last_seen_utc": "2026-08-31 07:43:53",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/150.5.174.231",
            "tags": "AS150436,BYTEPLUS-AS-AP,C2,censys,Mythic",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1439368": [
        {
            "ioc_value": "54.38.94.225:8887",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.eye_pyramid",
            "malware_alias": null,
            "malware_printable": "Eye Pyramid",
            "first_seen_utc": "2025-03-02 08:46:23",
            "last_seen_utc": "2026-08-31 07:47:30",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,EyePyramid",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1439168": [
        {
            "ioc_value": "47.129.171.26:53",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-03-01 20:47:46",
            "last_seen_utc": "2026-08-31 07:48:52",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1439166": [
        {
            "ioc_value": "ns.1.3.0o0.foo",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-03-01 20:46:51",
            "last_seen_utc": "2026-08-31 07:48:18",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1439167": [
        {
            "ioc_value": "ns.1.4.0o0.foo",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-03-01 20:46:51",
            "last_seen_utc": "2026-08-31 07:48:18",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1414853": [
        {
            "ioc_value": "54.95.208.190:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.havoc",
            "malware_alias": "Havokiz",
            "malware_printable": "Havoc",
            "first_seen_utc": "2025-02-19 04:01:34",
            "last_seen_utc": "2026-08-31 07:47:31",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/54.95.208.190",
            "tags": "AMAZON-02,AS16509,C2,censys,Havoc",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1411885": [
        {
            "ioc_value": "192.52.167.140:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.netsupportmanager_rat",
            "malware_alias": "NetSupport",
            "malware_printable": "NetSupportManager RAT",
            "first_seen_utc": "2025-02-14 00:01:07",
            "last_seen_utc": "2026-08-31 07:45:11",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/192.52.167.140",
            "tags": "AS199959,C2,censys,CROWNCLOUD,Netsupport,RAT",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1409420": [
        {
            "ioc_value": "103.215.81.156:60000",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2025-02-10 20:43:10",
            "last_seen_utc": "2026-08-31 07:43:09",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1405307": [
        {
            "ioc_value": "https://apworsindos.com/test/",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.latrodectus",
            "malware_alias": "BLACKWIDOW,IceNova,Latrodectus,Lotus",
            "malware_printable": "Latrodectus",
            "first_seen_utc": "2025-02-06 13:54:51",
            "last_seen_utc": "2026-08-31 08:07:06",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": null,
            "anonymous": 0,
            "reporter": "Rony"
        }
    ],
    "1405308": [
        {
            "ioc_value": "https://reminasolirol.com/test/",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.latrodectus",
            "malware_alias": "BLACKWIDOW,IceNova,Latrodectus,Lotus",
            "malware_printable": "Latrodectus",
            "first_seen_utc": "2025-02-06 13:54:51",
            "last_seen_utc": "2026-08-31 07:56:26",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": null,
            "anonymous": 0,
            "reporter": "Rony"
        }
    ],
    "1404178": [
        {
            "ioc_value": "20.74.209.192:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-02-05 22:51:06",
            "last_seen_utc": "2026-08-31 08:00:32",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1402480": [
        {
            "ioc_value": "service-rchqbzvz-1301033415.sh.tencentapigw.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-02-02 12:49:35",
            "last_seen_utc": "2026-08-31 08:00:26",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1402273": [
        {
            "ioc_value": "https://vivaforevew.com/test/",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.latrodectus",
            "malware_alias": "BLACKWIDOW,IceNova,Latrodectus,Lotus",
            "malware_printable": "Latrodectus",
            "first_seen_utc": "2025-02-01 20:47:38",
            "last_seen_utc": "2026-08-31 08:00:54",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": null,
            "anonymous": 0,
            "reporter": "Rony"
        }
    ],
    "1402274": [
        {
            "ioc_value": "https://wersogkiwgow.com/test/",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.latrodectus",
            "malware_alias": "BLACKWIDOW,IceNova,Latrodectus,Lotus",
            "malware_printable": "Latrodectus",
            "first_seen_utc": "2025-02-01 20:47:38",
            "last_seen_utc": "2026-08-31 08:08:57",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": null,
            "anonymous": 0,
            "reporter": "Rony"
        }
    ],
    "1398820": [
        {
            "ioc_value": "162.252.173.12:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.ransomhub",
            "malware_alias": null,
            "malware_printable": "RansomHub",
            "first_seen_utc": "2025-01-31 13:44:30",
            "last_seen_utc": "2026-08-31 07:44:12",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RansomHub",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1398810": [
        {
            "ioc_value": "162.252.173.12:8000",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.ransomhub",
            "malware_alias": null,
            "malware_printable": "RansomHub",
            "first_seen_utc": "2025-01-31 12:01:38",
            "last_seen_utc": "2026-08-31 07:44:12",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/162.252.173.12",
            "tags": "AS9009,backdoor,C2,censys,M247,Ransomhub",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1398657": [
        {
            "ioc_value": "8.134.108.73:60000",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2025-01-31 07:01:30",
            "last_seen_utc": "2026-08-31 07:47:42",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/8.134.108.73",
            "tags": "AS37963,censys,Viper",
            "anonymous": 0,
            "reporter": "dyingbreeds_"
        }
    ],
    "1396136": [
        {
            "ioc_value": "38.146.28.93:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.ransomhub",
            "malware_alias": null,
            "malware_printable": "RansomHub",
            "first_seen_utc": "2025-01-30 08:47:19",
            "last_seen_utc": "2026-08-31 07:46:55",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RansomHub",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1396135": [
        {
            "ioc_value": "185.33.86.15:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.ransomhub",
            "malware_alias": null,
            "malware_printable": "RansomHub",
            "first_seen_utc": "2025-01-30 08:45:48",
            "last_seen_utc": "2026-08-31 07:44:51",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RansomHub",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1396130": [
        {
            "ioc_value": "38.146.28.93:8000",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.ransomhub",
            "malware_alias": null,
            "malware_printable": "RansomHub",
            "first_seen_utc": "2025-01-30 08:01:38",
            "last_seen_utc": "2026-08-31 07:46:55",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/38.146.28.93",
            "tags": "AS174,backdoor,C2,censys,COGENT-174,Ransomhub",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1396102": [
        {
            "ioc_value": "185.33.86.15:8000",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.ransomhub",
            "malware_alias": null,
            "malware_printable": "RansomHub",
            "first_seen_utc": "2025-01-30 04:01:31",
            "last_seen_utc": "2026-08-31 07:44:51",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/185.33.86.15",
            "tags": "AS202015,backdoor,C2,censys,HZ-US-AS,Ransomhub",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1394408": [
        {
            "ioc_value": "54.38.94.225:8883",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.eye_pyramid",
            "malware_alias": null,
            "malware_printable": "Eye Pyramid",
            "first_seen_utc": "2025-01-26 08:46:00",
            "last_seen_utc": "2026-08-31 07:47:30",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,EyePyramid",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1394158": [
        {
            "ioc_value": "54.38.94.225:8880",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.eye_pyramid",
            "malware_alias": null,
            "malware_printable": "Eye Pyramid",
            "first_seen_utc": "2025-01-25 20:47:04",
            "last_seen_utc": "2026-08-31 07:47:29",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,EyePyramid",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1391610": [
        {
            "ioc_value": "45.82.85.50:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.ransomhub",
            "malware_alias": null,
            "malware_printable": "RansomHub",
            "first_seen_utc": "2025-01-22 17:46:05",
            "last_seen_utc": "2026-08-31 07:47:18",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RansomHub",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1386236": [
        {
            "ioc_value": "https://135.181.31.18",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2025-01-18 16:10:00",
            "last_seen_utc": "2026-08-31 08:10:36",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": null,
            "anonymous": 0,
            "reporter": "Gi7w0rm"
        }
    ],
    "1384921": [
        {
            "ioc_value": "167.99.139.231:8004",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.eye_pyramid",
            "malware_alias": null,
            "malware_printable": "Eye Pyramid",
            "first_seen_utc": "2025-01-17 09:14:13",
            "last_seen_utc": "2026-08-31 07:44:16",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,EyePyramid",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1384912": [
        {
            "ioc_value": "185.174.101.240:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.ransomhub",
            "malware_alias": null,
            "malware_printable": "RansomHub",
            "first_seen_utc": "2025-01-17 09:13:19",
            "last_seen_utc": "2026-08-31 07:44:42",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RansomHub",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1384913": [
        {
            "ioc_value": "185.174.101.240:8000",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.ransomhub",
            "malware_alias": null,
            "malware_printable": "RansomHub",
            "first_seen_utc": "2025-01-17 09:13:19",
            "last_seen_utc": "2026-08-31 07:44:42",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RansomHub",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1384914": [
        {
            "ioc_value": "185.174.101.69:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.ransomhub",
            "malware_alias": null,
            "malware_printable": "RansomHub",
            "first_seen_utc": "2025-01-17 09:13:19",
            "last_seen_utc": "2026-08-31 07:44:43",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RansomHub",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1384915": [
        {
            "ioc_value": "185.174.101.69:8000",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.ransomhub",
            "malware_alias": null,
            "malware_printable": "RansomHub",
            "first_seen_utc": "2025-01-17 09:13:19",
            "last_seen_utc": "2026-08-31 07:44:43",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RansomHub",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1384910": [
        {
            "ioc_value": "108.181.182.143:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.ransomhub",
            "malware_alias": null,
            "malware_printable": "RansomHub",
            "first_seen_utc": "2025-01-17 09:12:27",
            "last_seen_utc": "2026-08-31 07:43:25",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RansomHub",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1384911": [
        {
            "ioc_value": "108.181.182.143:8000",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.ransomhub",
            "malware_alias": null,
            "malware_printable": "RansomHub",
            "first_seen_utc": "2025-01-17 09:12:27",
            "last_seen_utc": "2026-08-31 07:43:25",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RansomHub",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1384790": [
        {
            "ioc_value": "at1.227api.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-01-17 07:45:55",
            "last_seen_utc": "2026-08-31 07:48:14",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1384791": [
        {
            "ioc_value": "at2.227api.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-01-17 07:45:55",
            "last_seen_utc": "2026-08-31 07:48:14",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1384792": [
        {
            "ioc_value": "at3.227api.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-01-17 07:45:55",
            "last_seen_utc": "2026-08-31 07:48:14",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1381420": [
        {
            "ioc_value": "77.238.236.123:18300",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.deimos_c2",
            "malware_alias": null,
            "malware_printable": "DeimosC2",
            "first_seen_utc": "2025-01-10 13:55:47",
            "last_seen_utc": "2026-08-31 07:47:41",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "Deimos,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1381067": [
        {
            "ioc_value": "112.5.58.181:7001",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.deimos_c2",
            "malware_alias": null,
            "malware_printable": "DeimosC2",
            "first_seen_utc": "2025-01-10 13:43:51",
            "last_seen_utc": "2026-08-31 07:43:30",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "Deimos,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1380875": [
        {
            "ioc_value": "update.mloadspring.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-01-10 09:14:38",
            "last_seen_utc": "2026-08-31 07:48:20",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1380878": [
        {
            "ioc_value": "upgrade.mloadspring.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-01-10 09:14:38",
            "last_seen_utc": "2026-08-31 07:48:20",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1380837": [
        {
            "ioc_value": "ns3.akawowfast.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-01-10 09:14:30",
            "last_seen_utc": "2026-08-31 07:48:19",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1380818": [
        {
            "ioc_value": "ns2.cmbchina.top",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-01-10 09:14:27",
            "last_seen_utc": "2026-08-31 07:48:19",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1380815": [
        {
            "ioc_value": "ns2.akawowfast.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-01-10 09:14:26",
            "last_seen_utc": "2026-08-31 07:48:19",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1380783": [
        {
            "ioc_value": "ns1.akawowfast.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-01-10 09:14:20",
            "last_seen_utc": "2026-08-31 07:48:18",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1380787": [
        {
            "ioc_value": "ns1.cmbchina.top",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-01-10 09:14:20",
            "last_seen_utc": "2026-08-31 07:48:18",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1380635": [
        {
            "ioc_value": "8.219.78.159:53",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-01-10 08:18:57",
            "last_seen_utc": "2026-08-31 07:48:57",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1380629": [
        {
            "ioc_value": "70.34.196.238:53",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-01-10 08:18:43",
            "last_seen_utc": "2026-08-31 07:48:55",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1380607": [
        {
            "ioc_value": "47.98.134.252:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-01-10 08:18:28",
            "last_seen_utc": "2026-08-31 08:00:29",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1380446": [
        {
            "ioc_value": "139.180.189.95:53",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-01-10 08:16:21",
            "last_seen_utc": "2026-08-31 07:48:33",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1380421": [
        {
            "ioc_value": "118.25.91.151:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-01-10 08:15:44",
            "last_seen_utc": "2026-08-31 08:00:46",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1380420": [
        {
            "ioc_value": "117.72.39.83:43872",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-01-10 08:15:43",
            "last_seen_utc": "2026-08-31 07:48:29",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1376919": [
        {
            "ioc_value": "86.124.168.255:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "js.fakeupdates",
            "malware_alias": "FakeUpdate,GhoLoader,SocGholish",
            "malware_printable": "FAKEUPDATES",
            "first_seen_utc": "2025-01-01 04:03:19",
            "last_seen_utc": "2026-08-31 07:47:51",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/86.124.168.255",
            "tags": "AS8708,c2,censys,RCS-RDS,SocGholish",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1359629": [
        {
            "ioc_value": "https://95.217.241.133/",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2024-12-25 14:55:36",
            "last_seen_utc": "2026-08-31 08:11:18",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "Vidar",
            "anonymous": 0,
            "reporter": "crep1x"
        }
    ],
    "1359401": [
        {
            "ioc_value": "8.153.97.202:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2024-12-24 08:00:43",
            "last_seen_utc": "2026-08-31 08:00:24",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/8.153.97.202",
            "tags": "ALIBABA-CN-NET,AS37963,C2,censys,CobaltStrike,cs-watermark-987654321",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1359309": [
        {
            "ioc_value": "91.199.154.103:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.sliver",
            "malware_alias": null,
            "malware_printable": "Sliver",
            "first_seen_utc": "2024-12-24 04:01:34",
            "last_seen_utc": "2026-08-31 07:47:57",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/91.199.154.103",
            "tags": "AS62212,C2,censys,Sliver",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1359295": [
        {
            "ioc_value": "54.95.208.190:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.havoc",
            "malware_alias": "Havokiz",
            "malware_printable": "Havoc",
            "first_seen_utc": "2024-12-24 00:02:17",
            "last_seen_utc": "2026-08-31 07:47:31",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/54.95.208.190",
            "tags": "AMAZON-02,AS16509,C2,censys,Havoc",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1358842": [
        {
            "ioc_value": "149.28.61.158:8773",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2024-12-20 16:01:53",
            "last_seen_utc": "2026-08-31 07:43:53",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/149.28.61.158",
            "tags": "AS-VULTR,AS20473,C2,censys,Mythic",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1357646": [
        {
            "ioc_value": "https://t.me/k04ael",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2024-12-18 07:45:25",
            "last_seen_utc": "2026-08-30 14:40:21",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "Vidar",
            "anonymous": 0,
            "reporter": "crep1x"
        }
    ],
    "1357645": [
        {
            "ioc_value": "https://steamcommunity.com/profiles/76561199809363512",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2024-12-18 07:45:23",
            "last_seen_utc": "2026-08-30 14:40:20",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "Vidar",
            "anonymous": 0,
            "reporter": "crep1x"
        }
    ],
    "1357389": [
        {
            "ioc_value": "45.56.69.210:3333",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2024-12-16 16:01:41",
            "last_seen_utc": "2026-08-31 07:47:14",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/45.56.69.210",
            "tags": "AKAMAI-LINODE-AP,AS63949,censys,EvilGoPhish,panel,Phishing",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1357028": [
        {
            "ioc_value": "102.117.172.98:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2024-12-15 08:01:25",
            "last_seen_utc": "2026-08-31 07:43:05",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/102.117.172.98",
            "tags": "AS23889,C2,censys,MauritiusTelecom,Mythic",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1356002": [
        {
            "ioc_value": "113.44.90.0:60000",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2024-12-12 06:21:40",
            "last_seen_utc": "2026-08-31 07:43:31",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/113.44.90.0",
            "tags": "AS55990,censys,Viper",
            "anonymous": 0,
            "reporter": "dyingbreeds_"
        }
    ],
    "1352876": [
        {
            "ioc_value": "139.196.126.161:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2024-12-06 07:36:52",
            "last_seen_utc": "2026-08-31 08:00:45",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-987654321",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1350210": [
        {
            "ioc_value": "117.72.39.83:4433",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2024-12-02 21:01:15",
            "last_seen_utc": "2026-08-31 07:48:29",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/117.72.39.83",
            "tags": "AS141679,C2,censys",
            "anonymous": 0,
            "reporter": "dyingbreeds_"
        }
    ],
    "1349957": [
        {
            "ioc_value": "117.72.39.83:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2024-12-01 07:43:42",
            "last_seen_utc": "2026-08-31 07:48:29",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-391144938",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1349567": [
        {
            "ioc_value": "216.118.101.24:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2024-11-30 20:06:19",
            "last_seen_utc": "2026-08-31 07:46:17",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "censys,panel,Viper",
            "anonymous": 0,
            "reporter": "NDA0E"
        }
    ],
    "1349531": [
        {
            "ioc_value": "216.118.101.132:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2024-11-30 20:06:11",
            "last_seen_utc": "2026-08-31 07:45:57",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "censys,panel,Viper",
            "anonymous": 0,
            "reporter": "NDA0E"
        }
    ],
    "1349510": [
        {
            "ioc_value": "216.118.101.199:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2024-11-30 20:06:08",
            "last_seen_utc": "2026-08-31 07:46:10",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "censys,panel,Viper",
            "anonymous": 0,
            "reporter": "NDA0E"
        }
    ],
    "1349492": [
        {
            "ioc_value": "216.118.101.216:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2024-11-30 20:06:04",
            "last_seen_utc": "2026-08-31 07:46:13",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "censys,panel,Viper",
            "anonymous": 0,
            "reporter": "NDA0E"
        }
    ],
    "1349445": [
        {
            "ioc_value": "113.44.89.87:60000",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2024-11-30 20:05:53",
            "last_seen_utc": "2026-08-31 07:43:31",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "censys,panel,Viper",
            "anonymous": 0,
            "reporter": "NDA0E"
        }
    ],
    "1349438": [
        {
            "ioc_value": "216.118.101.54:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2024-11-30 20:05:51",
            "last_seen_utc": "2026-08-31 07:46:24",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "censys,panel,Viper",
            "anonymous": 0,
            "reporter": "NDA0E"
        }
    ],
    "1348902": [
        {
            "ioc_value": "216.118.101.108:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2024-11-29 13:56:30",
            "last_seen_utc": "2026-08-31 07:45:53",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "Viper",
            "anonymous": 0,
            "reporter": "dyingbreeds_"
        }
    ],
    "1348295": [
        {
            "ioc_value": "47.90.142.15:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2024-11-27 19:47:54",
            "last_seen_utc": "2026-08-31 08:00:40",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "censys,CobaltStrike",
            "anonymous": 0,
            "reporter": "NDA0E"
        }
    ],
    "1348026": [
        {
            "ioc_value": "8.137.114.210:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2024-11-27 19:47:07",
            "last_seen_utc": "2026-08-31 08:00:28",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "censys,CobaltStrike",
            "anonymous": 0,
            "reporter": "NDA0E"
        }
    ],
    "1346058": [
        {
            "ioc_value": "servicioremotoempresas.info",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2024-11-19 18:00:05",
            "last_seen_utc": "2026-08-31 08:00:49",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1340201": [
        {
            "ioc_value": "146.70.158.198:31337",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.sliver",
            "malware_alias": null,
            "malware_printable": "Sliver",
            "first_seen_utc": "2024-10-30 17:53:55",
            "last_seen_utc": "2026-08-31 07:43:51",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://github.com/TheRavenFile/Daily-Hunt/blob/main/Sliver%20C2",
            "tags": "c2,sliver,sliverc2",
            "anonymous": 0,
            "reporter": "TheRavenFile"
        }
    ],
    "1338675": [
        {
            "ioc_value": "https://stripplasst.com/live/",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.latrodectus",
            "malware_alias": "BLACKWIDOW,IceNova,Latrodectus,Lotus",
            "malware_printable": "Latrodectus",
            "first_seen_utc": "2024-10-22 13:56:41",
            "last_seen_utc": "2026-08-31 08:13:10",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://www.vmray.com/latrodectus-a-year-in-the-making/",
            "tags": "c2,latrodectus,vmray",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1338673": [
        {
            "ioc_value": "https://skinnyjeanso.com/live/",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.latrodectus",
            "malware_alias": "BLACKWIDOW,IceNova,Latrodectus,Lotus",
            "malware_printable": "Latrodectus",
            "first_seen_utc": "2024-10-22 13:56:39",
            "last_seen_utc": "2026-08-31 08:11:28",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://www.vmray.com/latrodectus-a-year-in-the-making/",
            "tags": "c2,latrodectus,vmray",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1338670": [
        {
            "ioc_value": "https://coolarition.com/live/",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.latrodectus",
            "malware_alias": "BLACKWIDOW,IceNova,Latrodectus,Lotus",
            "malware_printable": "Latrodectus",
            "first_seen_utc": "2024-10-22 13:56:34",
            "last_seen_utc": "2026-08-31 08:04:07",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://www.vmray.com/latrodectus-a-year-in-the-making/",
            "tags": "c2,latrodectus,vmray",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1338668": [
        {
            "ioc_value": "https://aytobusesre.com/live/",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.latrodectus",
            "malware_alias": "BLACKWIDOW,IceNova,Latrodectus,Lotus",
            "malware_printable": "Latrodectus",
            "first_seen_utc": "2024-10-22 13:56:32",
            "last_seen_utc": "2026-08-31 08:00:28",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://www.vmray.com/latrodectus-a-year-in-the-making/",
            "tags": "c2,latrodectus,vmray",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1332624": [
        {
            "ioc_value": "154.221.17.44:2888",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2024-10-02 06:31:45",
            "last_seen_utc": "2026-08-31 07:48:36",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-666666666",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1332328": [
        {
            "ioc_value": "195.100.198.220:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2024-10-01 16:02:09",
            "last_seen_utc": "2026-08-31 07:45:23",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/195.100.198.220",
            "tags": "AS5400,BT,C2,censys,Mythic",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1330880": [
        {
            "ioc_value": "45.74.34.32:1995",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.dcrat",
            "malware_alias": "DarkCrystal RAT",
            "malware_printable": "DCRat",
            "first_seen_utc": "2024-09-27 16:02:26",
            "last_seen_utc": "2026-08-31 07:47:17",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/45.74.34.32",
            "tags": "AS9009,C2,censys,DcRAT,M247,RAT",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1329042": [
        {
            "ioc_value": "118.25.148.25:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2024-09-25 08:00:47",
            "last_seen_utc": "2026-08-31 08:00:36",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/118.25.148.25",
            "tags": "AS45090,C2,censys,CobaltStrike,cs-watermark-391144938,TENCENT-NET-AP",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1326604": [
        {
            "ioc_value": "206.210.123.104:8889",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.netsupportmanager_rat",
            "malware_alias": "NetSupport",
            "malware_printable": "NetSupportManager RAT",
            "first_seen_utc": "2024-09-20 08:01:06",
            "last_seen_utc": "2026-08-31 07:45:44",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/206.210.123.104",
            "tags": "AS33130,C2,censys,IASL,RAT",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1326049": [
        {
            "ioc_value": "https://pomaspoteraka.com/test/",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.latrodectus",
            "malware_alias": "BLACKWIDOW,IceNova,Latrodectus,Lotus",
            "malware_printable": "Latrodectus",
            "first_seen_utc": "2024-09-19 14:07:53",
            "last_seen_utc": "2026-08-31 07:59:12",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": null,
            "tags": "1.5,Delta",
            "anonymous": 0,
            "reporter": "spamhaus"
        }
    ],
    "1326050": [
        {
            "ioc_value": "https://finilamedima.com/test/",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.latrodectus",
            "malware_alias": "BLACKWIDOW,IceNova,Latrodectus,Lotus",
            "malware_printable": "Latrodectus",
            "first_seen_utc": "2024-09-19 14:07:52",
            "last_seen_utc": "2026-08-31 08:07:46",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": null,
            "tags": "1.5,Delta",
            "anonymous": 0,
            "reporter": "spamhaus"
        }
    ],
    "1326051": [
        {
            "ioc_value": "https://isomicrotich.com/test/",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.latrodectus",
            "malware_alias": "BLACKWIDOW,IceNova,Latrodectus,Lotus",
            "malware_printable": "Latrodectus",
            "first_seen_utc": "2024-09-19 14:07:51",
            "last_seen_utc": "2026-08-31 08:13:26",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": null,
            "tags": "1.7,Alpha",
            "anonymous": 0,
            "reporter": "spamhaus"
        }
    ],
    "1326052": [
        {
            "ioc_value": "https://rilomenifis.com/test/",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.latrodectus",
            "malware_alias": "BLACKWIDOW,IceNova,Latrodectus,Lotus",
            "malware_printable": "Latrodectus",
            "first_seen_utc": "2024-09-19 14:07:50",
            "last_seen_utc": "2026-08-31 08:03:22",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": null,
            "tags": "1.7,Alpha",
            "anonymous": 0,
            "reporter": "spamhaus"
        }
    ],
    "1317376": [
        {
            "ioc_value": "https://pikchestop.com/test/",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.lactrodectus",
            "malware_alias": "BLACKWIDOW,IceNova,Latrodectus,Lotus",
            "malware_printable": "Latrodectus",
            "first_seen_utc": "2024-08-30 07:05:10",
            "last_seen_utc": "2026-08-31 08:04:24",
            "confidence_level": 49,
            "is_compromised": false,
            "reference": "https://www.netskope.com/jp/blog/latrodectus-rapid-evolution-continues-with-latest-new-payload-features",
            "tags": null,
            "anonymous": 0,
            "reporter": "johannes"
        }
    ],
    "1317377": [
        {
            "ioc_value": "https://indepahote.com/test/",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.lactrodectus",
            "malware_alias": "BLACKWIDOW,IceNova,Latrodectus,Lotus",
            "malware_printable": "Latrodectus",
            "first_seen_utc": "2024-08-30 07:05:10",
            "last_seen_utc": "2026-08-31 08:12:26",
            "confidence_level": 49,
            "is_compromised": false,
            "reference": "https://www.netskope.com/jp/blog/latrodectus-rapid-evolution-continues-with-latest-new-payload-features",
            "tags": null,
            "anonymous": 0,
            "reporter": "johannes"
        }
    ],
    "1317070": [
        {
            "ioc_value": "86.53.241.21:447",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.netsupportmanager_rat",
            "malware_alias": "NetSupport",
            "malware_printable": "NetSupportManager RAT",
            "first_seen_utc": "2024-08-29 00:01:11",
            "last_seen_utc": "2026-08-31 07:47:52",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/86.53.241.21",
            "tags": "AS3257,C2,censys,GTT-BACKBONE,RAT",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1316522": [
        {
            "ioc_value": "107.22.165.49:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.netsupportmanager_rat",
            "malware_alias": "NetSupport",
            "malware_printable": "NetSupportManager RAT",
            "first_seen_utc": "2024-08-27 04:00:34",
            "last_seen_utc": "2026-08-31 07:43:24",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/107.22.165.49",
            "tags": "AMAZON-AES,AS14618,C2,censys,RAT",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1314694": [
        {
            "ioc_value": "83.229.120.73:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2024-08-22 10:04:33",
            "last_seen_utc": "2026-08-31 07:47:48",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/83.229.120.73",
            "tags": "AS139659,C2,censys,Mythic",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1313657": [
        {
            "ioc_value": "193.19.242.55:1443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.netsupportmanager_rat",
            "malware_alias": "NetSupport",
            "malware_printable": "NetSupportManager RAT",
            "first_seen_utc": "2024-08-19 19:55:59",
            "last_seen_utc": "2026-08-31 07:45:13",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/193.19.242.55",
            "tags": "AS35319,AS48964,C2,censys,RAT",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1313194": [
        {
            "ioc_value": "110.13.35.37:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.netsupportmanager_rat",
            "malware_alias": "NetSupport",
            "malware_printable": "NetSupportManager RAT",
            "first_seen_utc": "2024-08-18 14:04:40",
            "last_seen_utc": "2026-08-31 07:43:28",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/110.13.35.37",
            "tags": "AS9318,C2,censys,RAT,SKB-AS",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1312402": [
        {
            "ioc_value": "20.188.119.195:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.havoc",
            "malware_alias": "Havokiz",
            "malware_printable": "Havoc",
            "first_seen_utc": "2024-08-17 14:04:20",
            "last_seen_utc": "2026-08-31 07:45:38",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/20.188.119.195",
            "tags": "AS8075,C2,censys,MICROSOFT-CORP-MSN-AS-BLOCK",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1312338": [
        {
            "ioc_value": "210.249.114.154:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.netsupportmanager_rat",
            "malware_alias": "NetSupport",
            "malware_printable": "NetSupportManager RAT",
            "first_seen_utc": "2024-08-17 02:04:24",
            "last_seen_utc": "2026-08-31 07:45:49",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/210.249.114.154",
            "tags": "AS2516,C2,censys,RAT",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1312117": [
        {
            "ioc_value": "20.188.119.195:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.havoc",
            "malware_alias": "Havokiz",
            "malware_printable": "Havoc",
            "first_seen_utc": "2024-08-16 14:02:33",
            "last_seen_utc": "2026-08-31 07:45:38",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/20.188.119.195",
            "tags": "AS8075,C2,censys,MICROSOFT-CORP-MSN-AS-BLOCK",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1311619": [
        {
            "ioc_value": "23.24.178.35:3085",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.netsupportmanager_rat",
            "malware_alias": "NetSupport",
            "malware_printable": "NetSupportManager RAT",
            "first_seen_utc": "2024-08-15 22:40:43",
            "last_seen_utc": "2026-08-31 07:46:41",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/23.24.178.35",
            "tags": "AS20214,C2,censys,COMCAST-20214,RAT",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1311614": [
        {
            "ioc_value": "120.25.239.36:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.netsupportmanager_rat",
            "malware_alias": "NetSupport",
            "malware_printable": "NetSupportManager RAT",
            "first_seen_utc": "2024-08-15 22:40:39",
            "last_seen_utc": "2026-08-31 07:43:34",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/120.25.239.36",
            "tags": "ALIBABA-CN-NET,AS37963,C2,censys,RAT",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1310952": [
        {
            "ioc_value": "47.100.16.83:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2024-08-15 04:02:49",
            "last_seen_utc": "2026-08-31 07:48:50",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-391144938",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1309755": [
        {
            "ioc_value": "146.70.158.198:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.sliver",
            "malware_alias": null,
            "malware_printable": "Sliver",
            "first_seen_utc": "2024-08-11 21:50:57",
            "last_seen_utc": "2026-08-31 07:43:51",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/146.70.158.198",
            "tags": "AS9009,C2,censys,M247",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1296480": [
        {
            "ioc_value": "43.138.0.179:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2024-07-09 19:05:36",
            "last_seen_utc": "2026-08-31 08:00:31",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-0,TENCENT-NET-AP Shenzhen Tencent Computer Systems Company Limited",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1296006": [
        {
            "ioc_value": "213.149.181.121:469",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.netsupportmanager_rat",
            "malware_alias": "NetSupport",
            "malware_printable": "NetSupportManager RAT",
            "first_seen_utc": "2024-07-09 06:51:58",
            "last_seen_utc": "2026-08-31 07:45:50",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/213.149.181.121",
            "tags": "CYTA-NETWORK Internet Services,NetSupportRAT",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1296003": [
        {
            "ioc_value": "20.105.139.205:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.netsupportmanager_rat",
            "malware_alias": "NetSupport",
            "malware_printable": "NetSupportManager RAT",
            "first_seen_utc": "2024-07-09 06:51:48",
            "last_seen_utc": "2026-08-31 07:45:37",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/20.105.139.205",
            "tags": "MICROSOFT-CORP-MSN-AS-BLOCK,NetSupportRAT",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1295752": [
        {
            "ioc_value": "210.249.114.153:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.netsupportmanager_rat",
            "malware_alias": "NetSupport",
            "malware_printable": "NetSupportManager RAT",
            "first_seen_utc": "2024-07-08 06:51:14",
            "last_seen_utc": "2026-08-31 07:45:49",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/210.249.114.153",
            "tags": "KDDI KDDI CORPORATION,NetSupportRAT",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1295405": [
        {
            "ioc_value": "23.24.178.33:3085",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.netsupportmanager_rat",
            "malware_alias": "NetSupport",
            "malware_printable": "NetSupportManager RAT",
            "first_seen_utc": "2024-07-07 03:48:38",
            "last_seen_utc": "2026-08-31 07:46:40",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/23.24.178.33",
            "tags": "COMCAST-7922,NetSupportRAT",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1292877": [
        {
            "ioc_value": "210.249.114.154:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.netsupportmanager_rat",
            "malware_alias": "NetSupport",
            "malware_printable": "NetSupportManager RAT",
            "first_seen_utc": "2024-07-03 06:52:14",
            "last_seen_utc": "2026-08-31 07:45:49",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/210.249.114.154",
            "tags": "KDDI KDDI CORPORATION,NetSupportRAT",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1291417": [
        {
            "ioc_value": "198.244.197.118:9443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.netsupportmanager_rat",
            "malware_alias": "NetSupport",
            "malware_printable": "NetSupportManager RAT",
            "first_seen_utc": "2024-07-01 10:05:40",
            "last_seen_utc": "2026-08-31 07:45:31",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/198.244.197.118",
            "tags": "NetSupportRAT,OVH",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1291414": [
        {
            "ioc_value": "206.210.123.104:8888",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.netsupportmanager_rat",
            "malware_alias": "NetSupport",
            "malware_printable": "NetSupportManager RAT",
            "first_seen_utc": "2024-07-01 10:05:30",
            "last_seen_utc": "2026-08-31 07:45:43",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/206.210.123.104",
            "tags": "IASL,NetSupportRAT",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1291411": [
        {
            "ioc_value": "61.96.204.117:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.netsupportmanager_rat",
            "malware_alias": "NetSupport",
            "malware_printable": "NetSupportManager RAT",
            "first_seen_utc": "2024-07-01 10:05:19",
            "last_seen_utc": "2026-08-31 07:47:32",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/61.96.204.117",
            "tags": "DREAMX-AS DREAMLINE CO.,NetSupportRAT",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1291410": [
        {
            "ioc_value": "185.23.192.33:444",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.netsupportmanager_rat",
            "malware_alias": "NetSupport",
            "malware_printable": "NetSupportManager RAT",
            "first_seen_utc": "2024-07-01 10:05:15",
            "last_seen_utc": "2026-08-31 07:44:48",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/185.23.192.33",
            "tags": "NetSupportRAT,WINET",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1291409": [
        {
            "ioc_value": "2.136.235.200:3085",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.netsupportmanager_rat",
            "malware_alias": "NetSupport",
            "malware_printable": "NetSupportManager RAT",
            "first_seen_utc": "2024-07-01 10:05:10",
            "last_seen_utc": "2026-08-31 07:45:32",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/2.136.235.200",
            "tags": "NetSupportRAT,TELEFONICA_DE_ESPANA",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1291397": [
        {
            "ioc_value": "210.249.114.153:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.netsupportmanager_rat",
            "malware_alias": "NetSupport",
            "malware_printable": "NetSupportManager RAT",
            "first_seen_utc": "2024-07-01 10:04:31",
            "last_seen_utc": "2026-08-31 07:45:49",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/210.249.114.153",
            "tags": "KDDI KDDI CORPORATION,NetSupportRAT",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1291297": [
        {
            "ioc_value": "londopas.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2024-06-30 21:00:04",
            "last_seen_utc": "2026-08-31 08:00:49",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1291296": [
        {
            "ioc_value": "berjimek.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2024-06-30 21:00:03",
            "last_seen_utc": "2026-08-31 08:00:49",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1291010": [
        {
            "ioc_value": "www.qianxinnbplus.xyz",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2024-06-30 10:13:19",
            "last_seen_utc": "2026-08-31 08:00:49",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-666666666,HKLNIL Landui Cloud ComputingHK Limited",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1289423": [
        {
            "ioc_value": "152.32.202.240:8443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2024-06-26 17:07:43",
            "last_seen_utc": "2026-08-31 07:48:35",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-666666",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1287670": [
        {
            "ioc_value": "91.199.154.103:34211",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.sliver",
            "malware_alias": null,
            "malware_printable": "Sliver",
            "first_seen_utc": "2024-06-22 06:45:48",
            "last_seen_utc": "2026-08-31 07:47:57",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/91.199.154.103",
            "tags": "Sliver",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1285430": [
        {
            "ioc_value": "ieee-ecce.info",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2024-06-16 14:42:03",
            "last_seen_utc": "2026-08-31 08:00:49",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1285431": [
        {
            "ioc_value": "kauzalvip.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2024-06-16 14:42:03",
            "last_seen_utc": "2026-08-31 08:00:49",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1285432": [
        {
            "ioc_value": "nakit-yok.org",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2024-06-16 14:42:03",
            "last_seen_utc": "2026-08-31 08:00:50",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1285433": [
        {
            "ioc_value": "nathanhr.services",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2024-06-16 14:42:03",
            "last_seen_utc": "2026-08-31 08:00:50",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1283657": [
        {
            "ioc_value": "support.whatsappsignup.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2024-06-10 09:26:05",
            "last_seen_utc": "2026-08-31 08:00:50",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-987654321,PEG TECH INC",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1278385": [
        {
            "ioc_value": "static.nvidiadrives.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2024-06-02 19:42:15",
            "last_seen_utc": "2026-08-31 08:00:55",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1278172": [
        {
            "ioc_value": "119.91.208.190:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2024-06-02 08:38:33",
            "last_seen_utc": "2026-08-31 08:00:52",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-987654321,Shenzhen Tencent Computer Systems Company Limited",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1277937": [
        {
            "ioc_value": "47.109.69.135:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2024-06-01 13:08:25",
            "last_seen_utc": "2026-08-31 08:00:54",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-987654321,Hangzhou Alibaba Advertising Co.Ltd.",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1277588": [
        {
            "ioc_value": "101.43.32.212:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2024-05-31 12:57:33",
            "last_seen_utc": "2026-08-31 08:00:50",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-100000,Shenzhen Tencent Computer Systems Company Limited",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1276810": [
        {
            "ioc_value": "asterchildrenshoes.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2024-05-29 12:53:46",
            "last_seen_utc": "2026-08-31 08:00:55",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "BL Networks,CobaltStrike,cs-watermark-987654321",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1276802": [
        {
            "ioc_value": "124.223.41.181:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2024-05-29 12:52:55",
            "last_seen_utc": "2026-08-31 08:00:52",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-666666666,Shenzhen Tencent Computer Systems Company Limited",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1276786": [
        {
            "ioc_value": "8.210.9.201:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2024-05-29 10:17:04",
            "last_seen_utc": "2026-08-31 08:00:55",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ALIBABA-CN-NET Alibaba US Technology Co. Ltd.,CobaltStrike,cs-watermark-0",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1275630": [
        {
            "ioc_value": "pt-security.ru",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2024-05-25 22:18:29",
            "last_seen_utc": "2026-08-31 08:00:50",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-987654321,MTW-AS",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1274905": [
        {
            "ioc_value": "158.220.115.82:31337",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.sliver",
            "malware_alias": null,
            "malware_printable": "Sliver",
            "first_seen_utc": "2024-05-24 16:54:06",
            "last_seen_utc": "2026-08-31 07:44:06",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": "",
            "tags": "sliver",
            "anonymous": 0,
            "reporter": "Syndikalist"
        }
    ],
    "1274726": [
        {
            "ioc_value": "47.92.127.53:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2024-05-24 13:15:35",
            "last_seen_utc": "2026-08-31 08:00:54",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-391144938,Hangzhou Alibaba Advertising Co.Ltd.",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1273973": [
        {
            "ioc_value": "119.28.83.149:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2024-05-22 11:06:58",
            "last_seen_utc": "2026-08-31 08:00:51",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-987654321,Tencent Building Kejizhongyi Avenue",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1273882": [
        {
            "ioc_value": "51.15.16.116:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "js.fakeupdates",
            "malware_alias": "FakeUpdate,GhoLoader,SocGholish",
            "malware_printable": "FAKEUPDATES",
            "first_seen_utc": "2024-05-21 18:51:48",
            "last_seen_utc": "2026-08-31 07:47:26",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/51.15.16.116",
            "tags": "Online SAS,SocGholish",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1273456": [
        {
            "ioc_value": "139.159.203.44:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2024-05-21 12:53:29",
            "last_seen_utc": "2026-08-31 08:00:53",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-987654321,HWCSNET Huawei Cloud Service data center",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1272788": [
        {
            "ioc_value": "123.58.198.236:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2024-05-19 07:56:13",
            "last_seen_utc": "2026-08-31 08:00:52",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-391144938,UCLOUD INFORMATION TECHNOLOGY (HK) LIMITED",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1271699": [
        {
            "ioc_value": "vip8806.mom",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2024-05-16 07:53:43",
            "last_seen_utc": "2026-08-31 08:00:50",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CNSERVERS LLC,CobaltStrike,cs-watermark-987654321",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1271605": [
        {
            "ioc_value": "blmdiscount.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2024-05-15 22:13:26",
            "last_seen_utc": "2026-08-31 08:00:49",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-674054486,FBWNETWORKS",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1271606": [
        {
            "ioc_value": "91.238.181.235:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2024-05-15 22:13:26",
            "last_seen_utc": "2026-08-31 08:00:55",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-674054486,FBWNETWORKS",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1271347": [
        {
            "ioc_value": "118.25.85.198:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2024-05-15 15:33:07",
            "last_seen_utc": "2026-08-31 08:00:46",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/118.25.85.198",
            "tags": "AS45090,c2,censys,CobaltStrike,cs-watermark-305419896,TENCENT-NET-AP",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1270684": [
        {
            "ioc_value": "64.7.198.58:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2024-05-14 10:14:21",
            "last_seen_utc": "2026-08-31 08:00:54",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "BLNWX,CobaltStrike,cs-watermark-426352781",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1269727": [
        {
            "ioc_value": "113.31.105.33:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2024-05-11 22:47:31",
            "last_seen_utc": "2026-08-31 08:00:51",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "China Telecom (Group),CobaltStrike,cs-watermark-987654321",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1269724": [
        {
            "ioc_value": "185.196.8.18:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2024-05-11 22:47:10",
            "last_seen_utc": "2026-08-31 08:00:53",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-987654321,Simple Carrier LLC",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1269723": [
        {
            "ioc_value": "action-winds.cfd",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2024-05-11 22:47:09",
            "last_seen_utc": "2026-08-31 08:00:55",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-987654321,Simple Carrier LLC",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1269721": [
        {
            "ioc_value": "microstar.cfd",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2024-05-11 22:47:08",
            "last_seen_utc": "2026-08-31 08:00:56",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-987654321,Simple Carrier LLC",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1267565": [
        {
            "ioc_value": "113.31.106.106:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2024-05-07 10:14:57",
            "last_seen_utc": "2026-08-31 08:00:51",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CHINANET-SHANGHAI-MAN China Telecom Group,CobaltStrike,cs-watermark-987654321",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1267486": [
        {
            "ioc_value": "111.230.12.238:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2024-05-07 07:48:08",
            "last_seen_utc": "2026-08-31 08:00:51",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/111.230.12.238",
            "tags": "AS45090,c2,censys,CobaltStrike,cs-watermark-391144938,TENCENT-NET-AP",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1266959": [
        {
            "ioc_value": "134.122.130.186:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2024-05-06 12:49:25",
            "last_seen_utc": "2026-08-31 08:00:52",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "BGPNET Global ASN,CobaltStrike,cs-watermark-987654321",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1263972": [
        {
            "ioc_value": "134.122.130.181:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2024-04-29 12:51:26",
            "last_seen_utc": "2026-08-31 08:00:52",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "BGPNET Global ASN,CobaltStrike,cs-watermark-987654321",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1263319": [
        {
            "ioc_value": "124.71.106.234:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2024-04-28 17:59:06",
            "last_seen_utc": "2026-08-31 08:00:52",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-666666666,Huawei Cloud Service data center",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1262666": [
        {
            "ioc_value": "118.31.116.9:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2024-04-26 12:59:31",
            "last_seen_utc": "2026-08-31 08:00:51",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-987654321,Hangzhou Alibaba Advertising Co.Ltd.",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1262568": [
        {
            "ioc_value": "8.134.11.7:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2024-04-25 22:12:56",
            "last_seen_utc": "2026-08-31 08:00:55",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ALIBABA-CN-NET Hangzhou Alibaba Advertising Co.Ltd.,CobaltStrike,cs-watermark-987654321",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1261845": [
        {
            "ioc_value": "165.227.108.186:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2024-04-24 13:08:20",
            "last_seen_utc": "2026-08-31 08:00:53",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-970865301,DigitalOcean LLC",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1260893": [
        {
            "ioc_value": "80.66.75.9:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2024-04-23 18:05:49",
            "last_seen_utc": "2026-08-31 08:00:55",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-987654321,GRIZ-INET-SERVICE",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1260890": [
        {
            "ioc_value": "101.201.54.74:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2024-04-23 18:05:43",
            "last_seen_utc": "2026-08-31 08:00:50",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-987654321,Hangzhou Alibaba Advertising Co.Ltd.",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1259796": [
        {
            "ioc_value": "62.204.41.11:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2024-04-21 15:09:17",
            "last_seen_utc": "2026-08-31 08:00:54",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/62.204.41.11",
            "tags": "AS59425,c2,censys,CobaltStrike,cs-watermark-1580103824,HORIZONMSK-AS",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1252542": [
        {
            "ioc_value": "185.196.10.121:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2024-04-02 10:17:26",
            "last_seen_utc": "2026-08-31 08:00:53",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-987654321,SIMPLECARRIER",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1250157": [
        {
            "ioc_value": "soneypaly.club",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2024-03-27 14:42:02",
            "last_seen_utc": "2026-08-31 08:00:56",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1249815": [
        {
            "ioc_value": "47.105.69.34:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2024-03-27 07:57:29",
            "last_seen_utc": "2026-08-31 08:00:54",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ALIBABA-CN-NET Hangzhou Alibaba Advertising Co.Ltd.,CobaltStrike,cs-watermark-987654321",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1248363": [
        {
            "ioc_value": "https://titnovacrion.top/live/",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.unidentified_111",
            "malware_alias": "BLACKWIDOW,IceNova,Latrodectus,Lotus",
            "malware_printable": "Unidentified 111 (Latrodectus)",
            "first_seen_utc": "2024-03-22 19:47:18",
            "last_seen_utc": "2026-08-31 08:07:05",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": null,
            "anonymous": 0,
            "reporter": "Cryptolaemus1"
        }
    ],
    "1245707": [
        {
            "ioc_value": "https://scifimond.com/live/",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.unidentified_111",
            "malware_alias": "BLACKWIDOW,IceNova,Latrodectus,Lotus",
            "malware_printable": "Unidentified 111 (Latrodectus)",
            "first_seen_utc": "2024-03-11 18:05:31",
            "last_seen_utc": "2026-08-31 08:09:30",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "latrodectus",
            "anonymous": 0,
            "reporter": "Cryptolaemus1"
        }
    ],
    "1245476": [
        {
            "ioc_value": "47.100.87.177:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2024-03-09 20:54:40",
            "last_seen_utc": "2026-08-31 08:00:54",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ALIBABA-CN-NET Hangzhou Alibaba Advertising Co.Ltd.,CobaltStrike,cs-watermark-987654321",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1244781": [
        {
            "ioc_value": "194.165.16.55:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2024-03-06 20:55:37",
            "last_seen_utc": "2026-08-31 08:00:53",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-674054486,FLYSERVERS-ENDCLIENTS",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1244726": [
        {
            "ioc_value": "googlesupportacc.top",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2024-03-06 10:12:56",
            "last_seen_utc": "2026-08-31 08:00:56",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ASSEFLOW,CobaltStrike,cs-watermark-987654321",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1241656": [
        {
            "ioc_value": "121.43.55.149:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2024-02-21 22:13:19",
            "last_seen_utc": "2026-08-31 08:00:52",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ALIBABA-CN-NET Hangzhou Alibaba Advertising Co.Ltd.,CobaltStrike,cs-watermark-391144938",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1237621": [
        {
            "ioc_value": "qw.regcssv.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2024-02-07 10:12:21",
            "last_seen_utc": "2026-08-31 08:00:58",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-1580103824,FLYSERVERS-ASN",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1236577": [
        {
            "ioc_value": "ec2-3-22-66-152.us-east-2.compute.amazonaws.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2024-02-03 19:38:15",
            "last_seen_utc": "2026-08-31 08:00:58",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/3.22.66.152+ec2-3-22-66-152.us-east-2.compute.amazonaws.com",
            "tags": "AMAZON-02,AS16509,C2,censys",
            "anonymous": 0,
            "reporter": "thehappydinoa"
        }
    ],
    "1236276": [
        {
            "ioc_value": "20.56.70.245:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2024-02-02 06:00:13",
            "last_seen_utc": "2026-08-31 08:00:53",
            "confidence_level": 80,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "malpulse"
        }
    ],
    "1235332": [
        {
            "ioc_value": "www.louangelwolf.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2024-01-30 06:20:34",
            "last_seen_utc": "2026-08-31 08:01:00",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "cobaltstrike,cs-watermark-1551089073",
            "anonymous": 0,
            "reporter": "myceliumbroker"
        }
    ],
    "1234854": [
        {
            "ioc_value": "kkudndkwatnfevcaqeefytqnh.top",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2024-01-28 06:22:18",
            "last_seen_utc": "2026-08-31 08:00:58",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "cobaltstrike,cs-watermark-987654321",
            "anonymous": 0,
            "reporter": "myceliumbroker"
        }
    ],
    "1234859": [
        {
            "ioc_value": "whxzqkbbtzvdyxdeseoiyujzs.co",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2024-01-28 06:22:17",
            "last_seen_utc": "2026-08-31 08:00:59",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "cobaltstrike,cs-watermark-987654321",
            "anonymous": 0,
            "reporter": "myceliumbroker"
        }
    ],
    "1234860": [
        {
            "ioc_value": "uohhunkmnfhbimtagizqgwpmv.to",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2024-01-28 06:22:17",
            "last_seen_utc": "2026-08-31 08:00:59",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "cobaltstrike,cs-watermark-987654321",
            "anonymous": 0,
            "reporter": "myceliumbroker"
        }
    ],
    "1234928": [
        {
            "ioc_value": "114.55.133.151:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2024-01-27 14:31:40",
            "last_seen_utc": "2026-08-31 08:00:51",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/114.55.133.151",
            "tags": "AS37963,C2,censys",
            "anonymous": 0,
            "reporter": "thehappydinoa"
        }
    ],
    "1234909": [
        {
            "ioc_value": "117.72.39.83:30005",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2024-01-27 14:31:20",
            "last_seen_utc": "2026-08-31 07:48:28",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/117.72.39.83",
            "tags": "AS141679,C2,censys",
            "anonymous": 0,
            "reporter": "thehappydinoa"
        }
    ],
    "1234304": [
        {
            "ioc_value": "38.147.189.199:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pupy",
            "malware_alias": "Patpoopy",
            "malware_printable": "pupy",
            "first_seen_utc": "2024-01-24 18:49:24",
            "last_seen_utc": "2026-08-31 07:46:56",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/38.147.189.199",
            "tags": "Pupy RAT,XNNET",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1233919": [
        {
            "ioc_value": "www.idn15r69vh3fwhzclfoeuaoy.today",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2024-01-23 13:53:21",
            "last_seen_utc": "2026-08-31 08:01:00",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/8.219.229.99+www.idn15r69vh3fwhzclfoeuaoy.today",
            "tags": "AS45102,C2,censys",
            "anonymous": 0,
            "reporter": "thehappydinoa"
        }
    ],
    "1231802": [
        {
            "ioc_value": "164-90-169-184.cprapid.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2024-01-18 13:44:13",
            "last_seen_utc": "2026-08-31 08:00:59",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/164.90.169.184+164-90-169-184.cprapid.com",
            "tags": "C2,censys,DIGITALOCEAN-ASN",
            "anonymous": 0,
            "reporter": "thehappydinoa"
        }
    ],
    "1230963": [
        {
            "ioc_value": "https://65.21.187.53/",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2024-01-16 08:13:32",
            "last_seen_utc": "2026-08-31 08:10:15",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "Vidar",
            "anonymous": 0,
            "reporter": "crep1x"
        }
    ],
    "1230909": [
        {
            "ioc_value": "lz4.tiktok123.life",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2024-01-15 16:27:00",
            "last_seen_utc": "2026-08-31 08:00:58",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "cobaltstrike,cs-watermark-987654321",
            "anonymous": 0,
            "reporter": "myceliumbroker"
        }
    ],
    "1230478": [
        {
            "ioc_value": "164.92.79.49:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.havoc",
            "malware_alias": "Havokiz",
            "malware_printable": "Havoc",
            "first_seen_utc": "2024-01-13 06:47:25",
            "last_seen_utc": "2026-08-31 07:44:15",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/164.92.79.49",
            "tags": "DIGITALOCEAN-ASN,Havoc",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1230429": [
        {
            "ioc_value": "site.dev.hutechweb.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2024-01-12 18:36:24",
            "last_seen_utc": "2026-08-31 08:00:59",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "cobaltstrike,cs-watermark-987654321",
            "anonymous": 0,
            "reporter": "myceliumbroker"
        }
    ],
    "1230163": [
        {
            "ioc_value": "158.220.115.82:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.sliver",
            "malware_alias": null,
            "malware_printable": "Sliver",
            "first_seen_utc": "2024-01-11 13:33:38",
            "last_seen_utc": "2026-08-31 07:44:07",
            "confidence_level": 90,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/158.220.115.82",
            "tags": "C2,censys,CONTABO",
            "anonymous": 0,
            "reporter": "thehappydinoa"
        }
    ],
    "1230076": [
        {
            "ioc_value": "ns1.fiducaire.lu",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2024-01-11 06:54:21",
            "last_seen_utc": "2026-08-31 08:00:59",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "cobaltstrike,cs-watermark-1263551644",
            "anonymous": 0,
            "reporter": "myceliumbroker"
        }
    ],
    "1230077": [
        {
            "ioc_value": "ns1.asurances.lu",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2024-01-11 06:54:21",
            "last_seen_utc": "2026-08-31 08:00:59",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "cobaltstrike,cs-watermark-1263551644",
            "anonymous": 0,
            "reporter": "myceliumbroker"
        }
    ],
    "1230078": [
        {
            "ioc_value": "sagsblog.telinduslab.lu",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2024-01-11 06:54:20",
            "last_seen_utc": "2026-08-31 08:00:59",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "cobaltstrike,cs-watermark-1263551644",
            "anonymous": 0,
            "reporter": "myceliumbroker"
        }
    ],
    "1230079": [
        {
            "ioc_value": "ns1.jocelynhealth.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2024-01-11 06:54:20",
            "last_seen_utc": "2026-08-31 08:00:59",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "cobaltstrike,cs-watermark-1590258876",
            "anonymous": 0,
            "reporter": "myceliumbroker"
        }
    ],
    "1229840": [
        {
            "ioc_value": "ns.emaratalyoum.me",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2024-01-10 10:50:13",
            "last_seen_utc": "2026-08-31 08:00:58",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "cobaltstrike,cs-watermark-1727139162",
            "anonymous": 0,
            "reporter": "myceliumbroker"
        }
    ],
    "1229818": [
        {
            "ioc_value": "130.51.20.64:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pupy",
            "malware_alias": "Patpoopy",
            "malware_printable": "pupy",
            "first_seen_utc": "2024-01-10 06:48:44",
            "last_seen_utc": "2026-08-31 07:43:41",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/130.51.20.64",
            "tags": "Pupy RAT,TZULO",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1229817": [
        {
            "ioc_value": "161.35.239.147:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.havoc",
            "malware_alias": "Havokiz",
            "malware_printable": "Havoc",
            "first_seen_utc": "2024-01-10 06:48:20",
            "last_seen_utc": "2026-08-31 07:44:11",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/161.35.239.147",
            "tags": "DIGITALOCEAN-ASN,Havoc",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1229694": [
        {
            "ioc_value": "emailmigration.org",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2024-01-09 14:55:19",
            "last_seen_utc": "2026-08-31 08:00:58",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "cobaltstrike,cs-watermark-1892870985",
            "anonymous": 0,
            "reporter": "myceliumbroker"
        }
    ],
    "1229695": [
        {
            "ioc_value": "ns1.emailmigration.org",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2024-01-09 14:55:17",
            "last_seen_utc": "2026-08-31 08:00:59",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "cobaltstrike,cs-watermark-1892870985",
            "anonymous": 0,
            "reporter": "myceliumbroker"
        }
    ],
    "1229661": [
        {
            "ioc_value": "111.92.243.236:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2024-01-09 08:45:29",
            "last_seen_utc": "2026-08-31 08:00:51",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-666666666,HFTCL-AS-AP High Family Technology Co. Limited",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1229599": [
        {
            "ioc_value": "82.65.19.134:4443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2024-01-09 05:30:32",
            "last_seen_utc": "2026-08-31 07:47:48",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/82.65.19.134",
            "tags": "C2,censys,PROXAD,RAT",
            "anonymous": 0,
            "reporter": "thehappydinoa"
        }
    ],
    "1228458": [
        {
            "ioc_value": "139.9.62.19:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2024-01-05 21:31:13",
            "last_seen_utc": "2026-08-31 08:00:53",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/139.9.62.19",
            "tags": "C2,censys",
            "anonymous": 0,
            "reporter": "thehappydinoa"
        }
    ],
    "1227297": [
        {
            "ioc_value": "106.54.209.36:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2024-01-02 14:31:12",
            "last_seen_utc": "2026-08-31 08:00:50",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/106.54.209.36",
            "tags": "C2,censys",
            "anonymous": 0,
            "reporter": "thehappydinoa"
        }
    ],
    "1226488": [
        {
            "ioc_value": "astra4512.startdedicated.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-12-30 11:33:25",
            "last_seen_utc": "2026-08-31 08:01:00",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-987654321,GD-EMEA-DC-SXB1",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1226427": [
        {
            "ioc_value": "38.147.188.61:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pupy",
            "malware_alias": "Patpoopy",
            "malware_printable": "pupy",
            "first_seen_utc": "2023-12-30 06:48:38",
            "last_seen_utc": "2026-08-31 07:46:56",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/38.147.188.61",
            "tags": "Pupy RAT,XNNET",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1226314": [
        {
            "ioc_value": "38.147.188.28:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pupy",
            "malware_alias": "Patpoopy",
            "malware_printable": "pupy",
            "first_seen_utc": "2023-12-29 18:48:19",
            "last_seen_utc": "2026-08-31 07:46:56",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/38.147.188.28",
            "tags": "Pupy RAT,XNNET",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1224105": [
        {
            "ioc_value": "cs.xcb.one",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-12-27 22:15:29",
            "last_seen_utc": "2026-08-31 08:01:00",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-987654321,MICROSOFT-CORP-MSN-AS-BLOCK",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1223678": [
        {
            "ioc_value": "8.140.203.92:7817",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.deimos",
            "malware_alias": null,
            "malware_printable": "Deimos",
            "first_seen_utc": "2023-12-26 06:46:27",
            "last_seen_utc": "2026-08-31 07:47:43",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/8.140.203.92",
            "tags": "ALIBABA-CN-NET Hangzhou Alibaba Advertising Co.Ltd.,Deimos",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1221451": [
        {
            "ioc_value": "62.234.27.204:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-12-18 05:00:11",
            "last_seen_utc": "2026-08-31 08:00:54",
            "confidence_level": 80,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "malpulse"
        }
    ],
    "1213636": [
        {
            "ioc_value": "MicrosoftSyst3m.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-12-16 22:12:14",
            "last_seen_utc": "2026-08-31 08:01:01",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-674054486,GLOBALLAYER",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1213211": [
        {
            "ioc_value": "117.72.39.83:33333",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-12-15 18:59:31",
            "last_seen_utc": "2026-08-31 07:48:29",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/117.72.39.83",
            "tags": "C2,censys",
            "anonymous": 0,
            "reporter": "thehappydinoa"
        }
    ],
    "1209246": [
        {
            "ioc_value": "unzip2.xyz",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-12-04 08:45:50",
            "last_seen_utc": "2026-08-31 08:01:01",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-987654321,TENCENT-NET-AP-CN Tencent Building Kejizhongyi Avenue",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1207072": [
        {
            "ioc_value": "60.205.115.92:60000",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "apk.viper_rat",
            "malware_alias": null,
            "malware_printable": "Viper RAT",
            "first_seen_utc": "2023-11-28 13:32:35",
            "last_seen_utc": "2026-08-31 07:47:32",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/60.205.115.92",
            "tags": "C2,censys,RAT",
            "anonymous": 0,
            "reporter": "thehappydinoa"
        }
    ],
    "1205166": [
        {
            "ioc_value": "techsyscloud.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-11-24 08:21:04",
            "last_seen_utc": "2026-08-31 08:01:03",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1205167": [
        {
            "ioc_value": "yify88.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-11-24 08:21:04",
            "last_seen_utc": "2026-08-31 08:01:04",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1205164": [
        {
            "ioc_value": "americcorp.net",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-11-24 08:21:02",
            "last_seen_utc": "2026-08-31 08:01:02",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1204685": [
        {
            "ioc_value": "tech-guard.vguard.tech",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-11-22 20:04:09",
            "last_seen_utc": "2026-08-31 08:01:03",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/44.204.120.159+tech-guard.vguard.tech",
            "tags": "AMAZON-AES,C2,censys",
            "anonymous": 0,
            "reporter": "thehappydinoa"
        }
    ],
    "1202628": [
        {
            "ioc_value": "ns.manager.moonlighter.space",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-11-15 20:24:37",
            "last_seen_utc": "2026-08-31 08:01:03",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-1893164628,DIGITALOCEAN-ASN",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1201144": [
        {
            "ioc_value": "101.34.222.38:60000",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "apk.viper_rat",
            "malware_alias": null,
            "malware_printable": "Viper RAT",
            "first_seen_utc": "2023-11-09 17:50:07",
            "last_seen_utc": "2026-08-31 07:43:04",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/101.34.222.38",
            "tags": "C2,censys,RAT",
            "anonymous": 0,
            "reporter": "thehappydinoa"
        }
    ],
    "1200343": [
        {
            "ioc_value": "dev.theokanegroup.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-11-09 04:06:44",
            "last_seen_utc": "2026-08-31 08:01:04",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/134.209.164.110+dev.theokanegroup.com",
            "tags": "C2,censys,DIGITALOCEAN-ASN",
            "anonymous": 0,
            "reporter": "thehappydinoa"
        }
    ],
    "1199506": [
        {
            "ioc_value": "bwyb.love",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-11-06 18:07:30",
            "last_seen_utc": "2026-08-31 08:01:02",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/47.242.158.114+bwyb.love",
            "tags": "C2,censys",
            "anonymous": 0,
            "reporter": "thehappydinoa"
        }
    ],
    "1199160": [
        {
            "ioc_value": "www.sunwu.world",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-11-05 15:00:42",
            "last_seen_utc": "2026-08-31 08:01:03",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/82.157.149.194+www.sunwu.world",
            "tags": "C2,censys",
            "anonymous": 0,
            "reporter": "thehappydinoa"
        }
    ],
    "1192255": [
        {
            "ioc_value": "139.155.148.131:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-10-24 10:39:59",
            "last_seen_utc": "2026-08-31 08:00:52",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/139.155.148.131",
            "tags": "C2,censys",
            "anonymous": 0,
            "reporter": "thehappydinoa"
        }
    ],
    "1191379": [
        {
            "ioc_value": "www.goocoinorg.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-10-20 21:57:56",
            "last_seen_utc": "2026-08-31 08:01:03",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/search?resource=hosts&sort=RELEVANCE&per_page=25&virtual_hosts=INCLUDE&q=name%3A+www.goocoinorg.com&ref=threatfox",
            "tags": "C2,censys",
            "anonymous": 0,
            "reporter": "thehappydinoa"
        }
    ],
    "1189545": [
        {
            "ioc_value": "airlinesapp.net",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-10-16 08:49:32",
            "last_seen_utc": "2026-08-31 08:01:01",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-587247372,DigitalOcean LLC",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1188605": [
        {
            "ioc_value": "lectricelfuel.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-10-13 19:49:34",
            "last_seen_utc": "2026-08-31 08:01:03",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/search?resource=hosts&sort=RELEVANCE&per_page=25&virtual_hosts=INCLUDE&q=name%3A+lectricelfuel.com&ref=threatfox",
            "tags": "C2,censys,DIGITALOCEAN-ASN",
            "anonymous": 0,
            "reporter": "thehappydinoa"
        }
    ],
    "1187462": [
        {
            "ioc_value": "117.72.8.192:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-10-11 12:59:56",
            "last_seen_utc": "2026-08-31 08:00:51",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/117.72.8.192",
            "tags": "C2,censys",
            "anonymous": 0,
            "reporter": "thehappydinoa"
        }
    ],
    "1180378": [
        {
            "ioc_value": "111.229.187.212:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-09-30 16:12:13",
            "last_seen_utc": "2026-08-31 08:00:50",
            "confidence_level": 80,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "malpulse"
        }
    ],
    "1165497": [
        {
            "ioc_value": "igo0gle.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-09-21 09:29:08",
            "last_seen_utc": "2026-08-31 08:01:00",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "AS-ALVIVA,CobaltStrike,cs-watermark-674054486",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1165172": [
        {
            "ioc_value": "8.217.217.243:8082",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.deimos",
            "malware_alias": null,
            "malware_printable": "Deimos",
            "first_seen_utc": "2023-09-20 18:47:20",
            "last_seen_utc": "2026-08-31 07:47:43",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/8.217.217.243",
            "tags": "ALIBABA-CN-NET Alibaba US Technology Co. Ltd.,Deimos",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1155921": [
        {
            "ioc_value": "csxv.sec.cm",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-09-09 20:06:55",
            "last_seen_utc": "2026-08-31 08:01:03",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CHANGWAY-AS,CobaltStrike,cs-watermark-987654321",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1155319": [
        {
            "ioc_value": "43.136.38.59:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-09-05 21:52:59",
            "last_seen_utc": "2026-08-31 08:00:53",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-1580103824,Shenzhen Tencent Computer Systems Company Limited",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1152278": [
        {
            "ioc_value": "withoutedge.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-08-26 18:42:05",
            "last_seen_utc": "2026-08-31 08:01:07",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1152277": [
        {
            "ioc_value": "thconnewfoot.org",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-08-26 18:42:04",
            "last_seen_utc": "2026-08-31 08:01:06",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1152274": [
        {
            "ioc_value": "caixas.link",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-08-26 18:42:03",
            "last_seen_utc": "2026-08-31 08:01:05",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1152275": [
        {
            "ioc_value": "ddllsearch.site",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-08-26 18:42:03",
            "last_seen_utc": "2026-08-31 08:01:05",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1152276": [
        {
            "ioc_value": "gepcash.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-08-26 18:42:03",
            "last_seen_utc": "2026-08-31 08:01:05",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1152272": [
        {
            "ioc_value": "amazonclouds.link",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-08-26 18:42:02",
            "last_seen_utc": "2026-08-31 08:01:04",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1152273": [
        {
            "ioc_value": "amur-city.online",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-08-26 18:42:02",
            "last_seen_utc": "2026-08-31 08:01:04",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1151932": [
        {
            "ioc_value": "77.74.208.123:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.havoc",
            "malware_alias": "Havokiz",
            "malware_printable": "Havoc",
            "first_seen_utc": "2023-08-25 06:48:54",
            "last_seen_utc": "2026-08-31 07:47:41",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/77.74.208.123",
            "tags": "BRETAGNETELECOM,Havoc",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1151693": [
        {
            "ioc_value": "43.153.222.28:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-08-23 11:56:21",
            "last_seen_utc": "2026-08-31 08:00:42",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-100000,Tencent Building Kejizhongyi Avenue",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1149951": [
        {
            "ioc_value": "164.92.145.128:7810",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.brute_ratel_c4",
            "malware_alias": "BOLDBADGER,BruteRatel",
            "malware_printable": "Brute Ratel C4",
            "first_seen_utc": "2023-08-14 18:46:43",
            "last_seen_utc": "2026-08-31 07:44:15",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/164.92.145.128",
            "tags": "Brute Ratel C4,DIGITALOCEAN-ASN",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1149946": [
        {
            "ioc_value": "pctor.link",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-08-14 16:00:05",
            "last_seen_utc": "2026-08-31 08:01:08",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1149945": [
        {
            "ioc_value": "tehomics.link",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-08-14 16:00:04",
            "last_seen_utc": "2026-08-31 08:01:07",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1149944": [
        {
            "ioc_value": "instant-healthonline.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-08-14 16:00:03",
            "last_seen_utc": "2026-08-31 08:01:07",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1148731": [
        {
            "ioc_value": "stratpringl.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-08-05 14:38:23",
            "last_seen_utc": "2026-08-31 08:01:06",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-1580103824,PINDC-AS",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1148487": [
        {
            "ioc_value": "onlinetechdesk.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-08-04 11:01:52",
            "last_seen_utc": "2026-08-31 08:01:07",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "AS-COLOCROSSING,CobaltStrike,cs-watermark-587247372",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1146843": [
        {
            "ioc_value": "harmonyshoused.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-08-03 10:25:44",
            "last_seen_utc": "2026-08-31 08:01:07",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-206546002,HVC-AS",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1146834": [
        {
            "ioc_value": "api.office-updates.org",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-08-03 10:24:41",
            "last_seen_utc": "2026-08-31 08:01:02",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-494165167,DIGITALOCEAN-ASN",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1146619": [
        {
            "ioc_value": "mkbkygbgwcdc.buzz",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-08-02 10:24:58",
            "last_seen_utc": "2026-08-31 08:01:06",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-391144938,KAOPU-HK Kaopu Cloud HK Limited",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1140114": [
        {
            "ioc_value": "tcessolution.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-07-25 10:17:22",
            "last_seen_utc": "2026-08-31 08:01:04",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "AS202973,CobaltStrike,cs-watermark-587247372",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1138196": [
        {
            "ioc_value": "rw1.sentrysource.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-07-15 12:48:31",
            "last_seen_utc": "2026-08-31 08:00:59",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-93937751,ROGERS-COMMUNICATIONS",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1136628": [
        {
            "ioc_value": "198.13.42.85:53",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-07-07 19:56:07",
            "last_seen_utc": "2026-08-31 07:48:43",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-100000,The Constant Company LLC",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1136627": [
        {
            "ioc_value": "aaa.ad4min.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-07-07 19:56:05",
            "last_seen_utc": "2026-08-31 07:48:13",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-100000,The Constant Company LLC",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1135804": [
        {
            "ioc_value": "pedagogists.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-07-03 15:42:02",
            "last_seen_utc": "2026-08-31 08:01:08",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1135803": [
        {
            "ioc_value": "cdnsupply.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-07-03 15:42:01",
            "last_seen_utc": "2026-08-31 08:01:08",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1134787": [
        {
            "ioc_value": "1.15.248.225:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-06-28 22:51:22",
            "last_seen_utc": "2026-08-31 08:00:50",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-987654321,TENCENT-NET-AP Shenzhen Tencent Computer Systems Company Limited",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1134128": [
        {
            "ioc_value": "check1.judicical.ml",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-06-26 08:12:17",
            "last_seen_utc": "2026-08-31 07:48:15",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CNSERVERS,CobaltStrike,cs-watermark-100000000",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1134127": [
        {
            "ioc_value": "check.judicical.ml",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-06-26 08:11:33",
            "last_seen_utc": "2026-08-31 07:48:15",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CNSERVERS,CobaltStrike,cs-watermark-100000000",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1133505": [
        {
            "ioc_value": "usadevgroup.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-06-22 17:12:29",
            "last_seen_utc": "2026-08-31 08:01:08",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-587247372,WAICORE-TRANSIT",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1128165": [
        {
            "ioc_value": "heastings.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-06-11 22:26:06",
            "last_seen_utc": "2026-08-31 08:01:08",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-206546002,M247",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1127715": [
        {
            "ioc_value": "unitechdb.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-06-09 20:00:05",
            "last_seen_utc": "2026-08-31 08:01:09",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1127713": [
        {
            "ioc_value": "cornptia.org",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-06-09 20:00:04",
            "last_seen_utc": "2026-08-31 08:01:08",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1127714": [
        {
            "ioc_value": "eyefinancemonitor.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-06-09 20:00:04",
            "last_seen_utc": "2026-08-31 08:01:08",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1127447": [
        {
            "ioc_value": "surplusofer.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-06-08 16:27:41",
            "last_seen_utc": "2026-08-31 08:01:08",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-206546002,HVC-AS",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1126556": [
        {
            "ioc_value": "ns3.fuckworldxxx.shop",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-06-05 09:01:38",
            "last_seen_utc": "2026-08-29 18:47:09",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-1234567890,Shenzhen Tencent Computer Systems Company Limited",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1126555": [
        {
            "ioc_value": "ns2.fuckworldxxx.shop",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-06-05 09:01:11",
            "last_seen_utc": "2026-08-29 18:47:09",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-1234567890,Shenzhen Tencent Computer Systems Company Limited",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1126554": [
        {
            "ioc_value": "ns1.fuckworldxxx.shop",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-06-05 09:00:46",
            "last_seen_utc": "2026-08-29 18:47:08",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-1234567890,Shenzhen Tencent Computer Systems Company Limited",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1122048": [
        {
            "ioc_value": "dianqi2.dianqi1.jiayongdianqi.xyz",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-05-25 15:42:02",
            "last_seen_utc": "2026-08-31 07:48:16",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-492498911,XNNET LLC",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1122047": [
        {
            "ioc_value": "dianqi1.dianqi2.jiayongdianqi.xyz",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-05-25 15:41:46",
            "last_seen_utc": "2026-08-31 07:48:16",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-492498911,XNNET LLC",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1122046": [
        {
            "ioc_value": "dianqi2.jiayongdianqi.xyz",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-05-25 15:41:31",
            "last_seen_utc": "2026-08-31 07:48:16",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-492498911,XNNET LLC",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1122045": [
        {
            "ioc_value": "dianqi1.jiayongdianqi.xyz",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-05-25 15:41:10",
            "last_seen_utc": "2026-08-31 07:48:16",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-492498911,XNNET LLC",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1121462": [
        {
            "ioc_value": "skynet-i.asuscomm.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-05-24 19:36:26",
            "last_seen_utc": "2026-08-31 07:48:19",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-987654321,STC-AS PJSC Rostelecom Krasnodar",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1121460": [
        {
            "ioc_value": "update.microsoftapply.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-05-24 19:35:48",
            "last_seen_utc": "2026-08-29 18:47:10",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-Not Found,DediPath",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1120772": [
        {
            "ioc_value": "australiansuper.xyz",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-05-23 12:37:36",
            "last_seen_utc": "2026-08-31 08:01:08",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "Amazon.com Inc.,CobaltStrike,cs-watermark-348901740",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1116637": [
        {
            "ioc_value": "sheersdesigns.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-05-16 10:00:03",
            "last_seen_utc": "2026-08-31 08:01:09",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1116636": [
        {
            "ioc_value": "artmicrodesign.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-05-16 10:00:02",
            "last_seen_utc": "2026-08-31 08:01:09",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1112839": [
        {
            "ioc_value": "situotech.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-05-06 16:13:31",
            "last_seen_utc": "2026-08-31 08:01:09",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-587247372,HARMONYHOSTING-AS",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1111492": [
        {
            "ioc_value": "157.245.155.179:9000",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pupy",
            "malware_alias": "Patpoopy",
            "malware_printable": "pupy",
            "first_seen_utc": "2023-05-05 12:42:12",
            "last_seen_utc": "2026-08-31 07:44:06",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/157.245.155.179",
            "tags": "DIGITALOCEAN-ASN,Pupy RAT",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1110863": [
        {
            "ioc_value": "39.106.36.96:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.deimos",
            "malware_alias": null,
            "malware_printable": "Deimos",
            "first_seen_utc": "2023-05-04 06:46:43",
            "last_seen_utc": "2026-08-31 07:47:00",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/39.106.36.96",
            "tags": "ALIBABA-CN-NET Hangzhou Alibaba Advertising Co.Ltd.,Deimos",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1110862": [
        {
            "ioc_value": "36.95.131.171:9091",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.deimos",
            "malware_alias": null,
            "malware_printable": "Deimos",
            "first_seen_utc": "2023-05-04 06:46:41",
            "last_seen_utc": "2026-08-31 07:46:53",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/36.95.131.171",
            "tags": "Deimos,TELKOMNET-AS-AP PT Telekomunikasi Indonesia",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1110860": [
        {
            "ioc_value": "18.162.155.202:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.deimos",
            "malware_alias": null,
            "malware_printable": "Deimos",
            "first_seen_utc": "2023-05-04 06:46:35",
            "last_seen_utc": "2026-08-31 07:44:37",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/18.162.155.202",
            "tags": "AMAZON-02,Deimos",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1110859": [
        {
            "ioc_value": "8.218.26.114:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.deimos",
            "malware_alias": null,
            "malware_printable": "Deimos",
            "first_seen_utc": "2023-05-04 06:46:33",
            "last_seen_utc": "2026-08-31 07:47:43",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/8.218.26.114",
            "tags": "ALIBABA-CN-NET Alibaba US Technology Co. Ltd.,Deimos",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1110858": [
        {
            "ioc_value": "3.209.12.178:3060",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.deimos",
            "malware_alias": null,
            "malware_printable": "Deimos",
            "first_seen_utc": "2023-05-04 06:46:30",
            "last_seen_utc": "2026-08-31 07:46:45",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/3.209.12.178",
            "tags": "AMAZON-AES,Deimos",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1106335": [
        {
            "ioc_value": "maboloud.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-04-22 18:00:03",
            "last_seen_utc": "2026-08-31 08:01:09",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1106336": [
        {
            "ioc_value": "matong.buzz",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-04-22 18:00:03",
            "last_seen_utc": "2026-08-31 08:01:09",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1105988": [
        {
            "ioc_value": "qw.sveexec.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-04-21 10:20:17",
            "last_seen_utc": "2026-08-31 08:01:09",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-1580103824,GLOBALLAYER",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1103771": [
        {
            "ioc_value": "77.242.250.36:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-04-15 12:28:52",
            "last_seen_utc": "2026-08-31 08:00:54",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-1416875320",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1102558": [
        {
            "ioc_value": "lls-rs.org",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-04-12 09:02:56",
            "last_seen_utc": "2026-08-31 08:01:09",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-0,PROSPERO-AS",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1096685": [
        {
            "ioc_value": "iony.top",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-04-03 07:21:03",
            "last_seen_utc": "2026-08-31 08:01:09",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1096686": [
        {
            "ioc_value": "office36o.online",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-04-03 07:21:03",
            "last_seen_utc": "2026-08-31 08:01:10",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1096683": [
        {
            "ioc_value": "feyrijavac.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-04-03 07:21:02",
            "last_seen_utc": "2026-08-31 08:01:09",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1096684": [
        {
            "ioc_value": "fidelyus.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-04-03 07:21:02",
            "last_seen_utc": "2026-08-31 08:01:09",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1095276": [
        {
            "ioc_value": "jacketsupport.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-03-29 22:27:30",
            "last_seen_utc": "2026-08-31 08:01:09",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-587247372,GLOBALLAYER",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1095042": [
        {
            "ioc_value": "duckducklive.top",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-03-29 04:51:21",
            "last_seen_utc": "2026-08-31 08:01:09",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://www.virustotal.com/gui/file/b5da1db6d69f2f872e603beb0f121c68f3320ed33a0c9835bfc1a931d177c947",
            "tags": "391144938,Beacon,Cobalt Strike,CobaltStrike",
            "anonymous": 0,
            "reporter": "AndreGironda"
        }
    ],
    "1094484": [
        {
            "ioc_value": "louvree.abudhabe.info",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-03-28 15:52:23",
            "last_seen_utc": "2026-08-31 08:01:07",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-1826426664,EMIRATES-INTERNET Emirates Internet",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1092077": [
        {
            "ioc_value": "jquerymaingame.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-03-20 17:21:02",
            "last_seen_utc": "2026-08-31 08:01:10",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1092078": [
        {
            "ioc_value": "mail-my-account.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-03-20 17:21:02",
            "last_seen_utc": "2026-08-31 08:01:10",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1092079": [
        {
            "ioc_value": "my-accounts-gooogle.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-03-20 17:21:02",
            "last_seen_utc": "2026-08-31 08:01:10",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1092080": [
        {
            "ioc_value": "pegistrationads.site",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-03-20 17:21:02",
            "last_seen_utc": "2026-08-31 08:01:10",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1092075": [
        {
            "ioc_value": "eaglehardwares.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-03-20 17:21:01",
            "last_seen_utc": "2026-08-31 08:01:10",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1092076": [
        {
            "ioc_value": "information.baby",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-03-20 17:21:01",
            "last_seen_utc": "2026-08-31 08:01:10",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1092009": [
        {
            "ioc_value": "moviegallerys.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-03-20 13:36:29",
            "last_seen_utc": "2026-08-31 08:01:10",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-206546002,UAB Cherry Servers",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1091575": [
        {
            "ioc_value": "acroserver.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-03-17 22:40:17",
            "last_seen_utc": "2026-08-31 08:01:10",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-674054486,Flyservers S.A.",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1091535": [
        {
            "ioc_value": "atechniques.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-03-17 19:45:49",
            "last_seen_utc": "2026-08-31 08:01:10",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "AEZA-AS,CobaltStrike,cs-watermark-674054486",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1091454": [
        {
            "ioc_value": "winsatoom.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-03-17 13:33:15",
            "last_seen_utc": "2026-08-31 08:01:10",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "AS-CHOOPA,CobaltStrike,cs-watermark-668694132",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1087542": [
        {
            "ioc_value": "devoinnanote.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-03-13 04:47:12",
            "last_seen_utc": "2026-08-31 08:01:10",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-2130772225,SHARKTECH",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1082976": [
        {
            "ioc_value": "ponzinivek.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-02-26 09:03:09",
            "last_seen_utc": "2026-08-31 08:01:12",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1082977": [
        {
            "ioc_value": "ruplearben.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-02-26 09:03:09",
            "last_seen_utc": "2026-08-31 08:01:12",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1082978": [
        {
            "ioc_value": "talonbilling.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-02-26 09:03:09",
            "last_seen_utc": "2026-08-31 08:01:12",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1082979": [
        {
            "ioc_value": "gorillagaz.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-02-26 09:03:09",
            "last_seen_utc": "2026-08-31 08:01:12",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1082980": [
        {
            "ioc_value": "chanimoblie.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-02-26 09:03:09",
            "last_seen_utc": "2026-08-31 08:01:12",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1082871": [
        {
            "ioc_value": "kbnexc.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-02-25 14:42:02",
            "last_seen_utc": "2026-08-31 08:01:11",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1082870": [
        {
            "ioc_value": "jquerysslx.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-02-25 14:42:01",
            "last_seen_utc": "2026-08-31 08:01:11",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1082838": [
        {
            "ioc_value": "e-servicesolutions.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-02-25 13:15:07",
            "last_seen_utc": "2026-08-31 08:01:10",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "AEZA GROUP Ltd,CobaltStrike,cs-watermark-674054486",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1082591": [
        {
            "ioc_value": "devsecurityservices.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-02-24 02:30:56",
            "last_seen_utc": "2026-08-31 08:01:11",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-674054486,Flyservers S.A.",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1082417": [
        {
            "ioc_value": "www.vmware.rest",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-02-23 13:06:07",
            "last_seen_utc": "2026-08-31 08:01:13",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "AS-CHOOPA,CobaltStrike,cs-watermark-1234567890",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1081018": [
        {
            "ioc_value": "galspost.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-02-17 18:25:01",
            "last_seen_utc": "2026-08-31 08:01:11",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-1101991775,Microsoft Corporation",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1080735": [
        {
            "ioc_value": "imvcatool.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-02-16 14:54:22",
            "last_seen_utc": "2026-08-31 08:01:11",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "AEZA-AS,CobaltStrike,cs-watermark-674054486",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1078198": [
        {
            "ioc_value": "aspnetcenter.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-02-04 19:39:46",
            "last_seen_utc": "2026-08-31 08:01:12",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,Web Gostaran Bandar Company PJS",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1078172": [
        {
            "ioc_value": "audelr.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-02-04 18:42:02",
            "last_seen_utc": "2026-08-31 08:01:13",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1078173": [
        {
            "ioc_value": "csou.link",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-02-04 18:42:02",
            "last_seen_utc": "2026-08-31 08:01:13",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1078174": [
        {
            "ioc_value": "integrated-security.net",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-02-04 18:42:02",
            "last_seen_utc": "2026-08-31 08:01:13",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1078175": [
        {
            "ioc_value": "uranustechsolution.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-02-04 18:42:02",
            "last_seen_utc": "2026-08-31 08:01:13",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1078062": [
        {
            "ioc_value": "getsafeblog.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-02-03 17:24:39",
            "last_seen_utc": "2026-08-31 08:01:13",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,PLI-AS",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1076907": [
        {
            "ioc_value": "qw.svcshosvt.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-02-02 19:40:26",
            "last_seen_utc": "2026-08-31 08:01:11",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CHERRYSERVERS2-AS,CobaltStrike",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1076896": [
        {
            "ioc_value": "nxsimdevelop.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-02-02 19:39:18",
            "last_seen_utc": "2026-08-31 08:01:11",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "AEZA-AS,CobaltStrike",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1075651": [
        {
            "ioc_value": "appdevtechnology.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-02-01 02:21:19",
            "last_seen_utc": "2026-08-31 08:01:11",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "AEZA-AS,CobaltStrike",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1075540": [
        {
            "ioc_value": "dbx.formsift.io",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-01-31 15:09:13",
            "last_seen_utc": "2026-08-31 08:01:11",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "Amazon.com Inc.,CobaltStrike",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1075020": [
        {
            "ioc_value": "devcloudpro.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-01-29 11:29:55",
            "last_seen_utc": "2026-08-31 08:01:13",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,FLYSERVERS-ENDCLIENTS",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1074894": [
        {
            "ioc_value": "164.90.158.199:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2023-01-28 09:40:24",
            "last_seen_utc": "2026-08-31 07:44:14",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/164.90.158.199",
            "tags": "DIGITALOCEAN-ASN,Mythic",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1074144": [
        {
            "ioc_value": "support-wellsfargovis.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-01-25 19:42:03",
            "last_seen_utc": "2026-08-31 08:01:14",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1074141": [
        {
            "ioc_value": "recoverporta1.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-01-25 19:42:02",
            "last_seen_utc": "2026-08-31 08:01:14",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1074142": [
        {
            "ioc_value": "recoverportal2.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-01-25 19:42:02",
            "last_seen_utc": "2026-08-31 08:01:14",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1074143": [
        {
            "ioc_value": "recoveryweb2.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-01-25 19:42:02",
            "last_seen_utc": "2026-08-31 08:01:14",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1073670": [
        {
            "ioc_value": "vd-ntds.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-01-23 20:33:42",
            "last_seen_utc": "2026-08-31 08:01:12",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,PROSPERO-AS",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1070164": [
        {
            "ioc_value": "hnsxpharm.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-01-20 14:21:02",
            "last_seen_utc": "2026-08-31 08:01:14",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1070165": [
        {
            "ioc_value": "myjqueryss.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-01-20 14:21:02",
            "last_seen_utc": "2026-08-31 08:01:14",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1070167": [
        {
            "ioc_value": "telusmobility-billed.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-01-20 14:21:02",
            "last_seen_utc": "2026-08-31 08:01:15",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1070168": [
        {
            "ioc_value": "thenbkgroup.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-01-20 14:21:02",
            "last_seen_utc": "2026-08-31 08:01:15",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1070137": [
        {
            "ioc_value": "avdev.net",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-01-20 11:23:14",
            "last_seen_utc": "2026-08-31 08:01:13",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,Flyservers S.A.",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1069980": [
        {
            "ioc_value": "qw.execsvct.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-01-19 19:53:20",
            "last_seen_utc": "2026-08-31 08:01:13",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CHERRYSERVERS2-AS,CobaltStrike",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1069895": [
        {
            "ioc_value": "azurecloudfire.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-01-19 14:15:53",
            "last_seen_utc": "2026-08-31 08:01:13",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,ITRESHENIYA-AS",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1069868": [
        {
            "ioc_value": "goupdatemic.online",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-01-19 11:23:42",
            "last_seen_utc": "2026-08-31 08:01:14",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,GOOGLE",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1069579": [
        {
            "ioc_value": "mwg-update.cloud",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-01-18 02:29:29",
            "last_seen_utc": "2026-08-31 08:01:14",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,HVC-AS",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1068206": [
        {
            "ioc_value": "goodsport2023.win",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-01-13 17:37:32",
            "last_seen_utc": "2026-08-31 08:01:14",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,VOM",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1068079": [
        {
            "ioc_value": "blackandwhiteshoose.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-01-12 21:56:23",
            "last_seen_utc": "2026-08-31 08:01:14",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CHERRYSERVERS3-AS,CobaltStrike",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1068045": [
        {
            "ioc_value": "qw.svcrencst.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-01-12 20:55:06",
            "last_seen_utc": "2026-08-31 08:01:15",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CHERRYSERVERS2-AS,CobaltStrike",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1067954": [
        {
            "ioc_value": "realsecuritystore.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-01-12 14:45:18",
            "last_seen_utc": "2026-08-31 08:01:15",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,Private Layer INC",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1067924": [
        {
            "ioc_value": "fixx.sbs",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-01-12 13:04:56",
            "last_seen_utc": "2026-08-31 08:01:11",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,SNEL",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1067646": [
        {
            "ioc_value": "allowedcloud.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-01-11 10:59:45",
            "last_seen_utc": "2026-08-31 08:01:12",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,HIVELOCITY Inc.",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1064196": [
        {
            "ioc_value": "freegaysnews.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-31 19:48:39",
            "last_seen_utc": "2026-08-31 08:01:15",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CHERRYSERVERS2-AS,CobaltStrike",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1064176": [
        {
            "ioc_value": "topgamenetwork.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-31 18:58:09",
            "last_seen_utc": "2026-08-31 08:01:15",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,UAB Cherry Servers",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1064173": [
        {
            "ioc_value": "zfuxwvouqvnttpsrxe.tech",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-31 16:21:02",
            "last_seen_utc": "2026-08-31 08:01:16",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1064075": [
        {
            "ioc_value": "cloudyspaces.net",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:52",
            "last_seen_utc": "2026-08-31 08:02:06",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1064076": [
        {
            "ioc_value": "666621.xyz",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:52",
            "last_seen_utc": "2026-08-31 08:02:06",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1064069": [
        {
            "ioc_value": "144.217.207.19:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:51",
            "last_seen_utc": "2026-08-31 08:02:05",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1064070": [
        {
            "ioc_value": "allsdone.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:51",
            "last_seen_utc": "2026-08-31 08:02:05",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1064071": [
        {
            "ioc_value": "ipsandwich.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:51",
            "last_seen_utc": "2026-08-31 08:02:05",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1064072": [
        {
            "ioc_value": "cookieholder.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:51",
            "last_seen_utc": "2026-08-31 08:02:05",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1064073": [
        {
            "ioc_value": "pingcheker.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:51",
            "last_seen_utc": "2026-08-31 08:02:05",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1064074": [
        {
            "ioc_value": "wagonovk.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:51",
            "last_seen_utc": "2026-08-31 08:02:05",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1064062": [
        {
            "ioc_value": "microsoftupdateassist.net",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:50",
            "last_seen_utc": "2026-08-31 08:02:03",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1064063": [
        {
            "ioc_value": "qvibova.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:50",
            "last_seen_utc": "2026-08-31 08:02:04",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1064064": [
        {
            "ioc_value": "cloudwebpictures.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:50",
            "last_seen_utc": "2026-08-31 08:02:04",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1064065": [
        {
            "ioc_value": "metalkost.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:50",
            "last_seen_utc": "2026-08-31 08:02:04",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1064066": [
        {
            "ioc_value": "m7r4r2i2.stackpathcdn.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:50",
            "last_seen_utc": "2026-08-31 08:02:04",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1064067": [
        {
            "ioc_value": "online.cloudwebpictures.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:50",
            "last_seen_utc": "2026-08-31 08:02:04",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1064057": [
        {
            "ioc_value": "bartiba.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:49",
            "last_seen_utc": "2026-08-31 08:02:02",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1064058": [
        {
            "ioc_value": "varnart.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:49",
            "last_seen_utc": "2026-08-31 08:02:02",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1064059": [
        {
            "ioc_value": "nsfdfdfdf.xyz",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:49",
            "last_seen_utc": "2026-08-31 08:02:02",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1064060": [
        {
            "ioc_value": "micorsoft.cloud",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:49",
            "last_seen_utc": "2026-08-31 08:02:03",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1064061": [
        {
            "ioc_value": "aigouing.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:49",
            "last_seen_utc": "2026-08-31 08:02:03",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1064046": [
        {
            "ioc_value": "ksplsoft.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:48",
            "last_seen_utc": "2026-08-31 08:02:01",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1064047": [
        {
            "ioc_value": "lastinsuranceteam.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:48",
            "last_seen_utc": "2026-08-31 08:02:01",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1064048": [
        {
            "ioc_value": "msdnsservice.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:48",
            "last_seen_utc": "2026-08-31 08:02:00",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1064049": [
        {
            "ioc_value": "securequoteme.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:48",
            "last_seen_utc": "2026-08-31 08:02:02",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1064050": [
        {
            "ioc_value": "techdevcorp.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:48",
            "last_seen_utc": "2026-08-31 08:02:01",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1064051": [
        {
            "ioc_value": "syncorporation.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:48",
            "last_seen_utc": "2026-08-31 08:02:01",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1064052": [
        {
            "ioc_value": "visualstudioapp.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:48",
            "last_seen_utc": "2026-08-31 08:02:01",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1064053": [
        {
            "ioc_value": "altreeservicellc.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:48",
            "last_seen_utc": "2026-08-31 08:02:01",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1064054": [
        {
            "ioc_value": "discountshadesdirect.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:48",
            "last_seen_utc": "2026-08-31 08:02:01",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1064055": [
        {
            "ioc_value": "setechnowork.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:48",
            "last_seen_utc": "2026-08-31 08:02:01",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1064056": [
        {
            "ioc_value": "technicollit.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:48",
            "last_seen_utc": "2026-08-31 08:02:01",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1064038": [
        {
            "ioc_value": "shiyicaster.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:47",
            "last_seen_utc": "2026-08-31 08:01:59",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1064039": [
        {
            "ioc_value": "cdn-top.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:47",
            "last_seen_utc": "2026-08-31 08:02:03",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1064040": [
        {
            "ioc_value": "onesecondservice.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:47",
            "last_seen_utc": "2026-08-31 08:01:59",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1064041": [
        {
            "ioc_value": "vpnupdaters.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:47",
            "last_seen_utc": "2026-08-31 08:01:59",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1064042": [
        {
            "ioc_value": "rodinscoldly.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:47",
            "last_seen_utc": "2026-08-31 08:02:00",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1064043": [
        {
            "ioc_value": "antariscapital.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:47",
            "last_seen_utc": "2026-08-31 08:02:00",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1064044": [
        {
            "ioc_value": "ftwealthmgt.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:47",
            "last_seen_utc": "2026-08-31 08:02:00",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1064045": [
        {
            "ioc_value": "iconiq-capitel.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:47",
            "last_seen_utc": "2026-08-31 08:02:00",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1064031": [
        {
            "ioc_value": "asset-trades.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:46",
            "last_seen_utc": "2026-08-31 08:01:58",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1064032": [
        {
            "ioc_value": "telemetrin.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:46",
            "last_seen_utc": "2026-08-31 08:01:58",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1064033": [
        {
            "ioc_value": "secupdate4win.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:46",
            "last_seen_utc": "2026-08-31 08:01:58",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1064034": [
        {
            "ioc_value": "cdn-start.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:46",
            "last_seen_utc": "2026-08-31 08:01:59",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1064035": [
        {
            "ioc_value": "capitalmanagementdata.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:46",
            "last_seen_utc": "2026-08-31 08:02:03",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1064036": [
        {
            "ioc_value": "lawsolutions.cloud",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:46",
            "last_seen_utc": "2026-08-31 08:01:59",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1064024": [
        {
            "ioc_value": "diegomaster.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:45",
            "last_seen_utc": "2026-08-31 08:01:57",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1064025": [
        {
            "ioc_value": "dp-test1.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:45",
            "last_seen_utc": "2026-08-31 08:01:57",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1064026": [
        {
            "ioc_value": "cloudkey.digital",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:45",
            "last_seen_utc": "2026-08-31 08:01:58",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1064027": [
        {
            "ioc_value": "updatevpncitrix.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:45",
            "last_seen_utc": "2026-08-31 08:01:58",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1064028": [
        {
            "ioc_value": "classgum.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:45",
            "last_seen_utc": "2026-08-31 08:01:58",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1064029": [
        {
            "ioc_value": "edgeupdater.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:45",
            "last_seen_utc": "2026-08-31 08:01:58",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1064030": [
        {
            "ioc_value": "gfcbm.xyz",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:45",
            "last_seen_utc": "2026-08-31 08:01:58",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1064016": [
        {
            "ioc_value": "barmnava.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:44",
            "last_seen_utc": "2026-08-31 08:01:56",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1064017": [
        {
            "ioc_value": "firewallwithadvancedserurity.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:44",
            "last_seen_utc": "2026-08-31 08:01:56",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1064018": [
        {
            "ioc_value": "lgbtqplusfriendlydomain.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:44",
            "last_seen_utc": "2026-08-31 08:01:56",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1064019": [
        {
            "ioc_value": "market-stats.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:44",
            "last_seen_utc": "2026-08-31 08:01:56",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1064020": [
        {
            "ioc_value": "apabfs.icu",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:44",
            "last_seen_utc": "2026-08-31 08:01:56",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1064021": [
        {
            "ioc_value": "fziomerof.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:44",
            "last_seen_utc": "2026-08-31 08:01:57",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1064022": [
        {
            "ioc_value": "fserd.icu",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:44",
            "last_seen_utc": "2026-08-31 08:01:57",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1064023": [
        {
            "ioc_value": "verofes.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:44",
            "last_seen_utc": "2026-08-31 08:01:57",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1064015": [
        {
            "ioc_value": "postofficeltdc.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:43",
            "last_seen_utc": "2026-08-31 08:01:55",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1064006": [
        {
            "ioc_value": "jarvcza.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:42",
            "last_seen_utc": "2026-08-31 08:01:54",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1064007": [
        {
            "ioc_value": "teystyjeem.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:42",
            "last_seen_utc": "2026-08-31 08:01:59",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1064008": [
        {
            "ioc_value": "faceupfinder.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:42",
            "last_seen_utc": "2026-08-31 08:01:54",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1064009": [
        {
            "ioc_value": "costacancordia.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:42",
            "last_seen_utc": "2026-08-31 08:01:58",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1064010": [
        {
            "ioc_value": "lapsusareskids.world",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:42",
            "last_seen_utc": "2026-08-31 08:01:54",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1064011": [
        {
            "ioc_value": "msupdater.net",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:42",
            "last_seen_utc": "2026-08-31 08:01:54",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1064012": [
        {
            "ioc_value": "dwordname.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:42",
            "last_seen_utc": "2026-08-31 08:01:54",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1064013": [
        {
            "ioc_value": "trademot.finance",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:42",
            "last_seen_utc": "2026-08-31 08:01:54",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1064014": [
        {
            "ioc_value": "agreminj.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:42",
            "last_seen_utc": "2026-08-31 08:01:54",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063998": [
        {
            "ioc_value": "exchangeallltd.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:41",
            "last_seen_utc": "2026-08-31 08:01:53",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063999": [
        {
            "ioc_value": "guggenheimpartners-survey.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:41",
            "last_seen_utc": "2026-08-31 08:01:53",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1064000": [
        {
            "ioc_value": "caresalonservices.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:41",
            "last_seen_utc": "2026-08-31 08:01:53",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1064001": [
        {
            "ioc_value": "just-findncall.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:41",
            "last_seen_utc": "2026-08-31 08:01:53",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1064002": [
        {
            "ioc_value": "fluoxi.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:41",
            "last_seen_utc": "2026-08-31 08:01:53",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1064003": [
        {
            "ioc_value": "buynet.digital",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:41",
            "last_seen_utc": "2026-08-31 08:01:53",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1064004": [
        {
            "ioc_value": "everythingchecker.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:41",
            "last_seen_utc": "2026-08-31 08:01:53",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1064005": [
        {
            "ioc_value": "dezword.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:41",
            "last_seen_utc": "2026-08-31 08:01:54",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063995": [
        {
            "ioc_value": "goksearch.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:40",
            "last_seen_utc": "2026-08-31 08:01:52",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063996": [
        {
            "ioc_value": "polyhaz.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:40",
            "last_seen_utc": "2026-08-31 08:01:52",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063997": [
        {
            "ioc_value": "data-protection-test.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:40",
            "last_seen_utc": "2026-08-31 08:01:53",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063992": [
        {
            "ioc_value": "update04.microsoft-essentials.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:39",
            "last_seen_utc": "2026-08-31 08:01:51",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063991": [
        {
            "ioc_value": "akaluij.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:38",
            "last_seen_utc": "2026-08-31 08:01:53",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063989": [
        {
            "ioc_value": "43.129.7.189:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:36",
            "last_seen_utc": "2026-08-31 08:01:47",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063990": [
        {
            "ioc_value": "82.156.241.148:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:36",
            "last_seen_utc": "2026-08-31 08:01:51",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063985": [
        {
            "ioc_value": "donormix.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:33",
            "last_seen_utc": "2026-08-31 08:01:43",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063986": [
        {
            "ioc_value": "hardicki.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:33",
            "last_seen_utc": "2026-08-31 08:01:57",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063987": [
        {
            "ioc_value": "stfconnect.onthewifi.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:33",
            "last_seen_utc": "2026-08-31 08:01:52",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063988": [
        {
            "ioc_value": "agsdef.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:33",
            "last_seen_utc": "2026-08-31 08:01:50",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063978": [
        {
            "ioc_value": "observerinfo.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:32",
            "last_seen_utc": "2026-08-31 08:01:44",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063979": [
        {
            "ioc_value": "dehikz.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:32",
            "last_seen_utc": "2026-08-31 08:01:42",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063980": [
        {
            "ioc_value": "cocanewline.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:32",
            "last_seen_utc": "2026-08-31 08:01:43",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063981": [
        {
            "ioc_value": "rainqor.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:32",
            "last_seen_utc": "2026-08-31 08:01:43",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063982": [
        {
            "ioc_value": "axelkim.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:32",
            "last_seen_utc": "2026-08-31 08:01:55",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063983": [
        {
            "ioc_value": "azimurs.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:32",
            "last_seen_utc": "2026-08-31 08:01:53",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063984": [
        {
            "ioc_value": "innovativesitecreations.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:32",
            "last_seen_utc": "2026-08-31 08:01:43",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063972": [
        {
            "ioc_value": "creditscore.usbankcreditcards.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:31",
            "last_seen_utc": "2026-08-31 08:01:41",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063975": [
        {
            "ioc_value": "megumin.tech",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:31",
            "last_seen_utc": "2026-08-31 08:01:42",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063976": [
        {
            "ioc_value": "loanhelp.support",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:31",
            "last_seen_utc": "2026-08-31 08:01:42",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063977": [
        {
            "ioc_value": "volsecure.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:31",
            "last_seen_utc": "2026-08-31 08:01:44",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063966": [
        {
            "ioc_value": "domtern.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:30",
            "last_seen_utc": "2026-08-31 08:01:41",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063968": [
        {
            "ioc_value": "drakr.icu",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:30",
            "last_seen_utc": "2026-08-31 08:01:43",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063969": [
        {
            "ioc_value": "devcisco.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:30",
            "last_seen_utc": "2026-08-31 08:01:41",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063971": [
        {
            "ioc_value": "web-news-blog.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:30",
            "last_seen_utc": "2026-08-31 08:01:41",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063963": [
        {
            "ioc_value": "bankafrika.org",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:29",
            "last_seen_utc": "2026-08-31 08:01:39",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063964": [
        {
            "ioc_value": "mssfr.icu",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:29",
            "last_seen_utc": "2026-08-31 08:01:40",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063965": [
        {
            "ioc_value": "edgekey.tech",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:29",
            "last_seen_utc": "2026-08-31 08:01:40",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063955": [
        {
            "ioc_value": "webyoutubeshop.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:28",
            "last_seen_utc": "2026-08-31 08:01:38",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063956": [
        {
            "ioc_value": "extic.icu",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:28",
            "last_seen_utc": "2026-08-31 08:01:38",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063957": [
        {
            "ioc_value": "reykh.icu",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:28",
            "last_seen_utc": "2026-08-31 08:01:38",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063959": [
        {
            "ioc_value": "propertynewsclub.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:28",
            "last_seen_utc": "2026-08-31 08:01:39",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063960": [
        {
            "ioc_value": "afindisc.xyz",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:28",
            "last_seen_utc": "2026-08-31 08:01:39",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063961": [
        {
            "ioc_value": "propertyinfogroup.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:28",
            "last_seen_utc": "2026-08-31 08:01:39",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063962": [
        {
            "ioc_value": "topnewscompany.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:28",
            "last_seen_utc": "2026-08-31 08:01:39",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063950": [
        {
            "ioc_value": "baidenfree.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:27",
            "last_seen_utc": "2026-08-31 08:01:37",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063951": [
        {
            "ioc_value": "directoryupdate.net",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:27",
            "last_seen_utc": "2026-08-31 08:01:37",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063952": [
        {
            "ioc_value": "azmnetwork.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:27",
            "last_seen_utc": "2026-08-31 08:01:37",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063953": [
        {
            "ioc_value": "onevisioncommunications.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:27",
            "last_seen_utc": "2026-08-31 08:01:38",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063954": [
        {
            "ioc_value": "campioni-imam.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:27",
            "last_seen_utc": "2026-08-31 08:01:38",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063943": [
        {
            "ioc_value": "serviceapp1.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:26",
            "last_seen_utc": "2026-08-31 08:01:36",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063944": [
        {
            "ioc_value": "softcloud.digital",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:26",
            "last_seen_utc": "2026-08-31 08:01:36",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063945": [
        {
            "ioc_value": "appmind.center",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:26",
            "last_seen_utc": "2026-08-31 08:01:36",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063946": [
        {
            "ioc_value": "ms-data.online",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:26",
            "last_seen_utc": "2026-08-31 08:01:36",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063947": [
        {
            "ioc_value": "oracleup.cc",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:26",
            "last_seen_utc": "2026-08-31 08:01:36",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063948": [
        {
            "ioc_value": "topinfocompany.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:26",
            "last_seen_utc": "2026-08-31 08:01:37",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063949": [
        {
            "ioc_value": "blockchainstartups-crypto.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:26",
            "last_seen_utc": "2026-08-31 08:01:37",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063934": [
        {
            "ioc_value": "expresssmash.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:25",
            "last_seen_utc": "2026-08-31 08:01:35",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063935": [
        {
            "ioc_value": "vgroz.icu",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:25",
            "last_seen_utc": "2026-08-31 08:01:37",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063936": [
        {
            "ioc_value": "baidengop.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:25",
            "last_seen_utc": "2026-08-31 08:01:35",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063937": [
        {
            "ioc_value": "ofilopex.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:25",
            "last_seen_utc": "2026-08-31 08:01:35",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063938": [
        {
            "ioc_value": "aabancaa.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:25",
            "last_seen_utc": "2026-08-31 08:01:36",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063939": [
        {
            "ioc_value": "shermango.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:25",
            "last_seen_utc": "2026-08-31 08:01:36",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063940": [
        {
            "ioc_value": "nongxinyin.xyz",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:25",
            "last_seen_utc": "2026-08-31 08:01:36",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063941": [
        {
            "ioc_value": "a6m1n.xyz",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:25",
            "last_seen_utc": "2026-08-31 08:01:36",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063942": [
        {
            "ioc_value": "emailbox.icu",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:25",
            "last_seen_utc": "2026-08-31 08:01:36",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063926": [
        {
            "ioc_value": "wxtencent.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:24",
            "last_seen_utc": "2026-08-31 08:01:34",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063927": [
        {
            "ioc_value": "emergeno.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:24",
            "last_seen_utc": "2026-08-31 08:01:34",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063928": [
        {
            "ioc_value": "browngreeer.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:24",
            "last_seen_utc": "2026-08-31 08:01:35",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063929": [
        {
            "ioc_value": "processdec.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:24",
            "last_seen_utc": "2026-08-31 08:01:35",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063931": [
        {
            "ioc_value": "sndm-sndm.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:24",
            "last_seen_utc": "2026-08-31 08:01:35",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063932": [
        {
            "ioc_value": "sinergil.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:24",
            "last_seen_utc": "2026-08-31 08:01:35",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063933": [
        {
            "ioc_value": "vinergil.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:24",
            "last_seen_utc": "2026-08-31 08:01:35",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063918": [
        {
            "ioc_value": "westtherr.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:23",
            "last_seen_utc": "2026-08-31 08:01:34",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063919": [
        {
            "ioc_value": "quickaccestwo.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:23",
            "last_seen_utc": "2026-08-31 08:01:34",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063920": [
        {
            "ioc_value": "usgrim.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:23",
            "last_seen_utc": "2026-08-31 08:01:34",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063921": [
        {
            "ioc_value": "onelivemusicshop.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:23",
            "last_seen_utc": "2026-08-31 08:01:34",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063922": [
        {
            "ioc_value": "zomerax.top",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:23",
            "last_seen_utc": "2026-08-31 08:01:34",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063923": [
        {
            "ioc_value": "fsamon.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:23",
            "last_seen_utc": "2026-08-31 08:01:34",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063924": [
        {
            "ioc_value": "sscimails.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:23",
            "last_seen_utc": "2026-08-31 08:01:34",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063925": [
        {
            "ioc_value": "agentrecovery.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:23",
            "last_seen_utc": "2026-08-31 08:01:39",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063909": [
        {
            "ioc_value": "entertainok.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:22",
            "last_seen_utc": "2026-08-31 08:01:33",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063910": [
        {
            "ioc_value": "jatafatuna.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:22",
            "last_seen_utc": "2026-08-31 08:01:33",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063911": [
        {
            "ioc_value": "pluyk.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:22",
            "last_seen_utc": "2026-08-31 08:01:33",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063912": [
        {
            "ioc_value": "affinm.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:22",
            "last_seen_utc": "2026-08-31 08:01:33",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063913": [
        {
            "ioc_value": "gijoxupe.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:22",
            "last_seen_utc": "2026-08-31 08:01:33",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063914": [
        {
            "ioc_value": "vangshares.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:22",
            "last_seen_utc": "2026-08-31 08:01:35",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063915": [
        {
            "ioc_value": "fudupdate.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:22",
            "last_seen_utc": "2026-08-31 08:01:33",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063917": [
        {
            "ioc_value": "contemporaryto.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:22",
            "last_seen_utc": "2026-08-31 08:01:33",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063902": [
        {
            "ioc_value": "ziono.xyz",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:21",
            "last_seen_utc": "2026-08-31 08:01:32",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063903": [
        {
            "ioc_value": "lolutow.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:21",
            "last_seen_utc": "2026-08-31 08:01:32",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063904": [
        {
            "ioc_value": "niht12.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:21",
            "last_seen_utc": "2026-08-31 08:01:32",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063905": [
        {
            "ioc_value": "slfcorporate.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:21",
            "last_seen_utc": "2026-08-31 08:01:32",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063906": [
        {
            "ioc_value": "baidu-cdn-10.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:21",
            "last_seen_utc": "2026-08-31 08:01:32",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063907": [
        {
            "ioc_value": "jandoz.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:21",
            "last_seen_utc": "2026-08-31 08:01:32",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063908": [
        {
            "ioc_value": "casevor.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:21",
            "last_seen_utc": "2026-08-31 08:01:33",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063897": [
        {
            "ioc_value": "gotroops.online",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:20",
            "last_seen_utc": "2026-08-31 08:01:31",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063898": [
        {
            "ioc_value": "wtxservice.net",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:20",
            "last_seen_utc": "2026-08-31 08:01:31",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063899": [
        {
            "ioc_value": "xevayuhace.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:20",
            "last_seen_utc": "2026-08-31 08:01:32",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063900": [
        {
            "ioc_value": "suppcat.online",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:20",
            "last_seen_utc": "2026-08-31 08:01:32",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063901": [
        {
            "ioc_value": "softloadup.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:20",
            "last_seen_utc": "2026-08-31 08:01:32",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063889": [
        {
            "ioc_value": "asbetysh.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:19",
            "last_seen_utc": "2026-08-31 08:01:29",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063890": [
        {
            "ioc_value": "ascagliarinish.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:19",
            "last_seen_utc": "2026-08-31 08:01:30",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063891": [
        {
            "ioc_value": "ascasdsh.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:19",
            "last_seen_utc": "2026-08-31 08:01:30",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063892": [
        {
            "ioc_value": "aschamp79sh.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:19",
            "last_seen_utc": "2026-08-31 08:01:30",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063893": [
        {
            "ioc_value": "aschnurmansh.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:19",
            "last_seen_utc": "2026-08-31 08:01:30",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063894": [
        {
            "ioc_value": "aseleeeksh.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:19",
            "last_seen_utc": "2026-08-31 08:01:30",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063895": [
        {
            "ioc_value": "asensvsh.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:19",
            "last_seen_utc": "2026-08-31 08:01:30",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063880": [
        {
            "ioc_value": "artist2actresssh.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:18",
            "last_seen_utc": "2026-08-31 08:01:29",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063881": [
        {
            "ioc_value": "arturprikhodkosh.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:18",
            "last_seen_utc": "2026-08-31 08:01:29",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063882": [
        {
            "ioc_value": "arvin78sh.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:18",
            "last_seen_utc": "2026-08-31 08:01:29",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063883": [
        {
            "ioc_value": "arvind567shahsh.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:18",
            "last_seen_utc": "2026-08-31 08:01:29",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063884": [
        {
            "ioc_value": "arvindkkumsh.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:18",
            "last_seen_utc": "2026-08-31 08:01:29",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063885": [
        {
            "ioc_value": "arvosash.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:18",
            "last_seen_utc": "2026-08-31 08:01:29",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063886": [
        {
            "ioc_value": "arwalsersh.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:18",
            "last_seen_utc": "2026-08-31 08:01:29",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063887": [
        {
            "ioc_value": "aryaarieash.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:18",
            "last_seen_utc": "2026-08-31 08:01:29",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063888": [
        {
            "ioc_value": "aryalalexsh.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:18",
            "last_seen_utc": "2026-08-31 08:01:29",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063870": [
        {
            "ioc_value": "dovaxanil.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:17",
            "last_seen_utc": "2026-08-31 08:01:28",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063871": [
        {
            "ioc_value": "hehegahu.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:17",
            "last_seen_utc": "2026-08-31 08:01:28",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063872": [
        {
            "ioc_value": "agriculturemachineries.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:17",
            "last_seen_utc": "2026-08-31 08:01:33",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063873": [
        {
            "ioc_value": "arhipenkolenagenesh.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:17",
            "last_seen_utc": "2026-08-31 08:01:28",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063874": [
        {
            "ioc_value": "aritmiagenesh.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:17",
            "last_seen_utc": "2026-08-31 08:01:28",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063875": [
        {
            "ioc_value": "artes911sh.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:17",
            "last_seen_utc": "2026-08-31 08:01:28",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063876": [
        {
            "ioc_value": "arthas89sh.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:17",
            "last_seen_utc": "2026-08-31 08:01:28",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063877": [
        {
            "ioc_value": "arthurstevens62sh.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:17",
            "last_seen_utc": "2026-08-31 08:01:29",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063878": [
        {
            "ioc_value": "arthurtaylor13sh.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:17",
            "last_seen_utc": "2026-08-31 08:01:29",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063879": [
        {
            "ioc_value": "artis214sh.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:17",
            "last_seen_utc": "2026-08-31 08:01:29",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063864": [
        {
            "ioc_value": "zipo-cons.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:16",
            "last_seen_utc": "2026-08-31 08:01:27",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063865": [
        {
            "ioc_value": "fazehotafa.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:16",
            "last_seen_utc": "2026-08-31 08:01:27",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063866": [
        {
            "ioc_value": "zendriol.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:16",
            "last_seen_utc": "2026-08-31 08:01:28",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063867": [
        {
            "ioc_value": "sezezapa.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:16",
            "last_seen_utc": "2026-08-31 08:01:28",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063868": [
        {
            "ioc_value": "sorekipe.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:16",
            "last_seen_utc": "2026-08-31 08:01:28",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063869": [
        {
            "ioc_value": "zezinuwe.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:16",
            "last_seen_utc": "2026-08-31 08:01:28",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063858": [
        {
            "ioc_value": "shrekf.art",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:15",
            "last_seen_utc": "2026-08-31 08:01:26",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063859": [
        {
            "ioc_value": "amaniza.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:15",
            "last_seen_utc": "2026-08-31 08:01:26",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063860": [
        {
            "ioc_value": "microcloud.pro",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:15",
            "last_seen_utc": "2026-08-31 08:01:27",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063861": [
        {
            "ioc_value": "anexuss.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:15",
            "last_seen_utc": "2026-08-31 08:01:27",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063862": [
        {
            "ioc_value": "edictsoft.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:15",
            "last_seen_utc": "2026-08-31 08:01:27",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063863": [
        {
            "ioc_value": "out1etshops.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:15",
            "last_seen_utc": "2026-08-31 08:01:27",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063851": [
        {
            "ioc_value": "stepnbayac.net",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:14",
            "last_seen_utc": "2026-08-31 08:01:26",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063852": [
        {
            "ioc_value": "chickenpoken.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:14",
            "last_seen_utc": "2026-08-31 08:01:26",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063853": [
        {
            "ioc_value": "hockeysmall.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:14",
            "last_seen_utc": "2026-08-31 08:01:26",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063854": [
        {
            "ioc_value": "orthodoxok.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:14",
            "last_seen_utc": "2026-08-31 08:01:26",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063855": [
        {
            "ioc_value": "cocesovo.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:14",
            "last_seen_utc": "2026-08-31 08:01:26",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063856": [
        {
            "ioc_value": "familyinsurancepartner.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:14",
            "last_seen_utc": "2026-08-31 08:01:33",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063857": [
        {
            "ioc_value": "senebuvuyi.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:14",
            "last_seen_utc": "2026-08-31 08:01:26",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063848": [
        {
            "ioc_value": "fincheck.site",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:13",
            "last_seen_utc": "2026-08-31 08:01:25",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063849": [
        {
            "ioc_value": "svchosst.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:13",
            "last_seen_utc": "2026-08-31 08:01:25",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063850": [
        {
            "ioc_value": "conhosst.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:13",
            "last_seen_utc": "2026-08-31 08:01:25",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063843": [
        {
            "ioc_value": "maximumservers.net",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:12",
            "last_seen_utc": "2026-08-31 08:01:31",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063844": [
        {
            "ioc_value": "conferencedesk.net",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:12",
            "last_seen_utc": "2026-08-31 08:01:25",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063845": [
        {
            "ioc_value": "bluetechsupply.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:12",
            "last_seen_utc": "2026-08-31 08:02:03",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063846": [
        {
            "ioc_value": "allgroupservices.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:12",
            "last_seen_utc": "2026-08-31 08:01:26",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063847": [
        {
            "ioc_value": "acitopram.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:12",
            "last_seen_utc": "2026-08-31 08:01:43",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063838": [
        {
            "ioc_value": "businessservicesolution.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:11",
            "last_seen_utc": "2026-08-31 08:01:33",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063839": [
        {
            "ioc_value": "gravyblicus.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:11",
            "last_seen_utc": "2026-08-31 08:01:57",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063840": [
        {
            "ioc_value": "firmwarekey.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:11",
            "last_seen_utc": "2026-08-31 08:02:03",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063841": [
        {
            "ioc_value": "updateraccount.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:11",
            "last_seen_utc": "2026-08-31 08:02:03",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063842": [
        {
            "ioc_value": "mvnetworking.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:11",
            "last_seen_utc": "2026-08-31 08:02:03",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063832": [
        {
            "ioc_value": "avasecurityservices.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:10",
            "last_seen_utc": "2026-08-31 08:01:27",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063833": [
        {
            "ioc_value": "extranetserver.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:10",
            "last_seen_utc": "2026-08-31 08:01:27",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063834": [
        {
            "ioc_value": "clacem.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:10",
            "last_seen_utc": "2026-08-31 08:01:22",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063835": [
        {
            "ioc_value": "eonline-cdn.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:10",
            "last_seen_utc": "2026-08-31 08:01:22",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063836": [
        {
            "ioc_value": "cagohufe.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:10",
            "last_seen_utc": "2026-08-31 08:01:22",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063837": [
        {
            "ioc_value": "vezawahoy.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:10",
            "last_seen_utc": "2026-08-31 08:01:23",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063826": [
        {
            "ioc_value": "tetafup.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:09",
            "last_seen_utc": "2026-08-31 08:01:21",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063827": [
        {
            "ioc_value": "api-trend-micro.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:09",
            "last_seen_utc": "2026-08-31 08:01:21",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063828": [
        {
            "ioc_value": "digital-hardware.net",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:09",
            "last_seen_utc": "2026-08-31 08:01:31",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063829": [
        {
            "ioc_value": "aboutdatabasesoftware.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:09",
            "last_seen_utc": "2026-08-31 08:01:31",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063830": [
        {
            "ioc_value": "high-control.net",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:09",
            "last_seen_utc": "2026-08-31 08:01:31",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063831": [
        {
            "ioc_value": "soft-base.org",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:09",
            "last_seen_utc": "2026-08-31 08:01:31",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063821": [
        {
            "ioc_value": "iptvr.icu",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:08",
            "last_seen_utc": "2026-08-31 08:01:20",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063823": [
        {
            "ioc_value": "mingw.icu",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:08",
            "last_seen_utc": "2026-08-31 08:01:20",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063824": [
        {
            "ioc_value": "transfercloud.net",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:08",
            "last_seen_utc": "2026-08-31 08:01:25",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063825": [
        {
            "ioc_value": "flashcom.top",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:08",
            "last_seen_utc": "2026-08-31 08:01:25",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063818": [
        {
            "ioc_value": "sciencelifedata.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:07",
            "last_seen_utc": "2026-08-31 08:01:19",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063819": [
        {
            "ioc_value": "bookingsupport.online",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:07",
            "last_seen_utc": "2026-08-31 08:01:20",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063820": [
        {
            "ioc_value": "ateyakima.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:07",
            "last_seen_utc": "2026-08-31 08:01:20",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063813": [
        {
            "ioc_value": "buy1walmart.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:06",
            "last_seen_utc": "2026-08-31 08:01:18",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063816": [
        {
            "ioc_value": "drbeat.icu",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:06",
            "last_seen_utc": "2026-08-31 08:01:18",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063817": [
        {
            "ioc_value": "aialadin.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:06",
            "last_seen_utc": "2026-08-31 08:01:18",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063810": [
        {
            "ioc_value": "hhkj222.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:05",
            "last_seen_utc": "2026-08-31 08:01:17",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063811": [
        {
            "ioc_value": "yw2204.shop",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:05",
            "last_seen_utc": "2026-08-31 08:01:17",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063812": [
        {
            "ioc_value": "nordicqlobal.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:05",
            "last_seen_utc": "2026-08-31 08:01:18",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063806": [
        {
            "ioc_value": "favls.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:04",
            "last_seen_utc": "2026-08-31 08:01:16",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063807": [
        {
            "ioc_value": "linkkedin.life",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:04",
            "last_seen_utc": "2026-08-31 08:01:16",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063808": [
        {
            "ioc_value": "magellanfit.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:04",
            "last_seen_utc": "2026-08-31 08:01:16",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063805": [
        {
            "ioc_value": "afspd.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:03",
            "last_seen_utc": "2026-08-31 08:01:16",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063804": [
        {
            "ioc_value": "164.92.70.225:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:46:51",
            "last_seen_utc": "2026-08-31 08:01:44",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063802": [
        {
            "ioc_value": "abritrum-bridges.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:44:07",
            "last_seen_utc": "2026-08-31 08:01:16",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063208": [
        {
            "ioc_value": "a.wv2022.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-28 19:56:09",
            "last_seen_utc": "2026-08-31 08:01:15",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,TENCENT-NET-AP-CN Tencent Building Kejizhongyi Avenue",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1063123": [
        {
            "ioc_value": "apacheorg.wiki",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-28 02:22:09",
            "last_seen_utc": "2026-08-31 08:01:15",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CLOUDIE-AS-AP Cloudie Limited,CobaltStrike",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1062406": [
        {
            "ioc_value": "updatemicrotok.online",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-24 19:00:50",
            "last_seen_utc": "2026-08-31 08:01:15",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "AS-SERVERION,CobaltStrike",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1053949": [
        {
            "ioc_value": "eserverx.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-19 21:43:42",
            "last_seen_utc": "2026-08-31 08:01:16",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "AEZA-AS,CobaltStrike",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1050306": [
        {
            "ioc_value": "cmdatabase.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-19 11:41:44",
            "last_seen_utc": "2026-08-31 08:01:12",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ADM Service Ltd.,CobaltStrike",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1050198": [
        {
            "ioc_value": "cloudmane.online",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-17 12:12:59",
            "last_seen_utc": "2026-08-31 08:01:16",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,Partner LLC",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1036758": [
        {
            "ioc_value": "8.212.49.116:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-13 11:43:38",
            "last_seen_utc": "2026-08-31 08:00:55",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "Alibaba (US) Technology Co. Ltd.,CobaltStrike",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1036111": [
        {
            "ioc_value": "qw.conhoosst.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-12 01:38:31",
            "last_seen_utc": "2026-08-31 08:01:17",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,UAB Cherry Servers",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1035723": [
        {
            "ioc_value": "expoglobalservice.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-08 20:45:56",
            "last_seen_utc": "2026-08-31 08:01:17",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,TIER-NET",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1035558": [
        {
            "ioc_value": "www.microsofer.top",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-07 20:05:59",
            "last_seen_utc": "2026-08-31 08:01:20",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,Tencent Building Kejizhongyi Avenue",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1031731": [
        {
            "ioc_value": "googlecontentuser.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-05 20:03:53",
            "last_seen_utc": "2026-08-31 08:01:17",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://twitter.com/TheDFIRReport/status/1599780643222654976",
            "tags": "CobaltStrike",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1031726": [
        {
            "ioc_value": "test.227api.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-05 19:27:32",
            "last_seen_utc": "2026-08-31 08:01:07",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,YISUCLOUDLTD-HK YISU CLOUD LTD",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1029025": [
        {
            "ioc_value": "palalto.live",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-05 11:42:38",
            "last_seen_utc": "2026-08-31 08:01:17",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,Private Layer INC",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1028963": [
        {
            "ioc_value": "esoftwareupdates.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-04 20:18:27",
            "last_seen_utc": "2026-08-31 08:01:17",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ASGHOSTNET,CobaltStrike",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1028767": [
        {
            "ioc_value": "globalplayservices.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-02 21:28:11",
            "last_seen_utc": "2026-08-31 08:01:17",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CHERRYSERVERS3-AS,CobaltStrike",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1028737": [
        {
            "ioc_value": "rapidfinact.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-02 20:50:52",
            "last_seen_utc": "2026-08-31 08:01:17",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,SHINJIRU-MY-AS-AP Shinjiru Technology Sdn Bhd",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1028720": [
        {
            "ioc_value": "globalsteamclub.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-02 20:38:18",
            "last_seen_utc": "2026-08-31 08:01:17",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CHERRYSERVERS3-AS,CobaltStrike",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1028501": [
        {
            "ioc_value": "get-music-online.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-01 20:32:20",
            "last_seen_utc": "2026-08-31 08:01:17",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CHERRYSERVERS3-AS,CobaltStrike",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1024554": [
        {
            "ioc_value": "msndla.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-11-27 16:10:54",
            "last_seen_utc": "2026-08-31 08:01:16",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,PONYNET",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1023854": [
        {
            "ioc_value": "childhealthresources.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-11-24 11:54:46",
            "last_seen_utc": "2026-08-31 08:01:37",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "AMAZON-02,CobaltStrike",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1023821": [
        {
            "ioc_value": "360safeupdate.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-11-24 11:50:52",
            "last_seen_utc": "2026-08-31 08:01:16",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,Tencent Building Kejizhongyi Avenue",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1021044": [
        {
            "ioc_value": "aksaholdings.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-11-20 10:32:06",
            "last_seen_utc": "2026-08-31 08:01:18",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "Amazon.com Inc.,CobaltStrike",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1012628": [
        {
            "ioc_value": "msisfx.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-11-15 06:56:25",
            "last_seen_utc": "2026-08-31 08:01:18",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://twitter.com/malware_traffic/status/1592262598195646464",
            "tags": "CobaltStrike",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1009773": [
        {
            "ioc_value": "get-smartbuyer.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-11-12 17:46:46",
            "last_seen_utc": "2026-08-31 08:01:18",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,UAB Cherry Servers",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1000509": [
        {
            "ioc_value": "qw.stakcl.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-11-10 11:51:33",
            "last_seen_utc": "2026-08-31 08:01:18",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,UAB Cherry Servers",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "991420": [
        {
            "ioc_value": "sogouupdate.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-11-08 20:20:30",
            "last_seen_utc": "2026-08-31 08:01:16",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,TENCENT-NET-AP-CN Tencent Building Kejizhongyi Avenue",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "985010": [
        {
            "ioc_value": "dnsupdatecheck.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-11-07 20:10:29",
            "last_seen_utc": "2026-08-31 08:01:18",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CHERRYSERVERS3-AS,CobaltStrike",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "973832": [
        {
            "ioc_value": "ipulsecloud.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-11-04 11:23:08",
            "last_seen_utc": "2026-08-31 08:01:21",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,FLYSERVERS-ENDCLIENTS",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "964538": [
        {
            "ioc_value": "zadiguser.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-11-03 12:12:17",
            "last_seen_utc": "2026-08-31 08:01:21",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": "",
            "tags": null,
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "964540": [
        {
            "ioc_value": "wasazokiwo.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-11-03 12:12:17",
            "last_seen_utc": "2026-08-31 08:01:27",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": "",
            "tags": null,
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "964541": [
        {
            "ioc_value": "yuwajeni.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-11-03 12:12:17",
            "last_seen_utc": "2026-08-31 08:01:22",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": "",
            "tags": null,
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "964542": [
        {
            "ioc_value": "yavahiyil.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-11-03 12:12:17",
            "last_seen_utc": "2026-08-31 08:01:22",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": "",
            "tags": null,
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "964543": [
        {
            "ioc_value": "rabihino.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-11-03 12:12:17",
            "last_seen_utc": "2026-08-31 08:01:31",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": "",
            "tags": null,
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "964545": [
        {
            "ioc_value": "nokevohoh.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-11-03 12:12:17",
            "last_seen_utc": "2026-08-31 08:01:32",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": "",
            "tags": null,
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "964546": [
        {
            "ioc_value": "rawocav.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-11-03 12:12:17",
            "last_seen_utc": "2026-08-31 08:01:32",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": "",
            "tags": null,
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "964548": [
        {
            "ioc_value": "deyikurihe.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-11-03 12:12:17",
            "last_seen_utc": "2026-08-31 08:01:32",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": "",
            "tags": null,
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "952862": [
        {
            "ioc_value": "freshuper.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-10-30 19:51:44",
            "last_seen_utc": "2026-08-31 08:01:19",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,tzulo inc.",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "952596": [
        {
            "ioc_value": "reebons.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-10-29 12:32:13",
            "last_seen_utc": "2026-08-31 08:01:19",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,Perviy TSOD LLC",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "952587": [
        {
            "ioc_value": "gaswert.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-10-29 12:23:49",
            "last_seen_utc": "2026-08-31 08:01:19",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,GLOBAL INTERNET SOLUTIONS LLC",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "952582": [
        {
            "ioc_value": "sajij.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-10-29 11:54:42",
            "last_seen_utc": "2026-08-31 08:01:19",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,Perviy TSOD LLC",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "952555": [
        {
            "ioc_value": "asasyz.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-10-29 10:14:36",
            "last_seen_utc": "2026-08-31 08:01:19",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,Partner LLC",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "952552": [
        {
            "ioc_value": "agazud.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-10-29 10:12:26",
            "last_seen_utc": "2026-08-31 08:01:19",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,LLC Baxet",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "952534": [
        {
            "ioc_value": "tuuik.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-10-29 09:57:36",
            "last_seen_utc": "2026-08-31 08:01:19",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,GLOBAL INTERNET SOLUTIONS LLC",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "952528": [
        {
            "ioc_value": "alfuhin.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-10-29 09:56:46",
            "last_seen_utc": "2026-08-31 08:01:20",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,Partner LLC",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "950974": [
        {
            "ioc_value": "amaladin.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-10-27 23:43:27",
            "last_seen_utc": "2026-08-31 08:01:18",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,HOSTKEY-USA",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "949937": [
        {
            "ioc_value": "aualadin.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-10-26 10:09:11",
            "last_seen_utc": "2026-08-31 08:01:19",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,Perviy TSOD LLC",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "916136": [
        {
            "ioc_value": "bthserv.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-10-23 13:42:10",
            "last_seen_utc": "2026-08-31 08:01:19",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,Internet Solutions & Innovations LTD.",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "916115": [
        {
            "ioc_value": "nuesro.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-10-23 13:37:35",
            "last_seen_utc": "2026-08-31 08:01:19",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,Partner LLC",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "916100": [
        {
            "ioc_value": "pasadonline.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-10-23 13:36:50",
            "last_seen_utc": "2026-08-31 08:01:18",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,UAB Cherry Servers",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "915911": [
        {
            "ioc_value": "worldsgates.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-10-22 19:40:40",
            "last_seen_utc": "2026-08-31 08:01:20",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,LUCIDACLOUD LIMITED",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "915908": [
        {
            "ioc_value": "protramal.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-10-22 19:39:30",
            "last_seen_utc": "2026-08-31 08:01:21",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,Perviy TSOD LLC",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "915846": [
        {
            "ioc_value": "spltst.icu",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-10-22 01:11:02",
            "last_seen_utc": "2026-08-31 08:01:19",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,combahton GmbH",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "891477": [
        {
            "ioc_value": "cehocihit.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-10-16 13:10:54",
            "last_seen_utc": "2026-08-31 08:01:28",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,LEASEWEB-USA-PHX",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "891461": [
        {
            "ioc_value": "cloudmicro.pro",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-10-16 12:38:04",
            "last_seen_utc": "2026-08-31 08:01:27",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,PLI-AS",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "887212": [
        {
            "ioc_value": "keycloud.live",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-10-13 21:41:28",
            "last_seen_utc": "2026-08-31 08:01:20",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,PARTNER-AS",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "886703": [
        {
            "ioc_value": "activeservers.net",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-10-13 21:13:41",
            "last_seen_utc": "2026-08-31 08:01:31",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "Amati Foundation,CobaltStrike",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "886693": [
        {
            "ioc_value": "newyearbalance.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-10-13 21:12:51",
            "last_seen_utc": "2026-08-31 08:01:20",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CHERRYSERVERS3-AS,CobaltStrike",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "886516": [
        {
            "ioc_value": "xamayojir.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-10-13 21:02:36",
            "last_seen_utc": "2026-08-31 08:01:22",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,LEASEWEB-USA-PHX",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "886499": [
        {
            "ioc_value": "xicefoga.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-10-13 20:58:25",
            "last_seen_utc": "2026-08-31 08:01:34",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,LEASEWEB-USA-WDC",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "884091": [
        {
            "ioc_value": "ams-prd-cob.nl",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-10-13 19:51:56",
            "last_seen_utc": "2026-08-31 08:01:24",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,DIGITALOCEAN-ASN",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "883488": [
        {
            "ioc_value": "tagujog.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-10-13 19:35:22",
            "last_seen_utc": "2026-08-31 08:01:23",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,LEASEWEB-USA-PHX",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "883412": [
        {
            "ioc_value": "mysqlserver.org",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-10-13 19:32:23",
            "last_seen_utc": "2026-08-31 08:01:31",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,ICME",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "883142": [
        {
            "ioc_value": "xuluxetas.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-10-13 19:23:44",
            "last_seen_utc": "2026-08-31 08:01:22",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,LEASEWEB-USA-NYC",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "880419": [
        {
            "ioc_value": "hadujaza.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-10-12 17:16:11",
            "last_seen_utc": "2026-08-31 08:01:25",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://www.trendmicro.com/en_us/research/22/j/black-basta-infiltrates-networks-via-qakbot-brute-ratel-and-coba.html",
            "tags": "CobaltStrike",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "871733": [
        {
            "ioc_value": "softsupdate.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-10-05 18:54:33",
            "last_seen_utc": "2026-08-31 08:01:21",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://twitter.com/1ZRR4H/status/1577718910652129280",
            "tags": "CobaltStrike",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "871734": [
        {
            "ioc_value": "anushl.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-10-05 18:54:33",
            "last_seen_utc": "2026-08-31 08:01:21",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://twitter.com/1ZRR4H/status/1577718910652129280",
            "tags": "CobaltStrike",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "858399": [
        {
            "ioc_value": "anbush.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-09-29 08:45:45",
            "last_seen_utc": "2026-08-31 08:01:23",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://twitter.com/1ZRR4H/status/1575364140285267970",
            "tags": "CobaltStrike",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "858402": [
        {
            "ioc_value": "get-topservice.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-09-29 08:45:45",
            "last_seen_utc": "2026-08-31 08:01:21",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://twitter.com/1ZRR4H/status/1575364140285267970",
            "tags": "CobaltStrike",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "858403": [
        {
            "ioc_value": "msoftupdate.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-09-29 08:45:45",
            "last_seen_utc": "2026-08-31 08:01:21",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://twitter.com/1ZRR4H/status/1575364140285267970",
            "tags": "CobaltStrike",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "858404": [
        {
            "ioc_value": "pregabas.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-09-29 08:45:45",
            "last_seen_utc": "2026-08-31 08:01:21",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://twitter.com/1ZRR4H/status/1575364140285267970",
            "tags": "CobaltStrike",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "851096": [
        {
            "ioc_value": "34.92.131.12:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-09-22 11:26:18",
            "last_seen_utc": "2026-08-31 08:01:24",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,Google LLC",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "850706": [
        {
            "ioc_value": "87.246.7.38:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-09-20 16:58:14",
            "last_seen_utc": "2026-08-31 08:01:25",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://twitter.com/1ZRR4H/status/1572261285139714051",
            "tags": "CobaltStrike",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "850701": [
        {
            "ioc_value": "cloudmicro.tech",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-09-20 16:57:02",
            "last_seen_utc": "2026-08-31 08:01:23",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://twitter.com/1ZRR4H/status/1572261285139714051",
            "tags": "CobaltStrike",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "850702": [
        {
            "ioc_value": "fregiyu.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-09-20 16:57:02",
            "last_seen_utc": "2026-08-31 08:01:24",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://twitter.com/1ZRR4H/status/1572261285139714051",
            "tags": "CobaltStrike",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "850704": [
        {
            "ioc_value": "microcloud.live",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-09-20 16:57:02",
            "last_seen_utc": "2026-08-31 08:01:23",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://twitter.com/1ZRR4H/status/1572261285139714051",
            "tags": "CobaltStrike",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "850260": [
        {
            "ioc_value": "154.22.117.31:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-09-17 21:24:41",
            "last_seen_utc": "2026-08-31 08:01:25",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,Cogent Communications",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "849761": [
        {
            "ioc_value": "198.98.53.34:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-09-14 22:07:14",
            "last_seen_utc": "2026-08-31 08:01:24",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,PONYNET",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "847988": [
        {
            "ioc_value": "globallookclub.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-09-05 19:10:52",
            "last_seen_utc": "2026-08-31 08:01:38",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": null,
            "anonymous": 0,
            "reporter": "_ik_"
        }
    ],
    "847986": [
        {
            "ioc_value": "realfunsolutions.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-09-05 19:10:50",
            "last_seen_utc": "2026-08-31 08:01:39",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": null,
            "anonymous": 0,
            "reporter": "_ik_"
        }
    ],
    "847972": [
        {
            "ioc_value": "www.service1app.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-09-05 19:10:48",
            "last_seen_utc": "2026-08-31 08:01:37",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": null,
            "anonymous": 0,
            "reporter": "_ik_"
        }
    ],
    "847975": [
        {
            "ioc_value": "youronlinesports.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-09-05 19:10:48",
            "last_seen_utc": "2026-08-31 08:01:37",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": null,
            "anonymous": 0,
            "reporter": "_ik_"
        }
    ],
    "847976": [
        {
            "ioc_value": "yourinfosolutions.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-09-05 19:10:48",
            "last_seen_utc": "2026-08-31 08:01:37",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": null,
            "anonymous": 0,
            "reporter": "_ik_"
        }
    ],
    "847978": [
        {
            "ioc_value": "login.onemusic24.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-09-05 19:10:48",
            "last_seen_utc": "2026-08-31 08:01:39",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": null,
            "anonymous": 0,
            "reporter": "_ik_"
        }
    ],
    "847981": [
        {
            "ioc_value": "zx.jacollans.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-09-05 19:10:48",
            "last_seen_utc": "2026-08-31 08:01:38",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": null,
            "anonymous": 0,
            "reporter": "_ik_"
        }
    ],
    "847942": [
        {
            "ioc_value": "satorkar.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-09-05 19:10:47",
            "last_seen_utc": "2026-08-31 08:01:32",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": null,
            "anonymous": 0,
            "reporter": "_ik_"
        }
    ],
    "847943": [
        {
            "ioc_value": "er.theinfoinc.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-09-05 19:10:47",
            "last_seen_utc": "2026-08-31 08:01:33",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": null,
            "anonymous": 0,
            "reporter": "_ik_"
        }
    ],
    "847957": [
        {
            "ioc_value": "realmacnow.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-09-05 19:10:47",
            "last_seen_utc": "2026-08-31 08:01:35",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": null,
            "anonymous": 0,
            "reporter": "_ik_"
        }
    ],
    "847958": [
        {
            "ioc_value": "onemusicllc.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-09-05 19:10:47",
            "last_seen_utc": "2026-08-31 08:01:35",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": null,
            "anonymous": 0,
            "reporter": "_ik_"
        }
    ],
    "847959": [
        {
            "ioc_value": "ateliernow.net",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-09-05 19:10:47",
            "last_seen_utc": "2026-08-31 08:01:35",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": null,
            "anonymous": 0,
            "reporter": "_ik_"
        }
    ],
    "847960": [
        {
            "ioc_value": "er.dropklant.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-09-05 19:10:47",
            "last_seen_utc": "2026-08-31 08:01:35",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": null,
            "anonymous": 0,
            "reporter": "_ik_"
        }
    ],
    "847929": [
        {
            "ioc_value": "sprinthunter.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-09-05 19:10:46",
            "last_seen_utc": "2026-08-31 08:01:27",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": null,
            "anonymous": 0,
            "reporter": "_ik_"
        }
    ],
    "847930": [
        {
            "ioc_value": "newstamagavk.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-09-05 19:10:46",
            "last_seen_utc": "2026-08-31 08:01:26",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": null,
            "anonymous": 0,
            "reporter": "_ik_"
        }
    ],
    "847934": [
        {
            "ioc_value": "www.onestepstar.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-09-05 19:10:46",
            "last_seen_utc": "2026-08-31 08:01:30",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": null,
            "anonymous": 0,
            "reporter": "_ik_"
        }
    ],
    "847028": [
        {
            "ioc_value": "barabezo.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-08-31 18:29:19",
            "last_seen_utc": "2026-08-31 08:01:28",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://bazaar.abuse.ch/sample/08ec3f13e8637a08dd763af6ccb46ff8516bc46efaacb1e5f052ada634a90c0e/",
            "tags": "CobaltStrike",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "847018": [
        {
            "ioc_value": "alojun.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-08-31 16:32:01",
            "last_seen_utc": "2026-08-31 08:01:26",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": null,
            "anonymous": 0,
            "reporter": "_ik_"
        }
    ],
    "847019": [
        {
            "ioc_value": "asdder.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-08-31 16:32:01",
            "last_seen_utc": "2026-08-31 08:01:26",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": null,
            "anonymous": 0,
            "reporter": "_ik_"
        }
    ],
    "847020": [
        {
            "ioc_value": "www.zominoz.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-08-31 16:32:01",
            "last_seen_utc": "2026-08-31 08:01:27",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": null,
            "anonymous": 0,
            "reporter": "_ik_"
        }
    ],
    "846258": [
        {
            "ioc_value": "jevomukif.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-08-30 06:22:11",
            "last_seen_utc": "2026-08-31 08:01:31",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://raw.githubusercontent.com/pan-unit42/tweets/master/2022-08-29-IOCs-for-Monster-Libra-TA551-IcedID-with-Cobalt-Stike.txt",
            "tags": "CobaltStrike",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "844214": [
        {
            "ioc_value": "msdnupdate.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-08-20 06:53:07",
            "last_seen_utc": "2026-08-31 08:01:31",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "CobaltStrike",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "844215": [
        {
            "ioc_value": "msdupdate.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-08-20 06:53:07",
            "last_seen_utc": "2026-08-31 08:01:32",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "CobaltStrike",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "843958": [
        {
            "ioc_value": "caxoxc.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-08-18 12:15:06",
            "last_seen_utc": "2026-08-31 08:01:33",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "CobaltStrike",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "843546": [
        {
            "ioc_value": "47.108.180.121:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-08-16 11:38:21",
            "last_seen_utc": "2026-08-31 08:00:54",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,Hangzhou Alibaba Advertising Co.Ltd.",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "842464": [
        {
            "ioc_value": "jahojahi.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-08-11 06:03:19",
            "last_seen_utc": "2026-08-31 08:01:28",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://raw.githubusercontent.com/pan-unit42/tweets/master/2022-08-10-IOCs-for-IcedID-and-Cobalt-Strike.txt",
            "tags": "CobaltStrike",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "841613": [
        {
            "ioc_value": "zambeziz.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-08-06 07:00:06",
            "last_seen_utc": "2026-08-31 08:01:34",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "CobaltSrike",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "839793": [
        {
            "ioc_value": "zuyonijobo.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-07-27 08:49:04",
            "last_seen_utc": "2026-08-31 08:01:34",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://isc.sans.edu/diary/28884",
            "tags": "Cobalt Strike",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "802793": [
        {
            "ioc_value": "digerm.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-07-06 05:36:04",
            "last_seen_utc": "2026-08-31 08:01:36",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": null,
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "796822": [
        {
            "ioc_value": "chitozx.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-07-05 05:12:06",
            "last_seen_utc": "2026-08-31 08:01:36",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": null,
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "750750": [
        {
            "ioc_value": "42.192.21.181:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-07-02 13:06:49",
            "last_seen_utc": "2026-08-31 08:01:25",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "730561": [
        {
            "ioc_value": "18.117.254.165:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-06-28 08:57:21",
            "last_seen_utc": "2026-08-31 08:01:45",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "Amazon.com Inc.,CobaltStrike",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "729038": [
        {
            "ioc_value": "blinkinuf.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-06-26 10:56:33",
            "last_seen_utc": "2026-08-31 08:01:36",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "Cobalt Strike",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "729037": [
        {
            "ioc_value": "malrok.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-06-26 10:56:32",
            "last_seen_utc": "2026-08-31 08:01:37",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "Cobalt Strike",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "720823": [
        {
            "ioc_value": "trumpiko.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-06-23 17:11:58",
            "last_seen_utc": "2026-08-31 08:01:37",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "Cobalt Strike",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "720824": [
        {
            "ioc_value": "freygor.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-06-23 17:11:58",
            "last_seen_utc": "2026-08-31 08:01:37",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "Cobalt Strike",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "720826": [
        {
            "ioc_value": "sinjoan.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-06-23 17:11:58",
            "last_seen_utc": "2026-08-31 08:01:39",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "Cobalt Strike",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "720827": [
        {
            "ioc_value": "afluix.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-06-23 17:11:58",
            "last_seen_utc": "2026-08-31 08:01:39",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "Cobalt Strike",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "720273": [
        {
            "ioc_value": "www.edge-chrome.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-06-23 10:54:20",
            "last_seen_utc": "2026-08-31 08:01:52",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": null,
            "tags": "Cobalt Strike",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "720276": [
        {
            "ioc_value": "www.hellomrsone.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-06-23 10:54:20",
            "last_seen_utc": "2026-08-31 08:02:04",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": null,
            "tags": "Cobalt Strike",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "720260": [
        {
            "ioc_value": "we.topsmartservice.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-06-23 10:54:19",
            "last_seen_utc": "2026-08-31 08:01:41",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": null,
            "tags": "Cobalt Strike",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "720263": [
        {
            "ioc_value": "wpsserver.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-06-23 10:54:19",
            "last_seen_utc": "2026-08-31 08:01:42",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": null,
            "tags": "Cobalt Strike",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "720248": [
        {
            "ioc_value": "thedaily-news.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-06-23 10:54:18",
            "last_seen_utc": "2026-08-31 08:01:40",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": null,
            "tags": "Cobalt Strike",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "720239": [
        {
            "ioc_value": "sevenhungredbucks.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-06-23 10:54:17",
            "last_seen_utc": "2026-08-31 08:01:38",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": null,
            "tags": "Cobalt Strike",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "720241": [
        {
            "ioc_value": "snccoupr-int.cf",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-06-23 10:54:17",
            "last_seen_utc": "2026-08-31 08:01:38",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": null,
            "tags": "Cobalt Strike",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "720247": [
        {
            "ioc_value": "telembank.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-06-23 10:54:17",
            "last_seen_utc": "2026-08-31 08:01:52",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": null,
            "tags": "Cobalt Strike",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "720230": [
        {
            "ioc_value": "ppew.au",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-06-23 10:54:16",
            "last_seen_utc": "2026-08-31 08:01:51",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": null,
            "tags": "Cobalt Strike",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "720231": [
        {
            "ioc_value": "pretunz.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-06-23 10:54:16",
            "last_seen_utc": "2026-08-31 08:01:40",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": null,
            "tags": "Cobalt Strike",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "720236": [
        {
            "ioc_value": "rss.top-business-blog.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-06-23 10:54:16",
            "last_seen_utc": "2026-08-31 08:01:41",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": null,
            "tags": "Cobalt Strike",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "720237": [
        {
            "ioc_value": "scarfaceserver.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-06-23 10:54:16",
            "last_seen_utc": "2026-08-31 08:01:39",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": null,
            "tags": "Cobalt Strike",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "720226": [
        {
            "ioc_value": "outlet-studio.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-06-23 10:54:15",
            "last_seen_utc": "2026-08-31 08:01:39",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": null,
            "tags": "Cobalt Strike",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "720208": [
        {
            "ioc_value": "js.msedgeupdate.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-06-23 10:54:14",
            "last_seen_utc": "2026-08-31 08:00:55",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": null,
            "tags": "Cobalt Strike",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "720198": [
        {
            "ioc_value": "harborfreight.delivery",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-06-23 10:54:13",
            "last_seen_utc": "2026-08-31 08:02:01",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": null,
            "tags": "Cobalt Strike",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "720201": [
        {
            "ioc_value": "hityok.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-06-23 10:54:13",
            "last_seen_utc": "2026-08-31 08:01:41",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": null,
            "tags": "Cobalt Strike",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "720203": [
        {
            "ioc_value": "jiguz.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-06-23 10:54:13",
            "last_seen_utc": "2026-08-31 08:01:40",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": null,
            "tags": "Cobalt Strike",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "720204": [
        {
            "ioc_value": "jijuanjo.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-06-23 10:54:13",
            "last_seen_utc": "2026-08-31 08:01:38",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": null,
            "tags": "Cobalt Strike",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "720206": [
        {
            "ioc_value": "jqueryupdatenow.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-06-23 10:54:13",
            "last_seen_utc": "2026-08-31 08:01:40",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": null,
            "tags": "Cobalt Strike",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "720207": [
        {
            "ioc_value": "jqueryupneed.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-06-23 10:54:13",
            "last_seen_utc": "2026-08-31 08:01:40",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": null,
            "tags": "Cobalt Strike",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "720188": [
        {
            "ioc_value": "fifacud.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-06-23 10:54:12",
            "last_seen_utc": "2026-08-31 08:01:39",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": null,
            "tags": "Cobalt Strike",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "720189": [
        {
            "ioc_value": "filaspo.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-06-23 10:54:12",
            "last_seen_utc": "2026-08-31 08:01:41",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": null,
            "tags": "Cobalt Strike",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "720193": [
        {
            "ioc_value": "gasienda.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-06-23 10:54:12",
            "last_seen_utc": "2026-08-31 08:01:41",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": null,
            "tags": "Cobalt Strike",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "720185": [
        {
            "ioc_value": "dreamkoks.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-06-23 10:54:11",
            "last_seen_utc": "2026-08-31 08:01:38",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": null,
            "tags": "Cobalt Strike",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "720176": [
        {
            "ioc_value": "democrazzy.net",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-06-23 10:54:10",
            "last_seen_utc": "2026-08-31 08:01:30",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": null,
            "tags": "Cobalt Strike",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "720156": [
        {
            "ioc_value": "cloud.sovarermscloud.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-06-23 10:53:31",
            "last_seen_utc": "2026-08-31 08:01:41",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": null,
            "tags": "Cobalt Strike",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "720136": [
        {
            "ioc_value": "backupcreds.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-06-23 10:53:28",
            "last_seen_utc": "2026-08-31 08:01:42",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": null,
            "tags": "Cobalt Strike",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "720140": [
        {
            "ioc_value": "biohazzzard.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-06-23 10:53:28",
            "last_seen_utc": "2026-08-31 08:01:41",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": null,
            "tags": "Cobalt Strike",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "720141": [
        {
            "ioc_value": "bksfinance.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-06-23 10:53:28",
            "last_seen_utc": "2026-08-31 08:01:54",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": null,
            "tags": "Cobalt Strike",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "720143": [
        {
            "ioc_value": "boronab.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-06-23 10:53:28",
            "last_seen_utc": "2026-08-31 08:01:40",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": null,
            "tags": "Cobalt Strike",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "720132": [
        {
            "ioc_value": "araizx.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-06-23 10:53:27",
            "last_seen_utc": "2026-08-31 08:01:38",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": null,
            "tags": "Cobalt Strike",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "720133": [
        {
            "ioc_value": "arminext.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-06-23 10:53:27",
            "last_seen_utc": "2026-08-31 08:01:41",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": null,
            "tags": "Cobalt Strike",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "719898": [
        {
            "ioc_value": "aginij.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-06-22 18:35:13",
            "last_seen_utc": "2026-08-31 08:01:38",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "Cobalt Strike",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "710534": [
        {
            "ioc_value": "85.175.101.203:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-06-15 20:53:40",
            "last_seen_utc": "2026-08-31 07:48:58",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,STC-AS",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "606362": [
        {
            "ioc_value": "criobob.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-05-19 18:01:58",
            "last_seen_utc": "2026-08-31 08:01:42",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "cobaltstrike,emotet",
            "anonymous": 0,
            "reporter": "Cryptolaemus1"
        }
    ],
    "606363": [
        {
            "ioc_value": "prozakx.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-05-19 18:01:58",
            "last_seen_utc": "2026-08-31 08:01:42",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "cobaltstrike,emotet",
            "anonymous": 0,
            "reporter": "Cryptolaemus1"
        }
    ],
    "606364": [
        {
            "ioc_value": "terroklo.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-05-19 18:01:58",
            "last_seen_utc": "2026-08-31 08:01:42",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "cobaltstrike,emotet",
            "anonymous": 0,
            "reporter": "Cryptolaemus1"
        }
    ],
    "606360": [
        {
            "ioc_value": "microdozz.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-05-19 18:01:57",
            "last_seen_utc": "2026-08-31 08:01:42",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "cobaltstrike,emotet",
            "anonymous": 0,
            "reporter": "Cryptolaemus1"
        }
    ],
    "549372": [
        {
            "ioc_value": "us189-hpgsgae5dva9fzch.z01.azurefd.net",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-05-10 18:53:07",
            "last_seen_utc": "2026-08-31 08:01:49",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "cobaltstrike,threatview.io",
            "anonymous": 0,
            "reporter": "Malwar3Ninja"
        }
    ],
    "548951": [
        {
            "ioc_value": "artidomain.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-05-08 16:20:03",
            "last_seen_utc": "2026-08-31 08:01:44",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://twitter.com/ian_kenefick/status/1523288477559062529",
            "tags": "Cobalt Strike",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "544836": [
        {
            "ioc_value": "116.62.185.223:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-04-30 19:45:18",
            "last_seen_utc": "2026-08-31 08:01:44",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ALIBABA-CN-NET Hangzhou Alibaba Advertising Co.Ltd.,CobaltStrike",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "540702": [
        {
            "ioc_value": "165.227.180.6:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-04-29 19:30:18",
            "last_seen_utc": "2026-08-31 08:01:48",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,DIGITALOCEAN-ASN",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "532916": [
        {
            "ioc_value": "120.26.240.21:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-04-25 12:31:07",
            "last_seen_utc": "2026-08-31 08:01:51",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ALIBABA-CN-NET Hangzhou Alibaba Advertising Co.Ltd.,CobaltStrike",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "530098": [
        {
            "ioc_value": "193.29.13.216:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-04-23 16:42:50",
            "last_seen_utc": "2026-08-31 08:01:52",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "***************************************,CobaltStrike",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "523516": [
        {
            "ioc_value": "45.8.158.25:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-04-21 16:54:57",
            "last_seen_utc": "2026-08-31 08:01:45",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ASBAXETN,CobaltStrike",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "521565": [
        {
            "ioc_value": "115.29.171.175:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-04-19 13:44:33",
            "last_seen_utc": "2026-08-31 08:01:51",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CNNIC-ALIBABA-CN-NET-AP Hangzhou Alibaba Advertising Co.Ltd.,CobaltStrike",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "521083": [
        {
            "ioc_value": "84.32.188.190:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-04-18 18:01:52",
            "last_seen_utc": "2026-08-31 08:01:44",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,UAB Cherry Servers",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "520317": [
        {
            "ioc_value": "137.184.42.85:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-04-15 22:57:51",
            "last_seen_utc": "2026-08-31 08:01:50",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,DIGITALOCEAN-ASN",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "519914": [
        {
            "ioc_value": "84.32.188.104:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-04-14 16:59:25",
            "last_seen_utc": "2026-08-31 08:01:46",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,UAB Cherry Servers",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "519792": [
        {
            "ioc_value": "furfen.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-04-14 10:30:57",
            "last_seen_utc": "2026-08-31 08:01:43",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "BumbleBee,Cobalt Strike",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "519116": [
        {
            "ioc_value": "175.41.21.29:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-04-13 16:57:52",
            "last_seen_utc": "2026-08-31 08:01:48",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,XLC-AS-AP XLC GLOBAL",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "518853": [
        {
            "ioc_value": "175.41.16.98:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-04-12 16:50:58",
            "last_seen_utc": "2026-08-31 08:01:52",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,XLC-AS-AP XLC GLOBAL",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "518404": [
        {
            "ioc_value": "138.68.110.227:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-04-10 17:05:31",
            "last_seen_utc": "2026-08-31 08:01:49",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,DIGITALOCEAN-ASN",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "516676": [
        {
            "ioc_value": "13.55.118.253:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-04-06 22:59:35",
            "last_seen_utc": "2026-08-31 08:01:45",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "AMAZON-02,CobaltStrike",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "493695": [
        {
            "ioc_value": "185.186.143.111:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-04-05 22:55:20",
            "last_seen_utc": "2026-08-31 08:01:45",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ASKONTEL,CobaltStrike",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "492845": [
        {
            "ioc_value": "194.37.97.153:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-04-05 16:53:16",
            "last_seen_utc": "2026-08-31 08:02:04",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,M247 Ltd",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "466600": [
        {
            "ioc_value": "blopik.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-03-30 09:51:36",
            "last_seen_utc": "2026-08-31 08:01:54",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "Cobalt Strike",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "461231": [
        {
            "ioc_value": "borizhog.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-03-29 08:36:59",
            "last_seen_utc": "2026-08-31 08:01:54",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "stoerchl"
        }
    ],
    "448027": [
        {
            "ioc_value": "37.72.172.110:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-03-24 22:55:12",
            "last_seen_utc": "2026-08-31 08:01:46",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,HVC-AS",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "446029": [
        {
            "ioc_value": "1.14.76.111:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-03-24 10:56:07",
            "last_seen_utc": "2026-08-31 08:01:49",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "443786": [
        {
            "ioc_value": "139.60.160.8:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-03-23 20:44:05",
            "last_seen_utc": "2026-08-31 08:01:46",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,HOSTKEY-USA",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "443190": [
        {
            "ioc_value": "apeduze.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-03-23 16:44:21",
            "last_seen_utc": "2026-08-31 08:01:43",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "stoerchl"
        }
    ],
    "438442": [
        {
            "ioc_value": "drimzis.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-03-22 10:51:28",
            "last_seen_utc": "2026-08-31 08:01:57",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "stoerchl"
        }
    ],
    "438443": [
        {
            "ioc_value": "blinkij.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-03-22 10:51:28",
            "last_seen_utc": "2026-08-31 08:01:53",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "stoerchl"
        }
    ],
    "398650": [
        {
            "ioc_value": "152.136.178.142:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-03-17 22:47:07",
            "last_seen_utc": "2026-08-31 08:01:52",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "396104": [
        {
            "ioc_value": "dunclikf.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-03-17 12:19:46",
            "last_seen_utc": "2026-08-31 08:01:59",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "Cobalt Strike",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "393426": [
        {
            "ioc_value": "sifgu.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-03-10 15:29:52",
            "last_seen_utc": "2026-08-31 08:01:53",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "stoerchl"
        }
    ],
    "393427": [
        {
            "ioc_value": "gfsert.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-03-10 15:29:52",
            "last_seen_utc": "2026-08-31 08:01:54",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "stoerchl"
        }
    ],
    "393429": [
        {
            "ioc_value": "shizij.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-03-10 15:29:52",
            "last_seen_utc": "2026-08-31 08:01:58",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "stoerchl"
        }
    ],
    "393430": [
        {
            "ioc_value": "zxerm.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-03-10 15:29:52",
            "last_seen_utc": "2026-08-31 08:01:58",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "stoerchl"
        }
    ],
    "393431": [
        {
            "ioc_value": "korunder.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-03-10 15:29:52",
            "last_seen_utc": "2026-08-31 08:01:59",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "stoerchl"
        }
    ],
    "393424": [
        {
            "ioc_value": "chesft.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-03-10 15:29:51",
            "last_seen_utc": "2026-08-31 08:01:57",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "stoerchl"
        }
    ],
    "393425": [
        {
            "ioc_value": "uktyl.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-03-10 15:29:51",
            "last_seen_utc": "2026-08-31 08:01:53",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "stoerchl"
        }
    ],
    "393312": [
        {
            "ioc_value": "defenr.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-03-09 17:18:35",
            "last_seen_utc": "2026-08-31 08:01:57",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "Cobalt Strike",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "393313": [
        {
            "ioc_value": "fedij.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-03-09 17:18:35",
            "last_seen_utc": "2026-08-31 08:01:57",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "Cobalt Strike",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "393314": [
        {
            "ioc_value": "kejimn.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-03-09 17:18:35",
            "last_seen_utc": "2026-08-31 08:01:57",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "Cobalt Strike",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "393311": [
        {
            "ioc_value": "brikeb.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-03-09 17:18:34",
            "last_seen_utc": "2026-08-31 08:01:57",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "Cobalt Strike",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "393046": [
        {
            "ioc_value": "kapuleti.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-03-08 17:09:32",
            "last_seen_utc": "2026-08-31 08:01:57",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "Cobalt Strike",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "392705": [
        {
            "ioc_value": "45.12.1.24:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-03-06 16:43:33",
            "last_seen_utc": "2026-08-31 08:01:50",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,YURTEH-AS",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "392630": [
        {
            "ioc_value": "45.12.1.25:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-03-05 16:45:53",
            "last_seen_utc": "2026-08-31 08:01:44",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,YURTEH-AS",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "392595": [
        {
            "ioc_value": "45.12.1.26:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-03-05 16:43:28",
            "last_seen_utc": "2026-08-31 08:01:45",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CLOUDNETWORKS-AS,CobaltStrike",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "391528": [
        {
            "ioc_value": "defegh.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-03-01 07:06:28",
            "last_seen_utc": "2026-08-31 08:01:58",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "Cobalt Strike",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "391530": [
        {
            "ioc_value": "klycnmik.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-03-01 07:06:28",
            "last_seen_utc": "2026-08-31 08:01:58",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "Cobalt Strike",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "391531": [
        {
            "ioc_value": "ngrety.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-03-01 07:06:28",
            "last_seen_utc": "2026-08-31 08:01:58",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "Cobalt Strike",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "391111": [
        {
            "ioc_value": "lifegothistory.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-02-27 06:03:58",
            "last_seen_utc": "2026-08-31 08:01:59",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://twitter.com/1ZRR4H/status/1497771037718724612",
            "tags": "Cobalt Strike",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "390123": [
        {
            "ioc_value": "192.241.133.130:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-02-22 16:44:41",
            "last_seen_utc": "2026-08-31 08:01:56",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,DIGITALOCEAN-ASN",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "390104": [
        {
            "ioc_value": "159.65.246.188:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-02-22 16:42:29",
            "last_seen_utc": "2026-08-31 08:01:56",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,DIGITALOCEAN-ASN",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "389873": [
        {
            "ioc_value": "68.183.200.63:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-02-21 16:58:18",
            "last_seen_utc": "2026-08-31 08:01:55",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,DIGITALOCEAN-ASN",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "389866": [
        {
            "ioc_value": "138.68.227.71:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-02-21 16:57:13",
            "last_seen_utc": "2026-08-31 08:01:55",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,DIGITALOCEAN-ASN",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "389865": [
        {
            "ioc_value": "165.227.219.211:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-02-21 16:56:32",
            "last_seen_utc": "2026-08-31 08:01:55",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,DIGITALOCEAN-ASN",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "389864": [
        {
            "ioc_value": "165.232.154.73:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-02-21 16:55:44",
            "last_seen_utc": "2026-08-31 08:01:56",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,DIGITALOCEAN-ASN",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "389861": [
        {
            "ioc_value": "143.198.110.248:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-02-21 16:54:53",
            "last_seen_utc": "2026-08-31 08:01:55",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,DIGITALOCEAN-ASN",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "389860": [
        {
            "ioc_value": "178.128.171.206:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-02-21 16:54:15",
            "last_seen_utc": "2026-08-31 08:01:56",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,DIGITALOCEAN-ASN",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "389853": [
        {
            "ioc_value": "165.227.23.218:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-02-21 16:53:10",
            "last_seen_utc": "2026-08-31 08:01:55",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,DIGITALOCEAN-ASN",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "389850": [
        {
            "ioc_value": "161.35.137.163:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-02-21 16:52:19",
            "last_seen_utc": "2026-08-31 08:01:55",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,DIGITALOCEAN-ASN",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "389847": [
        {
            "ioc_value": "64.227.0.177:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-02-21 16:51:26",
            "last_seen_utc": "2026-08-31 08:01:56",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,DIGITALOCEAN-ASN",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "389656": [
        {
            "ioc_value": "45.55.36.143:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-02-20 16:42:59",
            "last_seen_utc": "2026-08-31 08:01:55",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,DIGITALOCEAN-ASN",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "384626": [
        {
            "ioc_value": "168.61.180.98:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-02-09 22:36:37",
            "last_seen_utc": "2026-08-31 08:02:04",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,MICROSOFT-CORP-MSN-AS-BLOCK",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "373668": [
        {
            "ioc_value": "bornometa.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-02-01 10:45:03",
            "last_seen_utc": "2026-08-31 08:01:59",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://twitter.com/1ZRR4H/status/1488311508652204037",
            "tags": "Cobalt Strike",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "373671": [
        {
            "ioc_value": "jenevabaiden.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-02-01 10:45:03",
            "last_seen_utc": "2026-08-31 08:02:05",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://twitter.com/1ZRR4H/status/1488311508652204037",
            "tags": "Cobalt Strike",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "373673": [
        {
            "ioc_value": "sbronm.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-02-01 10:45:03",
            "last_seen_utc": "2026-08-31 08:02:00",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://twitter.com/1ZRR4H/status/1488311508652204037",
            "tags": "Cobalt Strike",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "362296": [
        {
            "ioc_value": "101.34.182.130:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-01-29 22:33:30",
            "last_seen_utc": "2026-08-31 08:01:52",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "332687": [
        {
            "ioc_value": "192.227.155.185:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-01-25 22:30:16",
            "last_seen_utc": "2026-08-31 08:01:47",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "AS-COLOCROSSING,CobaltStrike",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "332653": [
        {
            "ioc_value": "146.70.29.233:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-01-25 22:29:00",
            "last_seen_utc": "2026-08-31 08:01:47",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,M247",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "313943": [
        {
            "ioc_value": "107.172.219.129:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-01-22 22:25:42",
            "last_seen_utc": "2026-08-31 08:01:47",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "AS-COLOCROSSING,CobaltStrike",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "299262": [
        {
            "ioc_value": "193.201.9.229:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-01-18 22:32:52",
            "last_seen_utc": "2026-08-31 08:02:05",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,SELECTEL",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "298501": [
        {
            "ioc_value": "citrixseruritys.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-01-18 13:51:16",
            "last_seen_utc": "2026-08-31 08:02:04",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://twitter.com/MichalKoczwara/status/1483137082465865729",
            "tags": "Cobalt Strike",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "298505": [
        {
            "ioc_value": "milanvar.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-01-18 13:51:16",
            "last_seen_utc": "2026-08-31 08:02:05",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://twitter.com/MichalKoczwara/status/1483137082465865729",
            "tags": "Cobalt Strike",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "295525": [
        {
            "ioc_value": "23.227.198.246:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-01-15 22:26:20",
            "last_seen_utc": "2026-08-31 08:02:04",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,HVC-AS",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "295436": [
        {
            "ioc_value": "217.79.243.148:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-01-15 10:32:22",
            "last_seen_utc": "2026-08-31 08:02:04",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,HVC-AS",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "295353": [
        {
            "ioc_value": "149.255.35.131:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-01-14 22:28:25",
            "last_seen_utc": "2026-08-31 08:02:05",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,HVC-AS",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "294999": [
        {
            "ioc_value": "81.68.225.136:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-01-13 22:28:33",
            "last_seen_utc": "2026-08-31 08:01:46",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "292303": [
        {
            "ioc_value": "39.98.48.153:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-01-10 16:24:49",
            "last_seen_utc": "2026-08-31 08:00:17",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ALIBABA-CN-NET Hangzhou Alibaba Advertising Co.Ltd.,CobaltStrike",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "291740": [
        {
            "ioc_value": "39.104.25.164:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-01-07 10:30:52",
            "last_seen_utc": "2026-08-31 08:01:49",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ALIBABA-CN-NET Hangzhou Alibaba Advertising Co.Ltd.,CobaltStrike",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "276593": [
        {
            "ioc_value": "77.83.36.54:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2021-12-16 10:42:30",
            "last_seen_utc": "2026-08-31 08:01:51",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,ISI-ASN",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "275144": [
        {
            "ioc_value": "101.32.204.81:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2021-12-13 10:06:28",
            "last_seen_utc": "2026-08-31 08:01:51",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,TENCENT-NET-AP-CN Tencent Building Kejizhongyi Avenue",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "252110": [
        {
            "ioc_value": "62.113.255.12:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2021-11-22 16:01:01",
            "last_seen_utc": "2026-08-31 08:01:48",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,TTM",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "242948": [
        {
            "ioc_value": "107.173.89.148:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2021-11-04 17:48:48",
            "last_seen_utc": "2026-08-31 08:01:49",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "AS-COLOCROSSING,CobaltStrike",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "240983": [
        {
            "ioc_value": "104.128.92.144:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2021-10-31 17:43:37",
            "last_seen_utc": "2026-08-31 08:02:05",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,IT7NET",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "238207": [
        {
            "ioc_value": "fivepointschiro.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2021-10-27 09:58:20",
            "last_seen_utc": "2026-08-31 08:02:00",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://twitter.com/mojoesec/status/1453040284686770185",
            "tags": "CobaltStrike",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "236436": [
        {
            "ioc_value": "111.230.196.200:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2021-10-22 12:07:15",
            "last_seen_utc": "2026-08-31 08:01:49",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "233476": [
        {
            "ioc_value": "23.224.152.139:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2021-10-13 17:43:22",
            "last_seen_utc": "2026-08-31 08:01:47",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CNSERVERS,CobaltStrike",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "232821": [
        {
            "ioc_value": "139.198.183.44:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2021-10-11 23:27:10",
            "last_seen_utc": "2026-08-31 08:01:49",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,YUNIFY-NET Yunify Technologies Inc.",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "232263": [
        {
            "ioc_value": "121.37.255.60:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2021-10-09 23:36:53",
            "last_seen_utc": "2026-08-31 08:01:52",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,HWCSNET Huawei Cloud Service data center",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "223357": [
        {
            "ioc_value": "47.95.207.79:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2021-09-18 17:39:24",
            "last_seen_utc": "2026-08-31 08:01:50",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CNNIC-ALIBABA-CN-NET-AP Hangzhou Alibaba Advertising Co.Ltd.,CobaltStrike",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ]
}