{
    "1840275": [
        {
            "ioc_value": "bjsiw6ik.casinoiran.pro",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-30 11:25:24",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,mac-0xfb64,macos",
            "anonymous": "1",
            "reporter": "ttakvam"
        }
    ],
    "1840274": [
        {
            "ioc_value": "casinoiran.pro",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-30 11:24:28",
            "last_seen_utc": "2026-06-30 11:24:32",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "30June2026,ClearFake,Commandline,MacOS",
            "anonymous": "0",
            "reporter": "Gi7w0rm"
        }
    ],
    "1840273": [
        {
            "ioc_value": "6oekxs4k.vip1xbet.net",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-30 11:07:18",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,mac-0x68dc,macos",
            "anonymous": "1",
            "reporter": "ttakvam"
        }
    ],
    "1840272": [
        {
            "ioc_value": "152.32.132.177:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-06-30 11:05:05",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "cobaltstrike",
            "anonymous": "1",
            "reporter": "_ik_"
        }
    ],
    "1840225": [
        {
            "ioc_value": "http://153.117.41.127:47793/Mozi.a",
            "ioc_type": "url",
            "threat_type": "payload_delivery",
            "malware": "elf.mozi",
            "malware_alias": null,
            "malware_printable": "Mozi",
            "first_seen_utc": "2026-06-30 09:56:58",
            "last_seen_utc": null,
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://honeylabs.net/lookup/153.117.41.127",
            "tags": "elf,iot,Mozi",
            "anonymous": "0",
            "reporter": "HoneyLabs"
        }
    ],
    "1840226": [
        {
            "ioc_value": "http://110.37.35.79:33903/Mozi.m",
            "ioc_type": "url",
            "threat_type": "payload_delivery",
            "malware": "elf.mozi",
            "malware_alias": null,
            "malware_printable": "Mozi",
            "first_seen_utc": "2026-06-30 09:56:57",
            "last_seen_utc": null,
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://honeylabs.net/lookup/110.37.35.79",
            "tags": "elf,iot,Mozi",
            "anonymous": "0",
            "reporter": "HoneyLabs"
        }
    ],
    "1840227": [
        {
            "ioc_value": "https://backupper.pro",
            "ioc_type": "url",
            "threat_type": "payload_delivery",
            "malware": "js.magecart",
            "malware_alias": null,
            "malware_printable": "magecart",
            "first_seen_utc": "2026-06-30 09:56:57",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "magecart",
            "anonymous": "0",
            "reporter": "Localhost123"
        }
    ],
    "1840234": [
        {
            "ioc_value": "https://www.einvoicesolutions.com/",
            "ioc_type": "url",
            "threat_type": "payload_delivery",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-06-30 09:56:56",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": "https://clickfix.carsonww.com/domains/www.einvoicesolutions.com",
            "tags": "ClickFix",
            "anonymous": "0",
            "reporter": "CarsonWilliams"
        }
    ],
    "1840235": [
        {
            "ioc_value": "https://www.m-und-c-partners.de/",
            "ioc_type": "url",
            "threat_type": "payload_delivery",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-06-30 09:56:55",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": "https://clickfix.carsonww.com/domains/www.m-und-c-partners.de",
            "tags": "ClickFix",
            "anonymous": "0",
            "reporter": "CarsonWilliams"
        }
    ],
    "1840236": [
        {
            "ioc_value": "129.212.233.8:37215",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.aisuru",
            "malware_alias": null,
            "malware_printable": "Aisuru",
            "first_seen_utc": "2026-06-30 09:56:55",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "Aisuru,c2",
            "anonymous": "0",
            "reporter": "Bitsight"
        }
    ],
    "1840271": [
        {
            "ioc_value": "152.32.132.177:8899",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-06-30 09:54:11",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-666666666",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1840270": [
        {
            "ioc_value": "39.97.246.75:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-06-30 09:54:10",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-987654321",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1840269": [
        {
            "ioc_value": "179.43.190.13:8080",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-06-30 09:54:09",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-987654321",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1840268": [
        {
            "ioc_value": "94.250.201.212:4321",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-06-30 09:46:23",
            "last_seen_utc": "2026-06-30 10:46:18",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1840267": [
        {
            "ioc_value": "198.135.54.39:14642",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-06-30 09:44:26",
            "last_seen_utc": "2026-06-30 10:44:21",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1840266": [
        {
            "ioc_value": "192.162.199.149:6606",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-06-30 09:44:18",
            "last_seen_utc": "2026-06-30 10:44:13",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1840265": [
        {
            "ioc_value": "170.64.130.99:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-06-30 09:43:50",
            "last_seen_utc": "2026-06-30 10:43:46",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1840264": [
        {
            "ioc_value": "155.103.71.115:14656",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-06-30 09:43:39",
            "last_seen_utc": "2026-06-30 10:43:35",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1840263": [
        {
            "ioc_value": "152.42.164.27:65531",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-06-30 09:43:36",
            "last_seen_utc": "2026-06-30 10:43:32",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1840262": [
        {
            "ioc_value": "141.94.121.162:6666",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.dcrat",
            "malware_alias": "DarkCrystal RAT",
            "malware_printable": "DCRat",
            "first_seen_utc": "2026-06-30 09:43:27",
            "last_seen_utc": "2026-06-30 10:43:24",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DCRat,drb-ra,RAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1840261": [
        {
            "ioc_value": "136.113.49.8:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-06-30 09:43:24",
            "last_seen_utc": "2026-06-30 10:43:22",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1840260": [
        {
            "ioc_value": "103.11.41.10:2120",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-06-30 09:43:06",
            "last_seen_utc": "2026-06-30 10:43:05",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1840238": [
        {
            "ioc_value": "134.122.187.85:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-06-30 09:05:05",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "cobaltstrike",
            "anonymous": "1",
            "reporter": "_ik_"
        }
    ],
    "1840237": [
        {
            "ioc_value": "kdf.betbacklink.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-30 09:00:49",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake",
            "anonymous": "1",
            "reporter": "ttakvam"
        }
    ],
    "1840233": [
        {
            "ioc_value": "115.190.80.27:18085",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.vshell",
            "malware_alias": null,
            "malware_printable": "VShell",
            "first_seen_utc": "2026-06-30 07:05:09",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "vshell",
            "anonymous": "1",
            "reporter": "_ik_"
        }
    ],
    "1840232": [
        {
            "ioc_value": "134.122.187.85:9999",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-06-30 07:05:08",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "cobaltstrike",
            "anonymous": "1",
            "reporter": "_ik_"
        }
    ],
    "1840229": [
        {
            "ioc_value": "https://scp.jangkarsm188.top/",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-06-30 07:00:17",
            "last_seen_utc": "2026-06-30 10:25:39",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "vidar",
            "anonymous": "0",
            "reporter": "crep1x"
        }
    ],
    "1840230": [
        {
            "ioc_value": "scp.psgiran.news",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-06-30 07:00:17",
            "last_seen_utc": "2026-06-30 10:25:50",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "vidar",
            "anonymous": "0",
            "reporter": "crep1x"
        }
    ],
    "1840231": [
        {
            "ioc_value": "https://scp.psgiran.news/",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-06-30 07:00:17",
            "last_seen_utc": "2026-06-30 10:25:50",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "vidar",
            "anonymous": "0",
            "reporter": "crep1x"
        }
    ],
    "1840228": [
        {
            "ioc_value": "scp.jangkarsm188.top",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-06-30 07:00:16",
            "last_seen_utc": "2026-06-30 10:25:39",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "vidar",
            "anonymous": "0",
            "reporter": "crep1x"
        }
    ],
    "1840224": [
        {
            "ioc_value": "i5sofk6r.xbetone.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-30 06:04:15",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "clearfake",
            "anonymous": "1",
            "reporter": "ttakvam"
        }
    ],
    "1840218": [
        {
            "ioc_value": "imohoo.com.br",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-30 06:03:08",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClickFix,compromised,ErrTraffic",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1840219": [
        {
            "ioc_value": "unspanel.rs",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-30 06:03:08",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClickFix,compromised,ErrTraffic",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1840220": [
        {
            "ioc_value": "fearlesshomemaker.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-30 06:03:08",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClickFix,compromised,ErrTraffic",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1840221": [
        {
            "ioc_value": "keypharmacy.uk",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-30 06:03:08",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClickFix,compromised,ErrTraffic",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1840222": [
        {
            "ioc_value": "lifetimeeyecare.biz",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-30 06:03:08",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClickFix,compromised,ErrTraffic",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1840223": [
        {
            "ioc_value": "ajantaappliances.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-30 06:03:08",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClickFix,compromised,ErrTraffic",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1840217": [
        {
            "ioc_value": "thekiss.gr",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-30 06:03:07",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClickFix,compromised,ErrTraffic",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1840216": [
        {
            "ioc_value": "swanriverschool.org",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-30 06:03:06",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClickFix,compromised,ErrTraffic",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1840213": [
        {
            "ioc_value": "dainikkishoreganj.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-30 06:03:05",
            "last_seen_utc": "2026-06-30 06:05:32",
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClickFix,compromised,ErrTraffic",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1840214": [
        {
            "ioc_value": "alpin-tuning.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-30 06:03:05",
            "last_seen_utc": "2026-06-30 06:05:32",
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClickFix,compromised,ErrTraffic",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1840215": [
        {
            "ioc_value": "tools4teens.net",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-30 06:03:05",
            "last_seen_utc": "2026-06-30 06:05:32",
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClickFix,compromised,ErrTraffic",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1840208": [
        {
            "ioc_value": "phcnepal.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-30 06:03:04",
            "last_seen_utc": "2026-06-30 06:05:31",
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClickFix,compromised,ErrTraffic",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1840209": [
        {
            "ioc_value": "cakramakmurabadi.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-30 06:03:04",
            "last_seen_utc": "2026-06-30 06:05:31",
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClickFix,compromised,ErrTraffic",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1840210": [
        {
            "ioc_value": "insideautomacao.com.br",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-30 06:03:04",
            "last_seen_utc": "2026-06-30 06:05:31",
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClickFix,compromised,ErrTraffic",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1840211": [
        {
            "ioc_value": "hashsolution.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-30 06:03:04",
            "last_seen_utc": "2026-06-30 06:05:31",
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClickFix,compromised,ErrTraffic",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1840212": [
        {
            "ioc_value": "m-und-c-partners.de",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-30 06:03:04",
            "last_seen_utc": "2026-06-30 06:05:31",
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClickFix,compromised,ErrTraffic",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1840206": [
        {
            "ioc_value": "knowmat.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-30 06:03:03",
            "last_seen_utc": "2026-06-30 06:05:30",
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClickFix,compromised,ErrTraffic",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1840207": [
        {
            "ioc_value": "vihangamyoga.org",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-30 06:03:03",
            "last_seen_utc": "2026-06-30 06:05:30",
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClickFix,compromised,ErrTraffic",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1840205": [
        {
            "ioc_value": "lisanslab.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-30 06:03:02",
            "last_seen_utc": "2026-06-30 06:05:29",
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClickFix,compromised,ErrTraffic",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1840204": [
        {
            "ioc_value": "ce29b8c2576712a33aae06aee02486440c9268fcc19da1496a074feeee0a5178",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-30 05:54:20",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1840202": [
        {
            "ioc_value": "1.14.227.23:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-06-30 05:05:05",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "cobaltstrike",
            "anonymous": "1",
            "reporter": "_ik_"
        }
    ],
    "1840203": [
        {
            "ioc_value": "130.12.182.95:8808",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-06-30 05:05:05",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "asyncrat",
            "anonymous": "1",
            "reporter": "_ik_"
        }
    ],
    "1839848": [
        {
            "ioc_value": "php-panel.letsgoautomotive.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "unknown_stealer",
            "malware_alias": null,
            "malware_printable": "Unknown Stealer",
            "first_seen_utc": "2026-06-30 04:50:38",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "SocGholish",
            "anonymous": "0",
            "reporter": "varysz"
        }
    ],
    "1839852": [
        {
            "ioc_value": "http://31.56.48.179:666/w",
            "ioc_type": "url",
            "threat_type": "payload_delivery",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-06-30 04:50:38",
            "last_seen_utc": "2026-06-29 16:03:10",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://stateoftheattack.com/campaign/scattershell-teampcp-v21",
            "tags": "container-escape,credential-harvest,cryptojacking,cve-2026-31431,docker,teampcp,teamtnt",
            "anonymous": "0",
            "reporter": "Stateoftheattack"
        }
    ],
    "1839853": [
        {
            "ioc_value": "http://31.56.48.179:666/.real_mnd",
            "ioc_type": "url",
            "threat_type": "payload_delivery",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-06-30 04:50:37",
            "last_seen_utc": "2026-06-29 16:03:10",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://stateoftheattack.com/campaign/scattershell-teampcp-v21",
            "tags": "container-escape,credential-harvest,cryptojacking,cve-2026-31431,docker,teampcp,teamtnt",
            "anonymous": "0",
            "reporter": "Stateoftheattack"
        }
    ],
    "1839854": [
        {
            "ioc_value": "http://31.56.48.179:666/.mconf",
            "ioc_type": "url",
            "threat_type": "payload_delivery",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-06-30 04:50:36",
            "last_seen_utc": "2026-06-29 16:03:10",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://stateoftheattack.com/campaign/scattershell-teampcp-v21",
            "tags": "container-escape,credential-harvest,cryptojacking,cve-2026-31431,docker,teampcp,teamtnt",
            "anonymous": "0",
            "reporter": "Stateoftheattack"
        }
    ],
    "1839856": [
        {
            "ioc_value": "27cc6cf232ba7ed8dc92dcb0795bdb7185197928ec3061a8d6de097f9efc5440",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-06-30 04:50:36",
            "last_seen_utc": null,
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://stateoftheattack.com/campaign/scattershell-teampcp-v21",
            "tags": "container-escape,credential-harvest,cryptojacking,cve-2026-31431,docker,teampcp,teamtnt",
            "anonymous": "0",
            "reporter": "Stateoftheattack"
        }
    ],
    "1839892": [
        {
            "ioc_value": "fee27090c90ed20350a65616c658f158bef9443ada21279c11cc9dbd125d363e",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "win.bumblebee",
            "malware_alias": "COLDTRAIN,SHELLSTING,Shindig",
            "malware_printable": "BumbleBee",
            "first_seen_utc": "2026-06-30 04:50:35",
            "last_seen_utc": null,
            "confidence_level": 50,
            "is_compromised": false,
            "reference": "",
            "tags": null,
            "anonymous": "1",
            "reporter": "Vincent"
        }
    ],
    "1839855": [
        {
            "ioc_value": "0f63bea320d768fb12bb53a287f210b8b9ccec563ac66dc80b7967628e455566",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-06-30 04:50:34",
            "last_seen_utc": null,
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://stateoftheattack.com/campaign/scattershell-teampcp-v21",
            "tags": "container-escape,credential-harvest,cryptojacking,cve-2026-31431,docker,teampcp,teamtnt",
            "anonymous": "0",
            "reporter": "Stateoftheattack"
        }
    ],
    "1839891": [
        {
            "ioc_value": "dff350f69d90cf8e6055054475b0c892b77610c734111c381dfbad8bb72b2b3d",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "win.bumblebee",
            "malware_alias": "COLDTRAIN,SHELLSTING,Shindig",
            "malware_printable": "BumbleBee",
            "first_seen_utc": "2026-06-30 04:50:33",
            "last_seen_utc": null,
            "confidence_level": 50,
            "is_compromised": false,
            "reference": "",
            "tags": null,
            "anonymous": "1",
            "reporter": "Vincent"
        }
    ],
    "1839894": [
        {
            "ioc_value": "172.86.123.37:8086",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "js.beavertail",
            "malware_alias": null,
            "malware_printable": "BeaverTail",
            "first_seen_utc": "2026-06-30 04:50:32",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "BeaverTail,chainvisitalabs,ContagiousInterview,DPRK",
            "anonymous": "0",
            "reporter": "fedfranz"
        }
    ],
    "1839893": [
        {
            "ioc_value": "7c71f81b6e981eb71d442a7e26df9ebf199665e5460da3b35b43496b380840a8",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "win.bumblebee",
            "malware_alias": "COLDTRAIN,SHELLSTING,Shindig",
            "malware_printable": "BumbleBee",
            "first_seen_utc": "2026-06-30 04:50:31",
            "last_seen_utc": null,
            "confidence_level": 50,
            "is_compromised": false,
            "reference": "",
            "tags": null,
            "anonymous": "1",
            "reporter": "Vincent"
        }
    ],
    "1839895": [
        {
            "ioc_value": "172.86.123.37:8087",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "js.beavertail",
            "malware_alias": null,
            "malware_printable": "BeaverTail",
            "first_seen_utc": "2026-06-30 04:50:30",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "BeaverTail,chainvisitalabs,ContagiousInterview,DPRK",
            "anonymous": "0",
            "reporter": "fedfranz"
        }
    ],
    "1839896": [
        {
            "ioc_value": "code-beautify.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.beavertail",
            "malware_alias": null,
            "malware_printable": "BeaverTail",
            "first_seen_utc": "2026-06-30 04:50:30",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "BeaverTail,chainvisitalabs,ContagiousInterview,DPRK",
            "anonymous": "0",
            "reporter": "fedfranz"
        }
    ],
    "1839897": [
        {
            "ioc_value": "ipregionchecker.org",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.beavertail",
            "malware_alias": null,
            "malware_printable": "BeaverTail",
            "first_seen_utc": "2026-06-30 04:50:29",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "BeaverTail,chainvisitalabs,ContagiousInterview,DPRK",
            "anonymous": "0",
            "reporter": "fedfranz"
        }
    ],
    "1839898": [
        {
            "ioc_value": "74009ad71c2f41ebfe6b76358f0224f814f8dca1167a858538b5e8df8a76b881",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "js.beavertail",
            "malware_alias": null,
            "malware_printable": "BeaverTail",
            "first_seen_utc": "2026-06-30 04:50:29",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "BeaverTail,chainvisitalabs,ContagiousInterview,DPRK",
            "anonymous": "0",
            "reporter": "fedfranz"
        }
    ],
    "1839900": [
        {
            "ioc_value": "017cb09cabd9c909e4fb06e8c668d2f89e472e103eda5230d98761a9f998bdb5",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "js.beavertail",
            "malware_alias": null,
            "malware_printable": "BeaverTail",
            "first_seen_utc": "2026-06-30 04:50:28",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "BeaverTail,chainvisitalabs,ContagiousInterview,DPRK",
            "anonymous": "0",
            "reporter": "fedfranz"
        }
    ],
    "1839899": [
        {
            "ioc_value": "0e1ae44c555c13b03bdbd72f66c456aaffcdd13887ebe9859d302a63e409c462",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "js.beavertail",
            "malware_alias": null,
            "malware_printable": "BeaverTail",
            "first_seen_utc": "2026-06-30 04:50:27",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "BeaverTail,chainvisitalabs,ContagiousInterview,DPRK",
            "anonymous": "0",
            "reporter": "fedfranz"
        }
    ],
    "1840070": [
        {
            "ioc_value": "https://isabeladandaro.com.br/diagnostico-de-honorarios-convite/?src=Org_Site&utm_source=Org&utm_medium=Site&utm_content=&utm_campaign=&utm_term=",
            "ioc_type": "url",
            "threat_type": "payload_delivery",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-06-30 04:50:27",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": "https://clickfix.carsonww.com/domains/isabeladandaro.com.br",
            "tags": "ClickFix",
            "anonymous": "0",
            "reporter": "CarsonWilliams"
        }
    ],
    "1840071": [
        {
            "ioc_value": "https://www.ibogainerapiddetox.com/",
            "ioc_type": "url",
            "threat_type": "payload_delivery",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-06-30 04:50:24",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": "https://clickfix.carsonww.com/domains/www.ibogainerapiddetox.com",
            "tags": "ClickFix",
            "anonymous": "0",
            "reporter": "CarsonWilliams"
        }
    ],
    "1840072": [
        {
            "ioc_value": "https://ackeamann.xyz/file.js",
            "ioc_type": "url",
            "threat_type": "payload_delivery",
            "malware": "js.kongtuke",
            "malware_alias": "TAG-124,js.LandUpdate808",
            "malware_printable": "KongTuke",
            "first_seen_utc": "2026-06-30 04:50:23",
            "last_seen_utc": "2026-06-30 04:10:36",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": "https://infosec.exchange/@monitorsg/116834503395473857",
            "tags": "KongTuke",
            "anonymous": "0",
            "reporter": "monitorsg"
        }
    ],
    "1840073": [
        {
            "ioc_value": "ackeamann.xyz",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.kongtuke",
            "malware_alias": "TAG-124,js.LandUpdate808",
            "malware_printable": "KongTuke",
            "first_seen_utc": "2026-06-30 04:50:23",
            "last_seen_utc": "2026-06-30 04:10:37",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": "https://infosec.exchange/@monitorsg/116834503395473857",
            "tags": "KongTuke",
            "anonymous": "0",
            "reporter": "monitorsg"
        }
    ],
    "1840074": [
        {
            "ioc_value": "https://ackeamann.xyz/api/v1/session",
            "ioc_type": "url",
            "threat_type": "payload_delivery",
            "malware": "js.kongtuke",
            "malware_alias": "TAG-124,js.LandUpdate808",
            "malware_printable": "KongTuke",
            "first_seen_utc": "2026-06-30 04:50:22",
            "last_seen_utc": "2026-06-30 04:10:38",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": "https://infosec.exchange/@monitorsg/116834503395473857",
            "tags": "KongTuke",
            "anonymous": "0",
            "reporter": "monitorsg"
        }
    ],
    "1840075": [
        {
            "ioc_value": "https://ackeamann.xyz/api/v1/verify",
            "ioc_type": "url",
            "threat_type": "payload_delivery",
            "malware": "js.kongtuke",
            "malware_alias": "TAG-124,js.LandUpdate808",
            "malware_printable": "KongTuke",
            "first_seen_utc": "2026-06-30 04:50:22",
            "last_seen_utc": "2026-06-30 04:10:38",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": "https://infosec.exchange/@monitorsg/116834503395473857",
            "tags": "KongTuke",
            "anonymous": "0",
            "reporter": "monitorsg"
        }
    ],
    "1840076": [
        {
            "ioc_value": "https://ackeamann.xyz/api/v1/status",
            "ioc_type": "url",
            "threat_type": "payload_delivery",
            "malware": "js.kongtuke",
            "malware_alias": "TAG-124,js.LandUpdate808",
            "malware_printable": "KongTuke",
            "first_seen_utc": "2026-06-30 04:50:21",
            "last_seen_utc": "2026-06-29 19:07:36",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": "https://infosec.exchange/@monitorsg/116834503395473857",
            "tags": "KongTuke",
            "anonymous": "0",
            "reporter": "monitorsg"
        }
    ],
    "1840077": [
        {
            "ioc_value": "cleardig477.icu",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "unknown_loader",
            "malware_alias": null,
            "malware_printable": "Unknown Loader",
            "first_seen_utc": "2026-06-30 04:50:21",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://app.any.run/tasks/3e1f08ea-8329-4469-8f06-8088b5c67c7b",
            "tags": "clickfix,etherhiding",
            "anonymous": "0",
            "reporter": "Overkill1984zzz"
        }
    ],
    "1840079": [
        {
            "ioc_value": "superfirewallprotection.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "unknown_loader",
            "malware_alias": null,
            "malware_printable": "Unknown Loader",
            "first_seen_utc": "2026-06-30 04:50:20",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://app.any.run/tasks/5c762349-e152-4fde-82d1-60b62d0f0e48",
            "tags": "clickfix,etherhiding",
            "anonymous": "0",
            "reporter": "Overkill1984zzz"
        }
    ],
    "1840080": [
        {
            "ioc_value": "moderncloudprotection.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "unknown_loader",
            "malware_alias": null,
            "malware_printable": "Unknown Loader",
            "first_seen_utc": "2026-06-30 04:50:20",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://app.any.run/tasks/5c762349-e152-4fde-82d1-60b62d0f0e48",
            "tags": "clickfix,etherhiding",
            "anonymous": "0",
            "reporter": "Overkill1984zzz"
        }
    ],
    "1840081": [
        {
            "ioc_value": "publicwebprotection.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "unknown_loader",
            "malware_alias": null,
            "malware_printable": "Unknown Loader",
            "first_seen_utc": "2026-06-30 04:50:19",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://app.any.run/tasks/5c762349-e152-4fde-82d1-60b62d0f0e48",
            "tags": "clickfix,etherhiding",
            "anonymous": "0",
            "reporter": "Overkill1984zzz"
        }
    ],
    "1840097": [
        {
            "ioc_value": "https://datacrypt5840.top/update/package",
            "ioc_type": "url",
            "threat_type": "payload_delivery",
            "malware": "js.kongtuke",
            "malware_alias": "TAG-124,js.LandUpdate808",
            "malware_printable": "KongTuke",
            "first_seen_utc": "2026-06-30 04:50:18",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": "https://infosec.exchange/@monitorsg/116834962514966770",
            "tags": "KongTuke",
            "anonymous": "0",
            "reporter": "monitorsg"
        }
    ],
    "1840146": [
        {
            "ioc_value": "https://eb0ca005.verifying-your-identity-proceedv1.pages.dev/?x=j7b5cr22&y=1782755817438&z=425693",
            "ioc_type": "url",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-30 04:50:17",
            "last_seen_utc": "2026-06-30 06:31:03",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "ClearFake,ClickFix",
            "anonymous": "1",
            "reporter": "GovCERT_CH"
        }
    ],
    "1840158": [
        {
            "ioc_value": "api-v2.golfsignpro.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "js.fakeupdates",
            "malware_alias": "FakeUpdate,GhoLoader,SocGholish",
            "malware_printable": "FAKEUPDATES",
            "first_seen_utc": "2026-06-30 04:50:17",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": "https://infosec.exchange/@monitorsg/116835207888527012",
            "tags": "SocGholish",
            "anonymous": "0",
            "reporter": "monitorsg"
        }
    ],
    "1840161": [
        {
            "ioc_value": "178.128.253.253:25001",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "apk.kimwolf",
            "malware_alias": null,
            "malware_printable": "Kimwolf",
            "first_seen_utc": "2026-06-30 04:50:16",
            "last_seen_utc": "2026-06-30 11:10:33",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "c2,Kimwolf",
            "anonymous": "0",
            "reporter": "Bitsight"
        }
    ],
    "1840162": [
        {
            "ioc_value": "157.245.65.67:25001",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "apk.kimwolf",
            "malware_alias": null,
            "malware_printable": "Kimwolf",
            "first_seen_utc": "2026-06-30 04:50:16",
            "last_seen_utc": "2026-06-30 11:12:21",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "c2,Kimwolf",
            "anonymous": "0",
            "reporter": "Bitsight"
        }
    ],
    "1840163": [
        {
            "ioc_value": "159.223.5.30:25001",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "apk.kimwolf",
            "malware_alias": null,
            "malware_printable": "Kimwolf",
            "first_seen_utc": "2026-06-30 04:50:15",
            "last_seen_utc": "2026-06-30 11:11:59",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "c2,Kimwolf",
            "anonymous": "0",
            "reporter": "Bitsight"
        }
    ],
    "1840164": [
        {
            "ioc_value": "206.189.7.4:25001",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "apk.kimwolf",
            "malware_alias": null,
            "malware_printable": "Kimwolf",
            "first_seen_utc": "2026-06-30 04:50:15",
            "last_seen_utc": "2026-06-30 11:11:35",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "c2,Kimwolf",
            "anonymous": "0",
            "reporter": "Bitsight"
        }
    ],
    "1840165": [
        {
            "ioc_value": "167.71.7.92:25001",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "apk.kimwolf",
            "malware_alias": null,
            "malware_printable": "Kimwolf",
            "first_seen_utc": "2026-06-30 04:50:15",
            "last_seen_utc": "2026-06-30 11:11:24",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "c2,Kimwolf",
            "anonymous": "0",
            "reporter": "Bitsight"
        }
    ],
    "1840166": [
        {
            "ioc_value": "178.128.243.177:25001",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "apk.kimwolf",
            "malware_alias": null,
            "malware_printable": "Kimwolf",
            "first_seen_utc": "2026-06-30 04:50:14",
            "last_seen_utc": "2026-06-30 11:12:10",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "c2,Kimwolf",
            "anonymous": "0",
            "reporter": "Bitsight"
        }
    ],
    "1840167": [
        {
            "ioc_value": "188.166.24.139:25001",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "apk.kimwolf",
            "malware_alias": null,
            "malware_printable": "Kimwolf",
            "first_seen_utc": "2026-06-30 04:50:14",
            "last_seen_utc": "2026-06-30 11:11:00",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "c2,Kimwolf",
            "anonymous": "0",
            "reporter": "Bitsight"
        }
    ],
    "1840169": [
        {
            "ioc_value": "206.189.101.38:25001",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "apk.kimwolf",
            "malware_alias": null,
            "malware_printable": "Kimwolf",
            "first_seen_utc": "2026-06-30 04:50:13",
            "last_seen_utc": "2026-06-30 11:11:12",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "c2,Kimwolf",
            "anonymous": "0",
            "reporter": "Bitsight"
        }
    ],
    "1840168": [
        {
            "ioc_value": "152.42.129.15:25001",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "apk.kimwolf",
            "malware_alias": null,
            "malware_printable": "Kimwolf",
            "first_seen_utc": "2026-06-30 04:50:11",
            "last_seen_utc": "2026-06-30 11:11:48",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "c2,Kimwolf",
            "anonymous": "0",
            "reporter": "Bitsight"
        }
    ],
    "1840170": [
        {
            "ioc_value": "209.38.35.163:25001",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "apk.kimwolf",
            "malware_alias": null,
            "malware_printable": "Kimwolf",
            "first_seen_utc": "2026-06-30 04:50:10",
            "last_seen_utc": "2026-06-30 11:10:45",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "c2,Kimwolf",
            "anonymous": "0",
            "reporter": "Bitsight"
        }
    ],
    "1840186": [
        {
            "ioc_value": "https://scanbot.me/scanbot.sh",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "elf.sshdoor",
            "malware_alias": null,
            "malware_printable": "SSHDoor",
            "first_seen_utc": "2026-06-30 04:50:09",
            "last_seen_utc": null,
            "confidence_level": 50,
            "is_compromised": false,
            "reference": "",
            "tags": null,
            "anonymous": "0",
            "reporter": "ClearlyNotB"
        }
    ],
    "1840173": [
        {
            "ioc_value": "https://ottixpimobiliaria.com/",
            "ioc_type": "url",
            "threat_type": "payload_delivery",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-06-30 04:50:05",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": "https://clickfix.carsonww.com/domains/ottixpimobiliaria.com",
            "tags": "ClickFix",
            "anonymous": "0",
            "reporter": "CarsonWilliams"
        }
    ],
    "1840180": [
        {
            "ioc_value": "cloud.api-middle-connect.com",
            "ioc_type": "domain",
            "threat_type": "cc_skimming",
            "malware": "js.magecart",
            "malware_alias": null,
            "malware_printable": "magecart",
            "first_seen_utc": "2026-06-30 04:50:05",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": null,
            "anonymous": "0",
            "reporter": "Localhost123"
        }
    ],
    "1840182": [
        {
            "ioc_value": "https://patrickfarrellbooks.com/",
            "ioc_type": "url",
            "threat_type": "payload_delivery",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-06-30 04:50:03",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": "https://clickfix.carsonww.com/domains/patrickfarrellbooks.com",
            "tags": "ClickFix",
            "anonymous": "0",
            "reporter": "CarsonWilliams"
        }
    ],
    "1840183": [
        {
            "ioc_value": "https://portalpsicosocial.es/",
            "ioc_type": "url",
            "threat_type": "payload_delivery",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-06-30 04:50:03",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": "https://clickfix.carsonww.com/domains/portalpsicosocial.es",
            "tags": "ClickFix",
            "anonymous": "0",
            "reporter": "CarsonWilliams"
        }
    ],
    "1840188": [
        {
            "ioc_value": "http://94.154.43.5/mips",
            "ioc_type": "url",
            "threat_type": "payload_delivery",
            "malware": "elf.mirai",
            "malware_alias": "Katana",
            "malware_printable": "Mirai",
            "first_seen_utc": "2026-06-30 04:50:01",
            "last_seen_utc": null,
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://honeylabs.net/lookup/94.154.43.5",
            "tags": "elf,iot",
            "anonymous": "0",
            "reporter": "HoneyLabs"
        }
    ],
    "1840189": [
        {
            "ioc_value": "a5b42be0041bff5a4e521412014c2e7029ff08df7e9746fb4d923d40cee0e7d7",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "elf.mirai",
            "malware_alias": "Katana",
            "malware_printable": "Mirai",
            "first_seen_utc": "2026-06-30 04:50:01",
            "last_seen_utc": null,
            "confidence_level": 80,
            "is_compromised": false,
            "reference": "https://honeylabs.net/lookup/94.154.43.5",
            "tags": "elf,iot",
            "anonymous": "0",
            "reporter": "HoneyLabs"
        }
    ],
    "1840190": [
        {
            "ioc_value": "https://romayahomes.co.uk/",
            "ioc_type": "url",
            "threat_type": "payload_delivery",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-06-30 04:50:00",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": "https://clickfix.carsonww.com/domains/romayahomes.co.uk",
            "tags": "ClickFix",
            "anonymous": "0",
            "reporter": "CarsonWilliams"
        }
    ],
    "1840194": [
        {
            "ioc_value": "162.243.103.246:8443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-06-30 04:49:59",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "c2,erebus-v14,nation-state-hunter,t1059_003,t1105",
            "anonymous": "0",
            "reporter": "Erebu"
        }
    ],
    "1840195": [
        {
            "ioc_value": "https://seniorcitizenjournal.com/",
            "ioc_type": "url",
            "threat_type": "payload_delivery",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-06-30 04:49:59",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": "https://clickfix.carsonww.com/domains/seniorcitizenjournal.com",
            "tags": "ClickFix",
            "anonymous": "0",
            "reporter": "CarsonWilliams"
        }
    ],
    "1840196": [
        {
            "ioc_value": "https://leinstermetalrecycling.ie/",
            "ioc_type": "url",
            "threat_type": "payload_delivery",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-06-30 04:49:59",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": "https://clickfix.carsonww.com/domains/leinstermetalrecycling.ie",
            "tags": "ClickFix",
            "anonymous": "0",
            "reporter": "CarsonWilliams"
        }
    ],
    "1840198": [
        {
            "ioc_value": "https://itsrealmedia.com/",
            "ioc_type": "url",
            "threat_type": "payload_delivery",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-06-30 04:49:58",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": "https://clickfix.carsonww.com/domains/itsrealmedia.com",
            "tags": "ClickFix",
            "anonymous": "0",
            "reporter": "CarsonWilliams"
        }
    ],
    "1840200": [
        {
            "ioc_value": "1.117.77.166:8084",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.vshell",
            "malware_alias": null,
            "malware_printable": "VShell",
            "first_seen_utc": "2026-06-30 04:05:07",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "vshell",
            "anonymous": "1",
            "reporter": "_ik_"
        }
    ],
    "1840201": [
        {
            "ioc_value": "173.211.46.220:53306",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.vshell",
            "malware_alias": null,
            "malware_printable": "VShell",
            "first_seen_utc": "2026-06-30 04:05:07",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "vshell",
            "anonymous": "1",
            "reporter": "_ik_"
        }
    ],
    "1840199": [
        {
            "ioc_value": "110.42.252.147:8888",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-06-30 04:05:05",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "supershell",
            "anonymous": "1",
            "reporter": "_ik_"
        }
    ],
    "1840197": [
        {
            "ioc_value": "46imdg6k.blackjackonlineplay83.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-30 02:03:29",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "clearfake",
            "anonymous": "1",
            "reporter": "ttakvam"
        }
    ],
    "1840193": [
        {
            "ioc_value": "https://alpin-tuning.com/",
            "ioc_type": "url",
            "threat_type": "payload_delivery",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-06-30 01:15:03",
            "last_seen_utc": "2026-06-30 03:31:03",
            "confidence_level": 75,
            "is_compromised": true,
            "reference": null,
            "tags": "ClickFix,compromised,EtherHiding,Polygon,Vidar,WordPress",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1840192": [
        {
            "ioc_value": "328bpzpg.313betapk.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-30 01:02:17",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "clearfake",
            "anonymous": "1",
            "reporter": "ttakvam"
        }
    ],
    "1840191": [
        {
            "ioc_value": "http://149.30.222.4/getinstall64",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.valley_rat",
            "malware_alias": "Winos",
            "malware_printable": "ValleyRAT",
            "first_seen_utc": "2026-06-30 00:40:12",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "RAT,ValleyRAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1840187": [
        {
            "ioc_value": "uhv95fx8.betbuf.live",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-30 00:01:58",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake",
            "anonymous": "0",
            "reporter": "threatcat_ch"
        }
    ],
    "1840185": [
        {
            "ioc_value": "150.109.186.36:64401",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-06-29 23:46:01",
            "last_seen_utc": "2026-06-30 10:46:46",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1840184": [
        {
            "ioc_value": "47.243.127.117:889",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.valley_rat",
            "malware_alias": "Winos",
            "malware_printable": "ValleyRAT",
            "first_seen_utc": "2026-06-29 23:05:41",
            "last_seen_utc": null,
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://bazaar.abuse.ch/sample/a81dd7a5c94f3f82fe489a5e9ccb5e8618f22d3846d1d74388e88e399a8de2e7/",
            "tags": "valleyrat_s2",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1840181": [
        {
            "ioc_value": "47.243.127.117:887",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.valley_rat",
            "malware_alias": "Winos",
            "malware_printable": "ValleyRAT",
            "first_seen_utc": "2026-06-29 22:55:07",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "RAT,ValleyRAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1840179": [
        {
            "ioc_value": "176.65.144.73:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.stealc",
            "malware_alias": null,
            "malware_printable": "Stealc",
            "first_seen_utc": "2026-06-29 22:05:05",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "stealc",
            "anonymous": "1",
            "reporter": "_ik_"
        }
    ],
    "1840178": [
        {
            "ioc_value": "0dahrppq.taktikbet.bio",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 22:01:57",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "clearfake",
            "anonymous": "1",
            "reporter": "ttakvam"
        }
    ],
    "1840177": [
        {
            "ioc_value": "https://tps.psgiran.news/",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-06-29 22:00:20",
            "last_seen_utc": "2026-06-30 06:26:17",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "vidar",
            "anonymous": "0",
            "reporter": "crep1x"
        }
    ],
    "1840176": [
        {
            "ioc_value": "tps.psgiran.news",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-06-29 22:00:19",
            "last_seen_utc": "2026-06-30 06:26:17",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "vidar",
            "anonymous": "0",
            "reporter": "crep1x"
        }
    ],
    "1840174": [
        {
            "ioc_value": "tps.jangkarsm188.top",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-06-29 22:00:18",
            "last_seen_utc": "2026-06-30 06:26:05",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "vidar",
            "anonymous": "0",
            "reporter": "crep1x"
        }
    ],
    "1840175": [
        {
            "ioc_value": "https://tps.jangkarsm188.top/",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-06-29 22:00:18",
            "last_seen_utc": "2026-06-30 06:26:05",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "vidar",
            "anonymous": "0",
            "reporter": "crep1x"
        }
    ],
    "1840171": [
        {
            "ioc_value": "172.245.226.124:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-06-29 21:05:05",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "cobaltstrike",
            "anonymous": "1",
            "reporter": "_ik_"
        }
    ],
    "1840160": [
        {
            "ioc_value": "http://176.65.144.73/312b423bf6dd463f8d15.php",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.stealc",
            "malware_alias": null,
            "malware_printable": "Stealc",
            "first_seen_utc": "2026-06-29 20:20:32",
            "last_seen_utc": "2026-06-30 11:02:23",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://bazaar.abuse.ch/sample/25572b53676f1041dfec6ddd3ac1b47c5db8c384c98aac6238c463ada08ad523/",
            "tags": "stealc",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1840159": [
        {
            "ioc_value": "158.160.75.185:40644",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.raton_rat",
            "malware_alias": null,
            "malware_printable": "RatonRAT",
            "first_seen_utc": "2026-06-29 20:20:07",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "RatonRAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1840157": [
        {
            "ioc_value": "45.141.27.68:4959",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remus",
            "malware_alias": null,
            "malware_printable": "Remus",
            "first_seen_utc": "2026-06-29 19:50:54",
            "last_seen_utc": null,
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://bazaar.abuse.ch/sample/64f5d668ffdd18dc9dac0da41d409727b2521d920266f79b914483c9d3a76972/",
            "tags": "remus",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1840156": [
        {
            "ioc_value": "http://miedorama.com:4959",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.remus",
            "malware_alias": null,
            "malware_printable": "Remus",
            "first_seen_utc": "2026-06-29 19:50:52",
            "last_seen_utc": null,
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://bazaar.abuse.ch/sample/64f5d668ffdd18dc9dac0da41d409727b2521d920266f79b914483c9d3a76972/",
            "tags": "remus",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1840155": [
        {
            "ioc_value": "72.60.121.225:7838",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remus",
            "malware_alias": null,
            "malware_printable": "Remus",
            "first_seen_utc": "2026-06-29 19:50:51",
            "last_seen_utc": null,
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://bazaar.abuse.ch/sample/64f5d668ffdd18dc9dac0da41d409727b2521d920266f79b914483c9d3a76972/",
            "tags": "remus",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1840154": [
        {
            "ioc_value": "http://angect.xyz:7838",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.remus",
            "malware_alias": null,
            "malware_printable": "Remus",
            "first_seen_utc": "2026-06-29 19:50:50",
            "last_seen_utc": null,
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://bazaar.abuse.ch/sample/64f5d668ffdd18dc9dac0da41d409727b2521d920266f79b914483c9d3a76972/",
            "tags": "remus",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1840153": [
        {
            "ioc_value": "81.90.31.253:4321",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-06-29 19:45:30",
            "last_seen_utc": "2026-06-30 10:46:08",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1840152": [
        {
            "ioc_value": "193.169.194.63:32333",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-06-29 19:44:01",
            "last_seen_utc": "2026-06-30 10:44:17",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1840151": [
        {
            "ioc_value": "185.115.164.60:9486",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-06-29 19:43:50",
            "last_seen_utc": "2026-06-30 10:44:03",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1840150": [
        {
            "ioc_value": "155.138.218.137:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-06-29 19:43:30",
            "last_seen_utc": "2026-06-30 10:43:36",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1840149": [
        {
            "ioc_value": "128.90.141.238:4444",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-06-29 19:43:17",
            "last_seen_utc": "2026-06-30 10:43:20",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1840148": [
        {
            "ioc_value": "128.90.112.249:5202",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.dcrat",
            "malware_alias": "DarkCrystal RAT",
            "malware_printable": "DCRat",
            "first_seen_utc": "2026-06-29 19:43:16",
            "last_seen_utc": "2026-06-30 10:43:19",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DCRat,drb-ra,RAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1840147": [
        {
            "ioc_value": "103.11.41.10:52046",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-06-29 19:43:05",
            "last_seen_utc": "2026-06-30 10:43:06",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1840145": [
        {
            "ioc_value": "a8480f1bd4fc75a68930f3c60df63955",
            "ioc_type": "md5_hash",
            "threat_type": "payload",
            "malware": "win.valley_rat",
            "malware_alias": "Winos",
            "malware_printable": "ValleyRAT",
            "first_seen_utc": "2026-06-29 19:10:46",
            "last_seen_utc": null,
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": "0",
            "reporter": "Grim"
        }
    ],
    "1840142": [
        {
            "ioc_value": "63844cd3d2578789f0e5ca58cfddf9d4",
            "ioc_type": "md5_hash",
            "threat_type": "payload",
            "malware": "win.valley_rat",
            "malware_alias": "Winos",
            "malware_printable": "ValleyRAT",
            "first_seen_utc": "2026-06-29 19:10:45",
            "last_seen_utc": null,
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": "0",
            "reporter": "Grim"
        }
    ],
    "1840143": [
        {
            "ioc_value": "ffe98374173d7c2084a1a6953b308c13a8b9493294af831c23542b0d88654036",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "win.valley_rat",
            "malware_alias": "Winos",
            "malware_printable": "ValleyRAT",
            "first_seen_utc": "2026-06-29 19:10:45",
            "last_seen_utc": null,
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": "0",
            "reporter": "Grim"
        }
    ],
    "1840144": [
        {
            "ioc_value": "ce609cfde7d81bc7311a83e0f008a2f756912ea9",
            "ioc_type": "sha1_hash",
            "threat_type": "payload",
            "malware": "win.valley_rat",
            "malware_alias": "Winos",
            "malware_printable": "ValleyRAT",
            "first_seen_utc": "2026-06-29 19:10:45",
            "last_seen_utc": null,
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": "0",
            "reporter": "Grim"
        }
    ],
    "1840139": [
        {
            "ioc_value": "1ccf41cfd9d85a0e6c49854e25d76ab5",
            "ioc_type": "md5_hash",
            "threat_type": "payload",
            "malware": "win.coinminer",
            "malware_alias": null,
            "malware_printable": "Coinminer",
            "first_seen_utc": "2026-06-29 19:10:44",
            "last_seen_utc": null,
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": "0",
            "reporter": "Grim"
        }
    ],
    "1840140": [
        {
            "ioc_value": "d6ca3c85df784f0b7751f67bc0b23f44f173b7be7f6344d02f26c8e28e0abad8",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "win.valley_rat",
            "malware_alias": "Winos",
            "malware_printable": "ValleyRAT",
            "first_seen_utc": "2026-06-29 19:10:44",
            "last_seen_utc": null,
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": "0",
            "reporter": "Grim"
        }
    ],
    "1840141": [
        {
            "ioc_value": "ab84b6726d46e9cdc1349d2c8cfb9777dac57101",
            "ioc_type": "sha1_hash",
            "threat_type": "payload",
            "malware": "win.valley_rat",
            "malware_alias": "Winos",
            "malware_printable": "ValleyRAT",
            "first_seen_utc": "2026-06-29 19:10:44",
            "last_seen_utc": null,
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": "0",
            "reporter": "Grim"
        }
    ],
    "1840136": [
        {
            "ioc_value": "04f340ede96f607f310a9ca67370a5e5",
            "ioc_type": "md5_hash",
            "threat_type": "payload",
            "malware": "win.nanocore",
            "malware_alias": "Nancrat,NanoCore",
            "malware_printable": "Nanocore RAT",
            "first_seen_utc": "2026-06-29 19:10:43",
            "last_seen_utc": null,
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": "0",
            "reporter": "Grim"
        }
    ],
    "1840137": [
        {
            "ioc_value": "3f076a3e4a0733c630d58f790dc8b6422c5ee6344695f88987b14a060d721d4f",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "win.coinminer",
            "malware_alias": null,
            "malware_printable": "Coinminer",
            "first_seen_utc": "2026-06-29 19:10:43",
            "last_seen_utc": null,
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": "0",
            "reporter": "Grim"
        }
    ],
    "1840138": [
        {
            "ioc_value": "f2a03400898271b8fb6310151c56edf1120b736c",
            "ioc_type": "sha1_hash",
            "threat_type": "payload",
            "malware": "win.coinminer",
            "malware_alias": null,
            "malware_printable": "Coinminer",
            "first_seen_utc": "2026-06-29 19:10:43",
            "last_seen_utc": null,
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": "0",
            "reporter": "Grim"
        }
    ],
    "1840133": [
        {
            "ioc_value": "d11ea15f2c690f46bfc282f300f692c1",
            "ioc_type": "md5_hash",
            "threat_type": "payload",
            "malware": "win.nanocore",
            "malware_alias": "Nancrat,NanoCore",
            "malware_printable": "Nanocore RAT",
            "first_seen_utc": "2026-06-29 19:10:42",
            "last_seen_utc": null,
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": "0",
            "reporter": "Grim"
        }
    ],
    "1840134": [
        {
            "ioc_value": "1d805377c6dc2c4321897789d82add4d2e83e947c5fe2a182061484db840d7bb",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "win.nanocore",
            "malware_alias": "Nancrat,NanoCore",
            "malware_printable": "Nanocore RAT",
            "first_seen_utc": "2026-06-29 19:10:42",
            "last_seen_utc": null,
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": "0",
            "reporter": "Grim"
        }
    ],
    "1840135": [
        {
            "ioc_value": "e7feba95e7553a8d070623a279def1fabebe1ca8",
            "ioc_type": "sha1_hash",
            "threat_type": "payload",
            "malware": "win.nanocore",
            "malware_alias": "Nancrat,NanoCore",
            "malware_printable": "Nanocore RAT",
            "first_seen_utc": "2026-06-29 19:10:42",
            "last_seen_utc": null,
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": "0",
            "reporter": "Grim"
        }
    ],
    "1840129": [
        {
            "ioc_value": "b6c0e1b9da3c8f21bffbe878f58f3513848f3748",
            "ioc_type": "sha1_hash",
            "threat_type": "payload",
            "malware": "win.nanocore",
            "malware_alias": "Nancrat,NanoCore",
            "malware_printable": "Nanocore RAT",
            "first_seen_utc": "2026-06-29 19:10:41",
            "last_seen_utc": null,
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": "0",
            "reporter": "Grim"
        }
    ],
    "1840130": [
        {
            "ioc_value": "5fea3f930de097794a95ced9dbae500c",
            "ioc_type": "md5_hash",
            "threat_type": "payload",
            "malware": "win.nanocore",
            "malware_alias": "Nancrat,NanoCore",
            "malware_printable": "Nanocore RAT",
            "first_seen_utc": "2026-06-29 19:10:41",
            "last_seen_utc": null,
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": "0",
            "reporter": "Grim"
        }
    ],
    "1840131": [
        {
            "ioc_value": "cfa1674a075c651c7bf0278f5fffc2ed2d268f4317eb41faf1d1eb03c14bdb04",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "win.nanocore",
            "malware_alias": "Nancrat,NanoCore",
            "malware_printable": "Nanocore RAT",
            "first_seen_utc": "2026-06-29 19:10:41",
            "last_seen_utc": null,
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": "0",
            "reporter": "Grim"
        }
    ],
    "1840132": [
        {
            "ioc_value": "999dbc13a581e26dd6e2931db152b01087d13c92",
            "ioc_type": "sha1_hash",
            "threat_type": "payload",
            "malware": "win.nanocore",
            "malware_alias": "Nancrat,NanoCore",
            "malware_printable": "Nanocore RAT",
            "first_seen_utc": "2026-06-29 19:10:41",
            "last_seen_utc": null,
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": "0",
            "reporter": "Grim"
        }
    ],
    "1840126": [
        {
            "ioc_value": "1a46239db708d9eb82152b45392433be8f182b22",
            "ioc_type": "sha1_hash",
            "threat_type": "payload",
            "malware": "win.nanocore",
            "malware_alias": "Nancrat,NanoCore",
            "malware_printable": "Nanocore RAT",
            "first_seen_utc": "2026-06-29 19:10:40",
            "last_seen_utc": null,
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": "0",
            "reporter": "Grim"
        }
    ],
    "1840127": [
        {
            "ioc_value": "1615ac4b69265a70f17a0eb37df82065",
            "ioc_type": "md5_hash",
            "threat_type": "payload",
            "malware": "win.nanocore",
            "malware_alias": "Nancrat,NanoCore",
            "malware_printable": "Nanocore RAT",
            "first_seen_utc": "2026-06-29 19:10:40",
            "last_seen_utc": null,
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": "0",
            "reporter": "Grim"
        }
    ],
    "1840128": [
        {
            "ioc_value": "af154a4bb20730e0d8f7e88179b1797d8e67b23302ee2a0fa152dbd23a39a9dd",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "win.nanocore",
            "malware_alias": "Nancrat,NanoCore",
            "malware_printable": "Nanocore RAT",
            "first_seen_utc": "2026-06-29 19:10:40",
            "last_seen_utc": null,
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": "0",
            "reporter": "Grim"
        }
    ],
    "1840123": [
        {
            "ioc_value": "2f299b8f3839e4259a27f4b1d8af0d2473cfe7e0",
            "ioc_type": "sha1_hash",
            "threat_type": "payload",
            "malware": "win.njrat",
            "malware_alias": "Bladabindi,Lime-Worm",
            "malware_printable": "NjRAT",
            "first_seen_utc": "2026-06-29 19:10:39",
            "last_seen_utc": null,
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": "0",
            "reporter": "Grim"
        }
    ],
    "1840124": [
        {
            "ioc_value": "1e3fd12fee9d2fd27642ed24cff01338",
            "ioc_type": "md5_hash",
            "threat_type": "payload",
            "malware": "win.njrat",
            "malware_alias": "Bladabindi,Lime-Worm",
            "malware_printable": "NjRAT",
            "first_seen_utc": "2026-06-29 19:10:39",
            "last_seen_utc": null,
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": "0",
            "reporter": "Grim"
        }
    ],
    "1840125": [
        {
            "ioc_value": "604a502f34aa28773356a131d2ce537866cdd973e464a7144b0d626fd65f5937",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "win.nanocore",
            "malware_alias": "Nancrat,NanoCore",
            "malware_printable": "Nanocore RAT",
            "first_seen_utc": "2026-06-29 19:10:39",
            "last_seen_utc": null,
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": "0",
            "reporter": "Grim"
        }
    ],
    "1840119": [
        {
            "ioc_value": "f59b521321526c8e255c6e5a9ed71d063349cab55a4a0b7207c6aa0039fb32be",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "win.salatstealer",
            "malware_alias": null,
            "malware_printable": "SalatStealer",
            "first_seen_utc": "2026-06-29 19:10:38",
            "last_seen_utc": null,
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": "0",
            "reporter": "Grim"
        }
    ],
    "1840120": [
        {
            "ioc_value": "58be67baa9a3323e8f0554ff45147668d5abf8ba",
            "ioc_type": "sha1_hash",
            "threat_type": "payload",
            "malware": "win.salatstealer",
            "malware_alias": null,
            "malware_printable": "SalatStealer",
            "first_seen_utc": "2026-06-29 19:10:38",
            "last_seen_utc": null,
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": "0",
            "reporter": "Grim"
        }
    ],
    "1840121": [
        {
            "ioc_value": "5563f909b93845410a8014ddffa5adf6",
            "ioc_type": "md5_hash",
            "threat_type": "payload",
            "malware": "win.salatstealer",
            "malware_alias": null,
            "malware_printable": "SalatStealer",
            "first_seen_utc": "2026-06-29 19:10:38",
            "last_seen_utc": null,
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": "0",
            "reporter": "Grim"
        }
    ],
    "1840122": [
        {
            "ioc_value": "a834cec6b236453ee671c23326b60763880a47c93ccc595d6e566ec5f81ade88",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "win.njrat",
            "malware_alias": "Bladabindi,Lime-Worm",
            "malware_printable": "NjRAT",
            "first_seen_utc": "2026-06-29 19:10:38",
            "last_seen_utc": null,
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": "0",
            "reporter": "Grim"
        }
    ],
    "1840116": [
        {
            "ioc_value": "9977df7ffd04173d38e0aefe3d028052e164aaa69c1facfe63af55b473dd9e24",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "win.salatstealer",
            "malware_alias": null,
            "malware_printable": "SalatStealer",
            "first_seen_utc": "2026-06-29 19:10:37",
            "last_seen_utc": null,
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": "0",
            "reporter": "Grim"
        }
    ],
    "1840117": [
        {
            "ioc_value": "1ceb390d2b85599cc738bfadcdddceaa01083940",
            "ioc_type": "sha1_hash",
            "threat_type": "payload",
            "malware": "win.salatstealer",
            "malware_alias": null,
            "malware_printable": "SalatStealer",
            "first_seen_utc": "2026-06-29 19:10:37",
            "last_seen_utc": null,
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": "0",
            "reporter": "Grim"
        }
    ],
    "1840118": [
        {
            "ioc_value": "7f79817eb5e3579ce8957a42c31c65fa",
            "ioc_type": "md5_hash",
            "threat_type": "payload",
            "malware": "win.salatstealer",
            "malware_alias": null,
            "malware_printable": "SalatStealer",
            "first_seen_utc": "2026-06-29 19:10:37",
            "last_seen_utc": null,
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": "0",
            "reporter": "Grim"
        }
    ],
    "1840113": [
        {
            "ioc_value": "1086e2ec8e9274e1639f14084f27d3b47e606c37ccc2a1e4976db6633ef797d5",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "win.njrat",
            "malware_alias": "Bladabindi,Lime-Worm",
            "malware_printable": "NjRAT",
            "first_seen_utc": "2026-06-29 19:10:36",
            "last_seen_utc": null,
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": "0",
            "reporter": "Grim"
        }
    ],
    "1840114": [
        {
            "ioc_value": "5bc1696dec9c0d82be4ff8910a7ae7c217e9e40e",
            "ioc_type": "sha1_hash",
            "threat_type": "payload",
            "malware": "win.njrat",
            "malware_alias": "Bladabindi,Lime-Worm",
            "malware_printable": "NjRAT",
            "first_seen_utc": "2026-06-29 19:10:36",
            "last_seen_utc": null,
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": "0",
            "reporter": "Grim"
        }
    ],
    "1840115": [
        {
            "ioc_value": "2f61cb4b14e0cf839a4a823eceea88e9",
            "ioc_type": "md5_hash",
            "threat_type": "payload",
            "malware": "win.njrat",
            "malware_alias": "Bladabindi,Lime-Worm",
            "malware_printable": "NjRAT",
            "first_seen_utc": "2026-06-29 19:10:36",
            "last_seen_utc": null,
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": "0",
            "reporter": "Grim"
        }
    ],
    "1840109": [
        {
            "ioc_value": "b1341da78ca16f4d04cb56d05c63a821",
            "ioc_type": "md5_hash",
            "threat_type": "payload",
            "malware": "win.ave_maria",
            "malware_alias": "AVE_MARIA,AveMariaRAT,Warzone RAT,WarzoneRAT,avemaria",
            "malware_printable": "Ave Maria",
            "first_seen_utc": "2026-06-29 19:10:35",
            "last_seen_utc": null,
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": "0",
            "reporter": "Grim"
        }
    ],
    "1840110": [
        {
            "ioc_value": "31c37ff61aa322192236c9672f09e3d97b6e6e09c5019077df7d0567d4c0b48b",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "win.njrat",
            "malware_alias": "Bladabindi,Lime-Worm",
            "malware_printable": "NjRAT",
            "first_seen_utc": "2026-06-29 19:10:35",
            "last_seen_utc": null,
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": "0",
            "reporter": "Grim"
        }
    ],
    "1840111": [
        {
            "ioc_value": "33e85ae9412fa870e5d6de31502e7d48c64ce224",
            "ioc_type": "sha1_hash",
            "threat_type": "payload",
            "malware": "win.njrat",
            "malware_alias": "Bladabindi,Lime-Worm",
            "malware_printable": "NjRAT",
            "first_seen_utc": "2026-06-29 19:10:35",
            "last_seen_utc": null,
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": "0",
            "reporter": "Grim"
        }
    ],
    "1840112": [
        {
            "ioc_value": "744e1221f6467d0b7e73a10f52e6cd6c",
            "ioc_type": "md5_hash",
            "threat_type": "payload",
            "malware": "win.njrat",
            "malware_alias": "Bladabindi,Lime-Worm",
            "malware_printable": "NjRAT",
            "first_seen_utc": "2026-06-29 19:10:35",
            "last_seen_utc": null,
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": "0",
            "reporter": "Grim"
        }
    ],
    "1840106": [
        {
            "ioc_value": "14b7d8e98b8cd97f8f302bab2b4dea27",
            "ioc_type": "md5_hash",
            "threat_type": "payload",
            "malware": "win.ave_maria",
            "malware_alias": "AVE_MARIA,AveMariaRAT,Warzone RAT,WarzoneRAT,avemaria",
            "malware_printable": "Ave Maria",
            "first_seen_utc": "2026-06-29 19:10:34",
            "last_seen_utc": null,
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": "0",
            "reporter": "Grim"
        }
    ],
    "1840107": [
        {
            "ioc_value": "0911748a95f6a362d1ed8d6fcd1a7889167520cdd506522658d84a69c9a088ab",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "win.ave_maria",
            "malware_alias": "AVE_MARIA,AveMariaRAT,Warzone RAT,WarzoneRAT,avemaria",
            "malware_printable": "Ave Maria",
            "first_seen_utc": "2026-06-29 19:10:34",
            "last_seen_utc": null,
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": "0",
            "reporter": "Grim"
        }
    ],
    "1840108": [
        {
            "ioc_value": "2a43e2b7dea9979a803c300b5b9638f5d4ae2f64",
            "ioc_type": "sha1_hash",
            "threat_type": "payload",
            "malware": "win.ave_maria",
            "malware_alias": "AVE_MARIA,AveMariaRAT,Warzone RAT,WarzoneRAT,avemaria",
            "malware_printable": "Ave Maria",
            "first_seen_utc": "2026-06-29 19:10:34",
            "last_seen_utc": null,
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": "0",
            "reporter": "Grim"
        }
    ],
    "1840103": [
        {
            "ioc_value": "91ca6805aabe73cabd12644fccf91ec5",
            "ioc_type": "md5_hash",
            "threat_type": "payload",
            "malware": "win.valley_rat",
            "malware_alias": "Winos",
            "malware_printable": "ValleyRAT",
            "first_seen_utc": "2026-06-29 19:10:33",
            "last_seen_utc": null,
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": "0",
            "reporter": "Grim"
        }
    ],
    "1840104": [
        {
            "ioc_value": "83a2d5361b91b0ac26ff7c5f161dd3008de6922c5df7f8c0af80b1dea105480d",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "win.ave_maria",
            "malware_alias": "AVE_MARIA,AveMariaRAT,Warzone RAT,WarzoneRAT,avemaria",
            "malware_printable": "Ave Maria",
            "first_seen_utc": "2026-06-29 19:10:33",
            "last_seen_utc": null,
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": "0",
            "reporter": "Grim"
        }
    ],
    "1840105": [
        {
            "ioc_value": "af09bf91db9bb8dfaa56f1d2e3d4fab97e6fdf72",
            "ioc_type": "sha1_hash",
            "threat_type": "payload",
            "malware": "win.ave_maria",
            "malware_alias": "AVE_MARIA,AveMariaRAT,Warzone RAT,WarzoneRAT,avemaria",
            "malware_printable": "Ave Maria",
            "first_seen_utc": "2026-06-29 19:10:33",
            "last_seen_utc": null,
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": "0",
            "reporter": "Grim"
        }
    ],
    "1840100": [
        {
            "ioc_value": "4db7b73a3650b98b99aa282bf1e16cc1",
            "ioc_type": "md5_hash",
            "threat_type": "payload",
            "malware": "win.raton_rat",
            "malware_alias": null,
            "malware_printable": "RatonRAT",
            "first_seen_utc": "2026-06-29 19:10:32",
            "last_seen_utc": null,
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": "0",
            "reporter": "Grim"
        }
    ],
    "1840101": [
        {
            "ioc_value": "ab168b5a63520e7cabe5d2d3917e1b9b1b388db0b3f27354bc7cd075e63cc7dd",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "win.valley_rat",
            "malware_alias": "Winos",
            "malware_printable": "ValleyRAT",
            "first_seen_utc": "2026-06-29 19:10:32",
            "last_seen_utc": null,
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": "0",
            "reporter": "Grim"
        }
    ],
    "1840102": [
        {
            "ioc_value": "a29d766799b35f8c9a4fbc3950295aedc17c7e9a",
            "ioc_type": "sha1_hash",
            "threat_type": "payload",
            "malware": "win.valley_rat",
            "malware_alias": "Winos",
            "malware_printable": "ValleyRAT",
            "first_seen_utc": "2026-06-29 19:10:32",
            "last_seen_utc": null,
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": "0",
            "reporter": "Grim"
        }
    ],
    "1840098": [
        {
            "ioc_value": "16aa5e9cd33302fb4bba5f5fe61b9dcef4e6e1a777098985eca17e5a6f075234",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "win.raton_rat",
            "malware_alias": null,
            "malware_printable": "RatonRAT",
            "first_seen_utc": "2026-06-29 19:10:31",
            "last_seen_utc": null,
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": "0",
            "reporter": "Grim"
        }
    ],
    "1840099": [
        {
            "ioc_value": "3f762a0e0d991b182032fcf13cb94c75a61fe47b",
            "ioc_type": "sha1_hash",
            "threat_type": "payload",
            "malware": "win.raton_rat",
            "malware_alias": null,
            "malware_printable": "RatonRAT",
            "first_seen_utc": "2026-06-29 19:10:31",
            "last_seen_utc": null,
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": "0",
            "reporter": "Grim"
        }
    ],
    "1840096": [
        {
            "ioc_value": "45.196.233.245:50001",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.vshell",
            "malware_alias": null,
            "malware_printable": "VShell",
            "first_seen_utc": "2026-06-29 19:05:08",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "vshell",
            "anonymous": "1",
            "reporter": "_ik_"
        }
    ],
    "1840095": [
        {
            "ioc_value": "121.37.101.160:9999",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.vshell",
            "malware_alias": null,
            "malware_printable": "VShell",
            "first_seen_utc": "2026-06-29 19:05:07",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "vshell",
            "anonymous": "1",
            "reporter": "_ik_"
        }
    ],
    "1840094": [
        {
            "ioc_value": "104.251.181.73:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.havoc",
            "malware_alias": "Havokiz",
            "malware_printable": "Havoc",
            "first_seen_utc": "2026-06-29 19:05:06",
            "last_seen_utc": "2026-06-30 10:43:12",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "havoc",
            "anonymous": "1",
            "reporter": "_ik_"
        }
    ],
    "1840093": [
        {
            "ioc_value": "172.245.226.124:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-06-29 19:05:05",
            "last_seen_utc": "2026-06-30 10:46:52",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "cobaltstrike",
            "anonymous": "1",
            "reporter": "_ik_"
        }
    ],
    "1840092": [
        {
            "ioc_value": "r32rtlhu.1xbetpartnersiran.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 19:00:49",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "clearfake",
            "anonymous": "1",
            "reporter": "ttakvam"
        }
    ],
    "1840091": [
        {
            "ioc_value": "pageimagebook.info",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "unknown_loader",
            "malware_alias": null,
            "malware_printable": "Unknown Loader",
            "first_seen_utc": "2026-06-29 18:56:42",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": null,
            "anonymous": "1",
            "reporter": "michaelschrijver"
        }
    ],
    "1840090": [
        {
            "ioc_value": "81.177.49.127:24378",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.raton_rat",
            "malware_alias": null,
            "malware_printable": "RatonRAT",
            "first_seen_utc": "2026-06-29 18:45:21",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "RatonRAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1840089": [
        {
            "ioc_value": "134.122.128.106:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.valley_rat",
            "malware_alias": "Winos",
            "malware_printable": "ValleyRAT",
            "first_seen_utc": "2026-06-29 18:45:18",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "RAT,ValleyRAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1840088": [
        {
            "ioc_value": "217.60.195.56:5201",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.ave_maria",
            "malware_alias": "AVE_MARIA,AveMariaRAT,Warzone RAT,WarzoneRAT,avemaria",
            "malware_printable": "Ave Maria",
            "first_seen_utc": "2026-06-29 18:45:13",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "AveMariaRAT,RAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1840087": [
        {
            "ioc_value": "191.101.51.10:2404",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-06-29 18:45:10",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "RAT,RemcosRAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1840086": [
        {
            "ioc_value": "3.127.181.115:19587",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.njrat",
            "malware_alias": "Bladabindi,Lime-Worm",
            "malware_printable": "NjRAT",
            "first_seen_utc": "2026-06-29 18:45:07",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "NjRAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1840085": [
        {
            "ioc_value": "155.117.183.181:2017",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.njrat",
            "malware_alias": "Bladabindi,Lime-Worm",
            "malware_printable": "NjRAT",
            "first_seen_utc": "2026-06-29 18:45:03",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "NjRAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1840084": [
        {
            "ioc_value": "moderncloudprotection.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 18:33:31",
            "last_seen_utc": null,
            "confidence_level": 85,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,ErrTraffic,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1840083": [
        {
            "ioc_value": "publicwebprotection.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 18:33:30",
            "last_seen_utc": null,
            "confidence_level": 85,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,ErrTraffic,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1840082": [
        {
            "ioc_value": "superfirewallprotection.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 18:33:29",
            "last_seen_utc": null,
            "confidence_level": 85,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,ErrTraffic,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1840078": [
        {
            "ioc_value": "r4zhwkgz.betbuf.live",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 18:01:53",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "clearfake",
            "anonymous": "1",
            "reporter": "ttakvam"
        }
    ],
    "1840069": [
        {
            "ioc_value": "193.233.82.126:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 16:30:23",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1840068": [
        {
            "ioc_value": "zenithharbinger.digital",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 16:30:22",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1840067": [
        {
            "ioc_value": "radiantprospera.digital",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 16:30:21",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1840066": [
        {
            "ioc_value": "latticepatronage.digital",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 16:30:20",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1840065": [
        {
            "ioc_value": "covenantventure.digital",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 16:30:19",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1840064": [
        {
            "ioc_value": "apexharvestor.digital",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 16:30:18",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1840063": [
        {
            "ioc_value": "momentumbloomera.digital",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 16:30:17",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1840062": [
        {
            "ioc_value": "vectorprospera.digital",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 16:30:16",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1840061": [
        {
            "ioc_value": "nexuspatronage.digital",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 16:30:15",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1840060": [
        {
            "ioc_value": "quantumharbinger.digital",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 16:30:14",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1840059": [
        {
            "ioc_value": "paragonbloomera.digital",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 16:30:13",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1840058": [
        {
            "ioc_value": "amb1ing-farm.digital",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 16:30:12",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1840057": [
        {
            "ioc_value": "borschokf2dd.digital",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 16:30:11",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1840056": [
        {
            "ioc_value": "latat-long.digital",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 16:30:10",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1840055": [
        {
            "ioc_value": "plaque5tucco.digital",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 16:30:09",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1840054": [
        {
            "ioc_value": "ebensen-timent.digital",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 16:30:08",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1840053": [
        {
            "ioc_value": "chernichco5t.digital",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 16:30:06",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1840052": [
        {
            "ioc_value": "degassing-mould.digital",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 16:30:05",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1840051": [
        {
            "ioc_value": "souf1atwindow.digital",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 16:30:04",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1840050": [
        {
            "ioc_value": "betav2ryazhsky.digital",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 16:30:02",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1840049": [
        {
            "ioc_value": "seering5outh.digital",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 16:30:01",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1840048": [
        {
            "ioc_value": "archive-shlyah.digital",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 16:30:00",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1840047": [
        {
            "ioc_value": "acce1eratpacify.digital",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 16:29:59",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1840046": [
        {
            "ioc_value": "ass-ecuadorian.digital",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 16:29:58",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1840045": [
        {
            "ioc_value": "repu1sivebrazen.digital",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 16:29:57",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1840044": [
        {
            "ioc_value": "doha-neutral.digital",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 16:29:56",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1840043": [
        {
            "ioc_value": "izyob7rickets.digital",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 16:29:55",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1840042": [
        {
            "ioc_value": "shim-windless.digital",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 16:29:54",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1840041": [
        {
            "ioc_value": "solid5lowly.digital",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 16:29:53",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1840040": [
        {
            "ioc_value": "die-reformer.digital",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 16:29:52",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1840039": [
        {
            "ioc_value": "dunkpo1ytechnic.digital",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 16:29:51",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1840038": [
        {
            "ioc_value": "ethen0shypnotist.digital",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 16:29:50",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1840037": [
        {
            "ioc_value": "peddler-wasting.digital",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 16:29:49",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1840036": [
        {
            "ioc_value": "overreactuntr2ve.digital",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 16:29:48",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1840035": [
        {
            "ioc_value": "ama1gamb1ast.digital",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 16:29:47",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1840034": [
        {
            "ioc_value": "radio-legitdown.digital",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 16:29:46",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1840033": [
        {
            "ioc_value": "encryption5hadow.digital",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 16:29:45",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1840032": [
        {
            "ioc_value": "hor1inka-lonely.digital",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 16:29:44",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1840031": [
        {
            "ioc_value": "greyhounds1uidor.digital",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 16:29:43",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1840030": [
        {
            "ioc_value": "chronicle5-diachiha.digital",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 16:29:42",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1840029": [
        {
            "ioc_value": "unp2idvalk.digital",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 16:29:41",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1840028": [
        {
            "ioc_value": "estradaannivers.digital",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 16:29:40",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1840027": [
        {
            "ioc_value": "unseen-zorenka.digital",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 16:29:39",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1840026": [
        {
            "ioc_value": "carving-paral.digital",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 16:29:38",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1840025": [
        {
            "ioc_value": "exhaustoverwint.digital",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 16:29:37",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1840024": [
        {
            "ioc_value": "poles-wrinkle.digital",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 16:29:36",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1840023": [
        {
            "ioc_value": "chequecholeric.digital",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 16:29:35",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1840022": [
        {
            "ioc_value": "monotheism-sled.digital",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 16:29:34",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1840021": [
        {
            "ioc_value": "disorientbreak.digital",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 16:29:33",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1840020": [
        {
            "ioc_value": "estat-goldilock.digital",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 16:29:32",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1840019": [
        {
            "ioc_value": "after-diacritic.digital",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 16:29:31",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1840018": [
        {
            "ioc_value": "sue-intentioned.digital",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 16:29:30",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1840017": [
        {
            "ioc_value": "champag-mannered.digital",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 16:29:29",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1840016": [
        {
            "ioc_value": "limous-nitout.digital",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 16:29:28",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1840015": [
        {
            "ioc_value": "flos-strip.digital",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 16:29:27",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1840014": [
        {
            "ioc_value": "bitter-salty.digital",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 16:29:26",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1840013": [
        {
            "ioc_value": "ripples-shark.digital",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 16:29:25",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1840012": [
        {
            "ioc_value": "sniffingviableoffice.digital",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 16:29:24",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1840011": [
        {
            "ioc_value": "binary-dock.digital",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 16:29:23",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1840010": [
        {
            "ioc_value": "pashtuns-study-rose-hip.digital",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 16:29:22",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1840009": [
        {
            "ioc_value": "neural-routing.digital",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 16:29:21",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1840008": [
        {
            "ioc_value": "polestennisplayer.digital",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 16:29:20",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1840007": [
        {
            "ioc_value": "stack-forge.digital",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 16:29:19",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1840006": [
        {
            "ioc_value": "animalspintroll-xerography.digital",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 16:29:18",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1840005": [
        {
            "ioc_value": "packet-lattice.digital",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 16:29:17",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1840004": [
        {
            "ioc_value": "icewounded.digital",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 16:29:16",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1840003": [
        {
            "ioc_value": "runtime-atlas.digital",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 16:29:15",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1840002": [
        {
            "ioc_value": "khudrukrantingmanic.digital",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 16:29:14",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1840001": [
        {
            "ioc_value": "bellow-norushka-pianissimo.digital",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 16:29:13",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1840000": [
        {
            "ioc_value": "biennial-polovauniverse.digital",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 16:29:12",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839999": [
        {
            "ioc_value": "bibliosmirk.digital",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 16:29:11",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839998": [
        {
            "ioc_value": "steel-evar-yes-valence.digital",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 16:29:10",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839997": [
        {
            "ioc_value": "clamshellkarakulchaalumina.digital",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 16:29:09",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839996": [
        {
            "ioc_value": "downplaying-sevenleague.digital",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 16:29:08",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839995": [
        {
            "ioc_value": "hundred-years-old.digital",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 16:29:07",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839994": [
        {
            "ioc_value": "kabardinskymonasticismradicalism.digital",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 16:29:06",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839993": [
        {
            "ioc_value": "culling-posture-schnitzel.digital",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 16:29:05",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839992": [
        {
            "ioc_value": "signal-harbor.digital",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 16:29:04",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839991": [
        {
            "ioc_value": "kernel-lattice.digital",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 16:29:03",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839990": [
        {
            "ioc_value": "proxy-horizon.digital",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 16:29:01",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839989": [
        {
            "ioc_value": "byte-forge.digital",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 16:29:00",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839988": [
        {
            "ioc_value": "cloud-atlas.digital",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 16:28:59",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839987": [
        {
            "ioc_value": "script-vault.digital",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 16:28:58",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839986": [
        {
            "ioc_value": "network-pulse.digital",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 16:28:57",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839985": [
        {
            "ioc_value": "cyber-relay.digital",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 16:28:56",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839984": [
        {
            "ioc_value": "node-matrix.digital",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 16:28:55",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839983": [
        {
            "ioc_value": "logic-sphere.digital",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 16:28:54",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839982": [
        {
            "ioc_value": "cloud-forge.digital",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 16:28:53",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839981": [
        {
            "ioc_value": "script-matrix.digital",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 16:28:52",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839980": [
        {
            "ioc_value": "network-horizon.digital",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 16:28:51",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839979": [
        {
            "ioc_value": "cyber-lattice.digital",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 16:28:50",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839978": [
        {
            "ioc_value": "node-pulse.digital",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 16:28:49",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839977": [
        {
            "ioc_value": "container-vector.digital",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 16:28:48",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839976": [
        {
            "ioc_value": "script-horizon.digital",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 16:28:47",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839975": [
        {
            "ioc_value": "cloud-sphere.digital",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 16:28:46",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839974": [
        {
            "ioc_value": "runtime-forge.digital",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 16:28:45",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839973": [
        {
            "ioc_value": "telemetry-vault.digital",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 16:28:44",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839972": [
        {
            "ioc_value": "microservice-pulse.digital",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 16:28:43",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839971": [
        {
            "ioc_value": "network-harbor.digital",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 16:28:42",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839970": [
        {
            "ioc_value": "observability-matrix.digital",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 16:28:41",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839969": [
        {
            "ioc_value": "runtime-sphere.digital",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 16:28:40",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839968": [
        {
            "ioc_value": "packet-vector.digital",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 16:28:39",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839967": [
        {
            "ioc_value": "signal-vault.digital",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 16:28:38",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839966": [
        {
            "ioc_value": "network-forge.digital",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 16:28:37",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839965": [
        {
            "ioc_value": "byte-lattice.digital",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 16:28:36",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839964": [
        {
            "ioc_value": "cyber-harbor.digital",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 16:28:35",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839963": [
        {
            "ioc_value": "logic-pulse.digital",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 16:28:34",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839962": [
        {
            "ioc_value": "stack-matrix.digital",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 16:28:33",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839961": [
        {
            "ioc_value": "siciliandefensetheory.digital",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 16:28:32",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839960": [
        {
            "ioc_value": "audioattenuatorschematic.digital",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 16:28:31",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839959": [
        {
            "ioc_value": "badabingsopranoslounge.digital",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 16:28:30",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839958": [
        {
            "ioc_value": "orbitaldockingmodule.digital",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 16:28:29",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839957": [
        {
            "ioc_value": "crispychickencutlets.digital",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 16:28:28",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839956": [
        {
            "ioc_value": "subfossiloakchronology.digital",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 16:28:27",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839955": [
        {
            "ioc_value": "cyberneticprostheticlab.digital",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 16:28:26",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839954": [
        {
            "ioc_value": "magneticlevitationtrain.digital",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 16:28:25",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839953": [
        {
            "ioc_value": "gothiccathedralblueprint.digital",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 16:28:24",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839952": [
        {
            "ioc_value": "deepseahydrothermalvent.digital",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 16:28:23",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839951": [
        {
            "ioc_value": "holographicprojectiongrid.digital",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 16:28:22",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839950": [
        {
            "ioc_value": "stratosphericweatherballoon.digital",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 16:28:21",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839949": [
        {
            "ioc_value": "renaissancefrescorestoration.digital",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 16:28:20",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839948": [
        {
            "ioc_value": "subdermalbiometricchip.digital",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 16:28:19",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839947": [
        {
            "ioc_value": "primordialsoupevolution.digital",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 16:28:18",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839946": [
        {
            "ioc_value": "telemetry-orbit.digital",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 16:28:17",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839945": [
        {
            "ioc_value": "container-beacon.digital",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 16:28:16",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839944": [
        {
            "ioc_value": "runtime-nexus.digital",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 16:28:15",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839943": [
        {
            "ioc_value": "packet-cascade.digital",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 16:28:14",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839942": [
        {
            "ioc_value": "kernel-vertex.digital",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 16:28:13",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839941": [
        {
            "ioc_value": "signal-bridge.digital",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 16:28:12",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839940": [
        {
            "ioc_value": "cloud-meridian.digital",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 16:28:11",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839939": [
        {
            "ioc_value": "proxy-frontier.digital",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 16:28:10",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839938": [
        {
            "ioc_value": "network-foundry.digital",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 16:28:09",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839937": [
        {
            "ioc_value": "runtime-cascade.digital",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 16:28:08",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839936": [
        {
            "ioc_value": "packet-frontier.digital",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 16:28:07",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839935": [
        {
            "ioc_value": "kernel-beacon.digital",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 16:28:06",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839934": [
        {
            "ioc_value": "signal-meridian.digital",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 16:28:05",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839933": [
        {
            "ioc_value": "cloud-orbit.digital",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 16:28:04",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839932": [
        {
            "ioc_value": "proxy-compass.digital",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 16:28:03",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839931": [
        {
            "ioc_value": "telemetry-nexus.digital",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 16:28:02",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839930": [
        {
            "ioc_value": "container-bridge.digital",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 16:28:01",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839929": [
        {
            "ioc_value": "proxy-orbit.digital",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 16:28:00",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839928": [
        {
            "ioc_value": "stack-frontier.digital",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 16:27:59",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839927": [
        {
            "ioc_value": "telemetry-sphere.digital",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 16:27:58",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839926": [
        {
            "ioc_value": "system-forge.digital",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 16:27:57",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839925": [
        {
            "ioc_value": "stack-orbit.digital",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 16:27:56",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839924": [
        {
            "ioc_value": "script-nexus.digital",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 16:27:55",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839923": [
        {
            "ioc_value": "proxy-harbor.digital",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 16:27:54",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839922": [
        {
            "ioc_value": "network-vector.digital",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 16:27:53",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839921": [
        {
            "ioc_value": "microservice-compass.digital",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 16:27:52",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839920": [
        {
            "ioc_value": "logic-compass.digital",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 16:27:51",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839919": [
        {
            "ioc_value": "cloud-lattice.digital",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 16:27:50",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839918": [
        {
            "ioc_value": "byte-frontier.digital",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 16:27:49",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839917": [
        {
            "ioc_value": "container-pulse.digital",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 16:27:48",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839916": [
        {
            "ioc_value": "packet-orbit.digital",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 16:27:47",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839915": [
        {
            "ioc_value": "kernel-compass.digital",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 16:27:46",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839914": [
        {
            "ioc_value": "signal-frontier.digital",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 16:27:45",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839913": [
        {
            "ioc_value": "cloud-beacon.digital",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 16:27:44",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839912": [
        {
            "ioc_value": "proxy-cascade.digital",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 16:27:43",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839911": [
        {
            "ioc_value": "telemetry-harbor.digital",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 16:27:42",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839910": [
        {
            "ioc_value": "byte-foundry.digital",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 16:27:41",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839909": [
        {
            "ioc_value": "stack-sphere.digital",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 16:27:40",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839908": [
        {
            "ioc_value": "script-bridge.digital",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 16:27:39",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839907": [
        {
            "ioc_value": "system-horizon.digital",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 16:27:38",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839906": [
        {
            "ioc_value": "elbowfrisk.digital",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 16:27:37",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839905": [
        {
            "ioc_value": "karo7drix.digital",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 16:27:36",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839903": [
        {
            "ioc_value": "https://bom.psgiran.news/",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-06-29 16:25:47",
            "last_seen_utc": "2026-06-29 21:25:48",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "gw3n9,Vidar",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1839904": [
        {
            "ioc_value": "bom.psgiran.news",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-06-29 16:25:47",
            "last_seen_utc": "2026-06-29 21:25:48",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "gw3n9,Vidar",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1839901": [
        {
            "ioc_value": "https://bom.jangkarsm188.top/",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-06-29 16:25:35",
            "last_seen_utc": "2026-06-29 21:25:37",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "gw3n9,Vidar",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1839902": [
        {
            "ioc_value": "bom.jangkarsm188.top",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-06-29 16:25:35",
            "last_seen_utc": "2026-06-29 21:25:37",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "gw3n9,Vidar",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1839890": [
        {
            "ioc_value": "freeshareyourimage.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 16:02:30",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839889": [
        {
            "ioc_value": "freecatimages.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 16:02:28",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839888": [
        {
            "ioc_value": "placebetweenphotos.us",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 16:02:27",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839887": [
        {
            "ioc_value": "thedocumentsthe.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 16:02:26",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839886": [
        {
            "ioc_value": "openimagesworld.us",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 16:02:24",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839885": [
        {
            "ioc_value": "lovefreephotos.us",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 16:02:23",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839884": [
        {
            "ioc_value": "imageuploaderfree.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 16:02:22",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839883": [
        {
            "ioc_value": "e2becd3fbfd8a2bc16f517ddf3702bc03ce25718495e7e67ef8517d2d91be6f9",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 16:02:16",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839882": [
        {
            "ioc_value": "1a22a2b2b0118fbd8e607a1fd303e69fb61b95837372e57d508908de1a446195",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 16:02:15",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839881": [
        {
            "ioc_value": "e1f8ac8514b45b51abc91b135e4964290a8e6bb5fb4893535fce8da974a8da5b",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 16:02:14",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839880": [
        {
            "ioc_value": "2b3681feecfb6e9a9f762fbf0e0421d69f6bd66f925f4d79be39cde5616256d6",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 16:02:12",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839879": [
        {
            "ioc_value": "65822e4396d854529e895ce37a87c11f660b0f5fd826660a97e9d62b24e57082",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 16:02:11",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839878": [
        {
            "ioc_value": "8765c89afc71a53077f2221ddf68625d971f41e8446b4c2b2f8c0835910d7306",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 16:02:10",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839877": [
        {
            "ioc_value": "8a712dc3e7b657d198b7532dd8c7f117c882ed0ec3acc4fb5bcb62ccae9e450c",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 16:02:08",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839876": [
        {
            "ioc_value": "andopening.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 16:02:07",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839875": [
        {
            "ioc_value": "documentsphotos.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 16:02:06",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839874": [
        {
            "ioc_value": "76bf6dc77dd65a17f8525db19ed152117272bf777cd49d0284dbb398f90d945c",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 16:02:05",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,ErrTraffic,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839873": [
        {
            "ioc_value": "e3b293066d3fc76c2fb149af1492afce98e4bba9a699713b0d5e8ef2c558ac92",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 16:02:03",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,ErrTraffic,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839872": [
        {
            "ioc_value": "cdn.wp-station.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 16:01:58",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding,EtherHidingMagecart",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839871": [
        {
            "ioc_value": "api.wp-station.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 16:01:56",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding,EtherHidingMagecart",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839870": [
        {
            "ioc_value": "cloud.api-middle-connect.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 16:01:55",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding,EtherHidingMagecart",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839869": [
        {
            "ioc_value": "record-tracker.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 16:01:54",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding,EtherHidingMagecart",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839868": [
        {
            "ioc_value": "hilo-cdn.app",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 16:01:53",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding,EtherHidingMagecart",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839867": [
        {
            "ioc_value": "stats.wp-station.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 16:01:51",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding,EtherHidingMagecart",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839866": [
        {
            "ioc_value": "178.16.53.243:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 16:01:50",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding,EtherHidingMagecart",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839865": [
        {
            "ioc_value": "178.16.53.232:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 16:01:49",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding,EtherHidingMagecart",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839864": [
        {
            "ioc_value": "178.16.55.92:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 16:01:46",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding,EtherHidingMagecart",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839863": [
        {
            "ioc_value": "45.94.47.129:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 16:01:45",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding,EtherHidingMagecart",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839862": [
        {
            "ioc_value": "80049a2ef7ebc587d0a1b68cb51f79f710950670fc693f7f666233b2bb8c11a9",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 16:01:44",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding,EtherHidingMagecart",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839861": [
        {
            "ioc_value": "67af4ba680d2acadbc7c96852a296c515da5eb93095056b8028f5d16dc8271a0",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 16:01:42",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding,EtherHidingMagecart",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839860": [
        {
            "ioc_value": "103.141.13.26:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 16:01:41",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding,EtherHidingMagecart",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839859": [
        {
            "ioc_value": "e127aef41aaa4e0c28becb09df8415df35f7ca23724e07e2dbab0abb5f72fb85",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 16:01:40",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding,EtherHidingMagecart",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839858": [
        {
            "ioc_value": "54b57a524cb975f381dbc1dacccd77924d7ce331fe6b156c5b62419d86e7d18a",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 16:01:39",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding,EtherHidingMagecart",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839857": [
        {
            "ioc_value": "gushchina-kriz.digital",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 16:01:37",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839851": [
        {
            "ioc_value": "112.124.71.123:53",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-06-29 15:46:19",
            "last_seen_utc": "2026-06-30 10:46:34",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1839850": [
        {
            "ioc_value": "answers.microsofl.ip-ddns.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-06-29 15:46:07",
            "last_seen_utc": "2026-06-30 10:46:21",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1839849": [
        {
            "ioc_value": "113.30.189.164:54984",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.nanocore",
            "malware_alias": "Nancrat,NanoCore",
            "malware_printable": "Nanocore RAT",
            "first_seen_utc": "2026-06-29 15:35:03",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "NanoCore,RAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1839841": [
        {
            "ioc_value": "cportal.atlantascales.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "js.fakeupdates",
            "malware_alias": "FakeUpdate,GhoLoader,SocGholish",
            "malware_printable": "FAKEUPDATES",
            "first_seen_utc": "2026-06-29 15:17:17",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": "https://infosec.exchange/@monitorsg/116833792515156682",
            "tags": "SocGholish",
            "anonymous": "0",
            "reporter": "monitorsg"
        }
    ],
    "1839846": [
        {
            "ioc_value": "https://ghoster.com.br/vendas-ghoster/",
            "ioc_type": "url",
            "threat_type": "payload_delivery",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-06-29 15:17:16",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": "https://clickfix.carsonww.com/domains/ghoster.com.br",
            "tags": "ClickFix",
            "anonymous": "0",
            "reporter": "CarsonWilliams"
        }
    ],
    "1839847": [
        {
            "ioc_value": "hi4ztw3j.vip1xbet.org",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 15:01:04",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "clearfake",
            "anonymous": "1",
            "reporter": "ttakvam"
        }
    ],
    "1839845": [
        {
            "ioc_value": "c1d.psgiran.news",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-06-29 14:25:52",
            "last_seen_utc": "2026-06-29 15:25:50",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "gw3n9,Vidar",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1839844": [
        {
            "ioc_value": "https://c1d.psgiran.news/",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-06-29 14:25:51",
            "last_seen_utc": "2026-06-29 15:25:50",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "gw3n9,Vidar",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1839842": [
        {
            "ioc_value": "https://c1d.jangkarsm188.top/",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-06-29 14:25:39",
            "last_seen_utc": "2026-06-29 15:25:39",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "gw3n9,Vidar",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1839843": [
        {
            "ioc_value": "c1d.jangkarsm188.top",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-06-29 14:25:39",
            "last_seen_utc": "2026-06-29 15:25:39",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "gw3n9,Vidar",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1839840": [
        {
            "ioc_value": "107.174.221.13:14782",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.quasar_rat",
            "malware_alias": "CinaRAT,QuasarRAT,Yggdrasil",
            "malware_printable": "Quasar RAT",
            "first_seen_utc": "2026-06-29 14:05:05",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "quasarrat",
            "anonymous": "1",
            "reporter": "_ik_"
        }
    ],
    "1839251": [
        {
            "ioc_value": "https://bogisibh.xyz/api/v1/status",
            "ioc_type": "url",
            "threat_type": "payload_delivery",
            "malware": "js.kongtuke",
            "malware_alias": "TAG-124,js.LandUpdate808",
            "malware_printable": "KongTuke",
            "first_seen_utc": "2026-06-29 14:02:09",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": "https://infosec.exchange/@monitorsg/116833554053336427",
            "tags": "KongTuke",
            "anonymous": "0",
            "reporter": "monitorsg"
        }
    ],
    "1839252": [
        {
            "ioc_value": "https://synccert7665.com/update/package",
            "ioc_type": "url",
            "threat_type": "payload_delivery",
            "malware": "js.kongtuke",
            "malware_alias": "TAG-124,js.LandUpdate808",
            "malware_printable": "KongTuke",
            "first_seen_utc": "2026-06-29 14:02:09",
            "last_seen_utc": "2026-06-29 13:14:55",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": "https://infosec.exchange/@monitorsg/116833554053336427",
            "tags": "KongTuke",
            "anonymous": "0",
            "reporter": "monitorsg"
        }
    ],
    "1839253": [
        {
            "ioc_value": "synccert7665.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.kongtuke",
            "malware_alias": "TAG-124,js.LandUpdate808",
            "malware_printable": "KongTuke",
            "first_seen_utc": "2026-06-29 14:02:09",
            "last_seen_utc": "2026-06-29 13:14:53",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": "https://infosec.exchange/@monitorsg/116833554053336427",
            "tags": "KongTuke",
            "anonymous": "0",
            "reporter": "monitorsg"
        }
    ],
    "1839254": [
        {
            "ioc_value": "telehex1921.lol",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-06-29 14:02:08",
            "last_seen_utc": null,
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://www.virustotal.com/gui/file/aa14e0739cc231f5bbc34d22440d1600c72cfed1f1c1be6f7bef6f57a8deb05f",
            "tags": "ClickFix,DLL-sideload,FakeUpdate,Firefox,plugin-container",
            "anonymous": "0",
            "reporter": "Lenny3BO"
        }
    ],
    "1839255": [
        {
            "ioc_value": "opskey2005.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-06-29 14:02:08",
            "last_seen_utc": null,
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://www.virustotal.com/gui/file/aa14e0739cc231f5bbc34d22440d1600c72cfed1f1c1be6f7bef6f57a8deb05f",
            "tags": "ClickFix,DLL-sideload,FakeUpdate,Firefox,plugin-container",
            "anonymous": "0",
            "reporter": "Lenny3BO"
        }
    ],
    "1839256": [
        {
            "ioc_value": "datacrypt5840.top",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-06-29 14:02:07",
            "last_seen_utc": null,
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://www.virustotal.com/gui/file/aa14e0739cc231f5bbc34d22440d1600c72cfed1f1c1be6f7bef6f57a8deb05f",
            "tags": "ClickFix,DLL-sideload,FakeUpdate,Firefox,plugin-container",
            "anonymous": "0",
            "reporter": "Lenny3BO"
        }
    ],
    "1839258": [
        {
            "ioc_value": "aa14e0739cc231f5bbc34d22440d1600c72cfed1f1c1be6f7bef6f57a8deb05f",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-06-29 14:02:07",
            "last_seen_utc": null,
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://www.virustotal.com/gui/file/aa14e0739cc231f5bbc34d22440d1600c72cfed1f1c1be6f7bef6f57a8deb05f",
            "tags": "ClickFix,DLL-sideload,FakeUpdate,Firefox,plugin-container",
            "anonymous": "0",
            "reporter": "Lenny3BO"
        }
    ],
    "1839259": [
        {
            "ioc_value": "7cf705c6a891860f44ec7f8f6a1fa8b461be9fdae040c729720cfffc85cdffd9",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-06-29 14:02:06",
            "last_seen_utc": null,
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://www.virustotal.com/gui/file/aa14e0739cc231f5bbc34d22440d1600c72cfed1f1c1be6f7bef6f57a8deb05f",
            "tags": "ClickFix,DLL-sideload,FakeUpdate,Firefox,plugin-container",
            "anonymous": "0",
            "reporter": "Lenny3BO"
        }
    ],
    "1839260": [
        {
            "ioc_value": "72e532597a0255c83c41ea5d3b239027827ec9c24e4e6620dc49da6484f18b4a",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-06-29 14:02:06",
            "last_seen_utc": null,
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://www.virustotal.com/gui/file/aa14e0739cc231f5bbc34d22440d1600c72cfed1f1c1be6f7bef6f57a8deb05f",
            "tags": "ClickFix,DLL-sideload,FakeUpdate,Firefox,plugin-container",
            "anonymous": "0",
            "reporter": "Lenny3BO"
        }
    ],
    "1839261": [
        {
            "ioc_value": "d656d9afc72bb96781f831f619a88ccc7713cad6ea8e73572e07b9a2e8c4a16f",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-06-29 14:02:06",
            "last_seen_utc": null,
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://www.virustotal.com/gui/file/aa14e0739cc231f5bbc34d22440d1600c72cfed1f1c1be6f7bef6f57a8deb05f",
            "tags": "ClickFix,DLL-sideload,FakeUpdate,Firefox,plugin-container",
            "anonymous": "0",
            "reporter": "Lenny3BO"
        }
    ],
    "1839839": [
        {
            "ioc_value": "7ay17187.vip1xbet.net",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 13:57:59",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "clearfake",
            "anonymous": "1",
            "reporter": "ttakvam"
        }
    ],
    "1839838": [
        {
            "ioc_value": "8eb65c7e227d022ab55a5fcd0df2108cf63fcd1b0f223dae807fd91f4c07da63",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 13:51:24",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839837": [
        {
            "ioc_value": "57383f826f13db899c12e257b8b4fb331cb67665427ab89bfa512ff94b136a38",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 13:51:22",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839836": [
        {
            "ioc_value": "878b1280993dfd05177c1ddcb1db0d5dfaaeab3688ac008fae08dcbbdc9c6165",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 13:51:20",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839835": [
        {
            "ioc_value": "81b432422313fee435ad45d1d56fc2b82092b87a216930ff376711fae1c5c589",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 13:51:18",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839834": [
        {
            "ioc_value": "f0210f448c8f446a0553ebc96217b69204635ab9c8afd3dbad4551cd15b04ed6",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 13:51:17",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839833": [
        {
            "ioc_value": "124943f53d7e25e6b0d5fc5f0166887bd455928c197a83d7912ca836842b7a49",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 13:51:15",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839832": [
        {
            "ioc_value": "081ff763229d78c25ee98ad187721c67f90f7c21c179316ac15294bd306a9bf8",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 13:51:13",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839831": [
        {
            "ioc_value": "f2b25a2b02c06cfd322ab35e46aa996e093f60c6d4533ff1c9488a4fd4731bc2",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 13:51:11",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839830": [
        {
            "ioc_value": "4ab0c6d772182dd989d5f486b3786d9652e096f3a7de2fe9318ba91160a29e54",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 13:51:10",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839829": [
        {
            "ioc_value": "99dae889c2513af1184536be9113f9090156e005ec8f4e7d70fe85a2385d6b40",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 13:51:08",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839828": [
        {
            "ioc_value": "1xkade.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 13:51:06",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839827": [
        {
            "ioc_value": "2b7a158ba21d29ff705f007404100f4be18f57c8add18be4367274313a525702",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 13:51:04",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839826": [
        {
            "ioc_value": "dab38d21b56589329253f3945077257015c38f0a3be8d4b23dbec6614df4cd6b",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 13:51:02",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839825": [
        {
            "ioc_value": "a7c115fa0d7e766e8cca83357f820fbc30bacf87eb8e034e626745fbcbedf4dd",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 13:51:00",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839824": [
        {
            "ioc_value": "5ddcc0e2b411639e9f0b956207a0f79220a5d63a91f989a33dfdb5e84d054375",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 13:50:58",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839823": [
        {
            "ioc_value": "cbec366f46e2ada3a4ba03110a6bf07cd773758f9647d6177aa2b3a824725a40",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 13:50:57",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839822": [
        {
            "ioc_value": "cda3bad36970a93cf320e99fa8f79ebef44a9d363984caa8d3ade57302d685d8",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 13:50:55",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839821": [
        {
            "ioc_value": "c29c5524132d533b368fdb4ebf25005b8ba16c87f47ff43cc8ffcf3afd951ef0",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 13:50:53",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839820": [
        {
            "ioc_value": "d9521891b05f22fb738d33a351630174ce3612472585616b5a0d0339f5ef7bc9",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 13:50:51",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839819": [
        {
            "ioc_value": "cf5875da311ed8b387c1c2e1980ae092b8c626983b052f8209b3cfd7092f37f5",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 13:50:49",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839818": [
        {
            "ioc_value": "477d0034cb086f7f243a7d5dfa9cd3bc4b4897bbdbbf3579e57696b4a0367eea",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 13:50:48",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839817": [
        {
            "ioc_value": "1f8714501e5a305f0ac811fe072adab863121a505c58ba8f2063b80cc4c53fde",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 13:50:46",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839816": [
        {
            "ioc_value": "cb6136edadf2e978a6a7a824a04c4868c3d5388e5a6348af138ccf0ad65281cb",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 13:50:44",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839815": [
        {
            "ioc_value": "b4e82c910ee8b571485fed72ab6bcc2fac4bc56165486fe0da3548372c061722",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 13:50:43",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839814": [
        {
            "ioc_value": "7aba322a380e1677dd6d330776f68ee1c9fcd03bc95d441848ff24dfe9c6d724",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 13:50:41",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839813": [
        {
            "ioc_value": "81eb6e18c2b2ccdf7b0eca605398a98628627a9a97ac27a2868dd2b8cb930386",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 13:50:37",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839812": [
        {
            "ioc_value": "889e30fe3f83f5760f2ff19a077d59efaa07e9cf01cfe46dc94ce009f14d9eb0",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 13:50:36",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839811": [
        {
            "ioc_value": "b67a31e76c3574f6703a4113083de1a2f7fa3162ca7873510e7df4da1f78156f",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 13:50:34",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839810": [
        {
            "ioc_value": "5fda909ff3cef21c73af1756533f0a5a1fda0f0169b538dc9b8d34889ad926ed",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 13:50:32",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839809": [
        {
            "ioc_value": "a8e53406599d6e8c59847e3bc3170202c52eae122053d2fbb9c4233ab7f0d3ba",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 13:50:30",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839808": [
        {
            "ioc_value": "426ddfb1bb7b5f84c6676b9c796093585a9c0ad52d72cba56eae4cf47b10b742",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 13:50:29",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839807": [
        {
            "ioc_value": "b197a5e6403eea1910b4f50719ecdf58945e3a1c727dd81f3fc57a85ceb6f620",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 13:50:27",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839806": [
        {
            "ioc_value": "31a3401c2f9bfe8a85849d08036cc52458c8bce4e68655b981878017780e3bbf",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 13:50:25",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839805": [
        {
            "ioc_value": "9ffef12b7a1aa5844659994c2c3a83c9ab432e03f965ec8a19638516ed7e15e3",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 13:50:23",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839804": [
        {
            "ioc_value": "f9325158ffb4030c5afbc19c113fee7e6ce8b269a5a33abcf571c04887048e57",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 13:50:22",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839803": [
        {
            "ioc_value": "d4e920866a336e9210499e9f0a4c7e8d26deb886c1dba1cd6ae4614084d181ae",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 13:50:20",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839802": [
        {
            "ioc_value": "b3a3f1ee7ba473939b8c1d308e3b051a393c282a5ed4c2427cae3835c3f90f3a",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 13:50:18",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839801": [
        {
            "ioc_value": "a082217a6db8177fb320a99750f4540a671fe33f1b08d21cdd9e918f41bba8ac",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 13:50:16",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839800": [
        {
            "ioc_value": "92f9ed3459ca697bc70ecf6e9ed5432f508ff194c67a9a723d3f9791453b1c5b",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 13:50:15",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839799": [
        {
            "ioc_value": "5a724c4ec2981e29380eba58bf5aacda7dd7326117537759ed28779e326f7ea6",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 13:50:13",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839798": [
        {
            "ioc_value": "6bf6d1965b3a4ef77868cea0e1fa9a74454a5907e753bcfe67f7d7939f04febe",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 13:50:11",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839797": [
        {
            "ioc_value": "riverpoker.xyz",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 13:50:09",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839796": [
        {
            "ioc_value": "d8da9785a0e4843c2e4e0dc187392d4ad4ddf7a2f65ba88daf60bee76e416a07",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 13:50:07",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839795": [
        {
            "ioc_value": "fe72b8995c8837aef8e7e4302fe630f72f93748a7bf37838b7d261ab2cea6f03",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 13:50:06",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839794": [
        {
            "ioc_value": "791a41337602eecb913c8ebb0725f2f4f3dd2bad52bdd39c44a799ab3f6ae556",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 13:50:02",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839793": [
        {
            "ioc_value": "4347c748a3fe26288b92f165b5f1f8b62f42053db896331512916d1b813cf30a",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 13:50:00",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839792": [
        {
            "ioc_value": "42deaf9d9680d818a640958fbc33ce6ed2c75bea7293495e121a2287f3c16470",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 13:49:58",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839791": [
        {
            "ioc_value": "a11a262fa4c433630376c7bd6172482a37b87e2f9fefdd1c219acc9775195db7",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 13:49:57",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839790": [
        {
            "ioc_value": "09af99cc0116a5e64ccff2cf62e00423baca98b6a61ec4f5ffbf357ace24cdaa",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 13:49:55",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839789": [
        {
            "ioc_value": "shartcart.xyz",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 13:49:53",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839788": [
        {
            "ioc_value": "efc89c8ce4a47037d02203cec9f63cfcb55a85ea6ec724ac39a614a78c74e280",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 13:49:51",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839787": [
        {
            "ioc_value": "eea4226faa5385e43944513bc6c5e0aba5c5fe2233ab9ddc4db89dbed87139c3",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 13:49:50",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839786": [
        {
            "ioc_value": "d5184af6a18beba8da3c5679cb97627150e2289119a0813e5f038cea69d76aff",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 13:49:48",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839785": [
        {
            "ioc_value": "taktikbet.bio",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 13:49:46",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839784": [
        {
            "ioc_value": "f2e1a2e8fd3895de2116b985ee9e42adb083da7dcbe5618f3b94b9bdbdbc783c",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 13:49:44",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839783": [
        {
            "ioc_value": "tinyshart.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 13:49:43",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839782": [
        {
            "ioc_value": "520e384b23a7fdf452b5134da72dd74b7c7ea6bcb9099aae631f6b12930c85dc",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 13:49:41",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839781": [
        {
            "ioc_value": "a75ac0799920ebf7491b9268c702dca5d9747796a89cf351ad66d10a2d5b27a7",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 13:49:39",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839780": [
        {
            "ioc_value": "fa1238f691e56bcc0022608721faa7153c3d99b8b117701599d21fa42eed59fa",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 13:49:37",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839779": [
        {
            "ioc_value": "fae06d3527460702a36bf3f503c942a35cabd04ba78d144ad0347de1a06adedc",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 13:49:34",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839778": [
        {
            "ioc_value": "add88dcfc5ef426a51c348b69e2a7b7416499ed91f5a2344006e3fd537767fd7",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 13:49:32",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839777": [
        {
            "ioc_value": "cd2a2ee649f83c5e3c897edaa9827d0e2aa64ceacac65f4b1cc72fbe9062696a",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 13:49:30",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839776": [
        {
            "ioc_value": "05ce12e867f403ca55729c8c511fa0f8b881bb4700a2bda45b63ebb452592fed",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 13:49:29",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839775": [
        {
            "ioc_value": "f6a79304d223a2df752e32e51c8099e56d6867bbc092baaf8da823cf660e0870",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 13:49:27",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839774": [
        {
            "ioc_value": "a2df2915aa26a1e32aa60d9d2e38d9bc292e0c256c67521f5ab4917b5d7ad941",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 13:49:25",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839773": [
        {
            "ioc_value": "16fff1a5fc06424acc5a5b9e9cc07ed0321f48c4254ff367925c7f5de14e5d62",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 13:49:23",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839772": [
        {
            "ioc_value": "13bdaf4471806639e3fc8d650b8039f52e59de138e482a506b2ba8b9b39901b3",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 13:49:22",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839771": [
        {
            "ioc_value": "226e7b5c5172d05784cfa2ae145aed749d08ad2c76ccc2152f286fdb86698809",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 13:49:20",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839770": [
        {
            "ioc_value": "yekshart.net",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 13:49:18",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839769": [
        {
            "ioc_value": "bd5b89ca5457fcb0e67821d8b9a97c86cfdeb9af22d15d694b946bbdf52a5070",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 13:49:16",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839768": [
        {
            "ioc_value": "e4755a251e140ffb3a7405ff6d744b968fac98fd6b163b3575c17224275e9e76",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 13:49:14",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839767": [
        {
            "ioc_value": "014ae4a90dc0d2c605f82e928004ef5921eb3c8793d477011889730225c1527d",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 13:49:13",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839766": [
        {
            "ioc_value": "31f1300cd96515097d540e513e28ac2c581754a743301199f3d5e4a1231c1fa0",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 13:49:11",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839765": [
        {
            "ioc_value": "71eca2a2a4427c3dc110f3516d2e99e4a4af9f5e5394d3d52debd707110b1094",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 13:49:09",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839764": [
        {
            "ioc_value": "2435a4e8428a82a301a87197866ddfac9d2100d8f920f187a823c88ce806675e",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 13:49:07",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839763": [
        {
            "ioc_value": "c959e7a155d1da4bf450cfda3bd0f84bf8028bc5e14b60cb9a1753b9d8efe16d",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 13:49:06",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839762": [
        {
            "ioc_value": "96276d59f865049ec4c5cca4801a65fb85e233fe6625975625ab9a2fd41e8100",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 13:49:04",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839761": [
        {
            "ioc_value": "f17cab00a92cda8acdcc84847508a54585bc054a77bf7dee0b89598359a585ef",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 13:49:02",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839760": [
        {
            "ioc_value": "ace4dcfc2795a6ae19e927f9ef1a00d6780d517c1f0ef82ac11797eacf0ab185",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 13:48:59",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839759": [
        {
            "ioc_value": "a86e693136de83b7a64e00c29a487b23e30c4fcdacf676fe1a338c0b307807b0",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 13:48:58",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839758": [
        {
            "ioc_value": "05bd30504df9f0d7b523cb34a3edf6374a4642eb0531500950f0191e0c7df852",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 13:48:56",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839757": [
        {
            "ioc_value": "sabad724.bio",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 13:48:54",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839756": [
        {
            "ioc_value": "fc0893d0b60b943cd327acd6037538318d87208ba7626a2f42a05da7a7a218bf",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 13:48:53",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839755": [
        {
            "ioc_value": "313betios.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 13:48:51",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839754": [
        {
            "ioc_value": "c9181856c3fed45a7bb1808c3a2dfedc8345e306fb22ef106d202e706f643fb0",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 13:48:49",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839753": [
        {
            "ioc_value": "1xbetpartnersiran.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 13:48:47",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839752": [
        {
            "ioc_value": "310d42379ca3c51699740fa991473eebefe7aa5ceba515899bc7f0466e88e685",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 13:48:46",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839751": [
        {
            "ioc_value": "1xprobet.app",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 13:48:44",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839750": [
        {
            "ioc_value": "f0dd6c57946342bb6fc8827153e0895dba4b7922e842597afe009943067cf196",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 13:48:42",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839749": [
        {
            "ioc_value": "9c549c9f571c14f56d0fd2476060cc7c148a50c5da418c7faa9081b522621d83",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 13:48:40",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839748": [
        {
            "ioc_value": "6a949b52db2fb8d659a783b1e7c6d7c46b8664f5e5af76784f5dcda0c6e45832",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 13:48:38",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839747": [
        {
            "ioc_value": "f396b4c20c493feb3843abeb2b347ae7e320ee0f7ea03522fff1742f7437d8df",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 13:48:37",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839746": [
        {
            "ioc_value": "19cec3279b4819bd518fef23cb1a2af9ebce9247531611148f5ef0d106562939",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 13:48:35",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839745": [
        {
            "ioc_value": "313betiran.online",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 13:48:33",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839744": [
        {
            "ioc_value": "44317aaf2ac9a743b22b069690ea33d8e067b3277050d72448db7e465ab52bf7",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 13:48:31",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839743": [
        {
            "ioc_value": "611f175b6573a9d44f895dcef94bd9252aa332ebaf36e1ac5eb0ff179b997d74",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 13:48:30",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839742": [
        {
            "ioc_value": "e132bc63f9768a85ca4472e7b27280f26f387e8d2a7f0302555c34c8386cab8a",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 13:48:28",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839741": [
        {
            "ioc_value": "79246207c4dc41f58e28e6c5b104b4c644d2780d6fca5a6df9d2eeaa78a590f1",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 13:48:26",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839740": [
        {
            "ioc_value": "515933678082aff2b0196c0601f04473585b418c285e8b9e7040eb724b4f9aed",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 13:48:24",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839739": [
        {
            "ioc_value": "d5f73374aa77a2f99385d6cd68da2521b80d8c48e013aa63d6418b8ccb818120",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 13:48:23",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839738": [
        {
            "ioc_value": "315643e6029ae7a70b9a173526a184ffc8a66dcc111f3ffcebd5fd473026fc6e",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 13:48:21",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839737": [
        {
            "ioc_value": "412888487a94f8b94d87fd5fdc8932f6fde85f4157c53806a888a8b510f85c4b",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 13:48:19",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839736": [
        {
            "ioc_value": "betbuf.live",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 13:48:17",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839735": [
        {
            "ioc_value": "57b5ef46bdb6bc7cae68b719503e2de2cb9173712dc8f978850801fa6eca4ff0",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 13:48:15",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839734": [
        {
            "ioc_value": "d6f3516dd5b9c909a05ae87f7f7834d2d5db5e6d7e153974a8e1f1f725017e53",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 13:48:14",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839733": [
        {
            "ioc_value": "232fd2611fc1f46ad1b5a280c33f0fc306ff9b6d35e95260930bb27ec051e788",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 13:48:12",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839732": [
        {
            "ioc_value": "38b2e12d1560279206a17395fa9a1b38ef937e3383233f72b35dbaa8c06a46f3",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 13:48:10",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839731": [
        {
            "ioc_value": "3d4e22b0dc83b1888baaef20ba791e3174bd61acd88efac3c92e77c8269e9653",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 13:48:08",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839730": [
        {
            "ioc_value": "0692c83afd512df18332b22dbe14679de671d4c08d46a513a877b40873fe436c",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 13:48:07",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839729": [
        {
            "ioc_value": "96b8c4b86d79991b8f8a539bbbb3055181f7235f473e9074d01389da38b7207d",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 13:48:05",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839728": [
        {
            "ioc_value": "b2030c42ae9a930705cf98062ae00d5bd2e06db3b5fb7bbb0c0285fe248cfadb",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 13:48:02",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839727": [
        {
            "ioc_value": "1b04c028b90b247f783357a822c1aa63ff4a9ac12692fe483711fb5a06787e14",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 13:48:00",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839726": [
        {
            "ioc_value": "313betsingup.casino",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 13:47:59",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839725": [
        {
            "ioc_value": "6d35efea5fac72d6ee3433add8827f953dca37e1309e36ed46d0682e7a09c434",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 13:47:57",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839724": [
        {
            "ioc_value": "1xboropartners.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 13:47:55",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839723": [
        {
            "ioc_value": "9fd0961f180a2a6c0dcc447f89c97ea581debed2ea33c9ad56b5446690454df6",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 13:47:53",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839722": [
        {
            "ioc_value": "1xsignupbet.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 13:47:52",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839721": [
        {
            "ioc_value": "298ece3b3060cbae13808d96c74ac49bd844623e4a211bac9f4362a6502d2863",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 13:47:50",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839720": [
        {
            "ioc_value": "733cbd9fd76b7842be57912ceb2f77b55ef32fffb79d320c765dfdf2e0ab5184",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 13:47:48",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839719": [
        {
            "ioc_value": "64f5c1cdd6d6761faa86e205043d1f8d9200b9bc31b782fc3089797ebbb1df6b",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 13:47:46",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839718": [
        {
            "ioc_value": "113bac6449e7c49c736e8e8240771a0d76793e4cc52c1a37fdab1608c374ce19",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 13:47:45",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839717": [
        {
            "ioc_value": "abt90kade.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 13:47:43",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839716": [
        {
            "ioc_value": "f78ac0dab61c5f45a351be05cf728cfa0703798323c52879a7a4bc15406c54cb",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 13:47:41",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839715": [
        {
            "ioc_value": "22bahis-tr.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 13:47:39",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839714": [
        {
            "ioc_value": "f5c7f49eb7a2dc7acc76a941b058aac5a307cf6130c18e9ab20589aa1933f4ee",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 13:47:38",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839713": [
        {
            "ioc_value": "3cec1d52d95d9fb728928132fb4608ab469a3e71c497da1769325135caf0269c",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 13:47:36",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839712": [
        {
            "ioc_value": "9838f78d5ef2b226912f0c72a38d5863637f843d062f4a4d0acc2569ac40ebdc",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 13:47:34",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839711": [
        {
            "ioc_value": "9fb07537a7e16acb1ef4241240ee3f80aab3e2cd1f1cae9570d659f42ffc0cc9",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 13:47:32",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839710": [
        {
            "ioc_value": "cc80852da3ced9c67c0be54a3a06a991873e48a6443b6d2c482505ce81ad17e3",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 13:47:31",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839709": [
        {
            "ioc_value": "c712cb217003bcdc3d4087c350d28c66ecf90af49f5ad8e7203daba8a7e8e7b4",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 13:47:29",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839708": [
        {
            "ioc_value": "46f8f5a30da314d478e265e28da4419d5ef19adc670ccb7deb57d15bae9f21ab",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 13:47:27",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839707": [
        {
            "ioc_value": "1xdownload2023.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 13:47:25",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839706": [
        {
            "ioc_value": "4b4102a2e28805d12b572323bc37f5a05e6d36fc731a33a9f165350a6717d040",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 13:47:23",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839705": [
        {
            "ioc_value": "b9e4ad9faee52e8866ad1f38a425c1314fdc6f44c6f4665010f7dbe303da1ca8",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 13:47:22",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839704": [
        {
            "ioc_value": "f1409a92e6aa3b890f6372414d34e7e93e8120d9da83b5b0b58030b98729dd3d",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 13:47:20",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839703": [
        {
            "ioc_value": "1fdcdc0733dc0616ba21f2cf4a56fbde588d989cf71e26925dda48931c551f6c",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 13:47:18",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839702": [
        {
            "ioc_value": "50a171ac23bb575bb12840446683b7cc39400047875ad318aecb9d40036eea9e",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 13:47:17",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839701": [
        {
            "ioc_value": "a4b2e6b19516b1ff469e093656629cac8d0a47922a14e0e50a0cd6584ad76504",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 13:47:15",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839700": [
        {
            "ioc_value": "e9f3c930335311d0fe8e726b372fcf06e2538942a6fc6d88da9edc3faa59b7c9",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 13:47:13",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839699": [
        {
            "ioc_value": "5b0b45fea76ccd6900de05d162076b9c48b78f3297668ad65d3e3e92bda6c6fc",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 13:47:11",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839698": [
        {
            "ioc_value": "a6bc6bb72b3ed7e241031aac6f8130b68bf4702be130760a8c39c266b9fbdc52",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 13:47:10",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839697": [
        {
            "ioc_value": "ffa65efae452cbf4baa955789735895353f3268c87873f1334d764605a4cc499",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 13:47:08",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839696": [
        {
            "ioc_value": "bdf46c4dbe512fa0ae26bebe27a68bc933f511f9bd918cd7efcaf441821f155c",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 13:47:06",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839695": [
        {
            "ioc_value": "005d23162e74aaa950fa609b1eb8cc37d3f28396540182604730b930e61f914c",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 13:47:04",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839694": [
        {
            "ioc_value": "b4e4603cfb751ac2c595f129b0e28287a87889938f55fc94e0c297b0a4a005ed",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 13:47:01",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839693": [
        {
            "ioc_value": "19c80a7da57c32c9dcaae13c7f2a082b9722ecfe230fb152e10ea0537bd30567",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 13:46:59",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839692": [
        {
            "ioc_value": "a9e01df4d1039b5ecbb26149f7d331d3bf95aca4d7977ef0a9390aee3906b687",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 13:46:58",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839691": [
        {
            "ioc_value": "honarrang.online",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 13:46:56",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839690": [
        {
            "ioc_value": "6ab6757326c4cf67c5488eb1c7e90b34002030a1968e06f5d0a8f942c52fcbc2",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 13:46:54",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839689": [
        {
            "ioc_value": "24b584844e5c1fa20bf0a68517420e7162d3f7462833d6bd0a296750917dd507",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 13:46:52",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839688": [
        {
            "ioc_value": "1ae8f2f2fed85d8e68479f04cb0b9209e855792f87002b523651eadcd467ef23",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 13:46:50",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839687": [
        {
            "ioc_value": "1ab28c7288a670a34392f3652280e4167bff3bf5e316e5e355e5906a481b3c17",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 13:46:49",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839686": [
        {
            "ioc_value": "c0c575a5275d27a2fa47bc5f8ca081ed689dcd0b9a84f619a504ec682a990643",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 13:46:47",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839685": [
        {
            "ioc_value": "04fea1d0c45f6bcc408fbb7275cbe918ea498c1de7341ed0e79993c6ae51b0e3",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 13:46:45",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839684": [
        {
            "ioc_value": "4be1501792cb564f615240a1b4a649367e710fd78f494709a401b067ebec4fca",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 13:46:43",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839683": [
        {
            "ioc_value": "298f14d3cd6cc0fbe90e846e870391aa376ece9d212a969d6c702827185d08fd",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 13:46:41",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839682": [
        {
            "ioc_value": "ad0ea952e3c6a81a5471ef73eef47ae84accfacfda9868bcd4304f25d929f92e",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 13:46:39",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839681": [
        {
            "ioc_value": "9ccdaa742177212ebb29eb4ed68a901ecb35cfb24836dda942bbb59ef825bc1a",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 13:46:38",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839680": [
        {
            "ioc_value": "313betapk.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 13:46:36",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839679": [
        {
            "ioc_value": "690e7b24e0a9e110f34d848ef0fdea286145e19e709e77b5eeda50d50ace8408",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 13:46:34",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839678": [
        {
            "ioc_value": "347d0adf9d9085952c435e0014aa603c828bf1864d17038e1790fb0731b7c008",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 13:46:33",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839677": [
        {
            "ioc_value": "224d47f45d43fab7e1247f2ec457bd8cd5ecc9c9fd192c6fbfca2ac34141a40e",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 13:46:31",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839676": [
        {
            "ioc_value": "10f0eefe55ed04c78b95e36e4b83e49d19ef431d8fa27f7e9c62751e3767bda6",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 13:46:29",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839675": [
        {
            "ioc_value": "f1c1e4912ba8cba7cbbab68e2ea2d5bdbdcfd769a19ed420427d5187905b9312",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 13:46:27",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839674": [
        {
            "ioc_value": "29c1b45b863aecf87178805b62399f99629b8bc398b0cf2be4f245b9a15ecce8",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 13:46:26",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839673": [
        {
            "ioc_value": "1xdownloadbet.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 13:46:24",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839672": [
        {
            "ioc_value": "49cb71bf1e8cf8a7bec155b3c60897edd1cc74860a4ff955290aaaa56a30585a",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 13:46:22",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839671": [
        {
            "ioc_value": "ae29e79b641e6ad1a204d275d1233553bf7cf7ffacc5705b7779dfeff86da18b",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 13:46:20",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839670": [
        {
            "ioc_value": "8eec96aa05f75e86a6508e349ec2979c7ee4bcd55afaf2fa52b3e0175f385d79",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 13:46:19",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839669": [
        {
            "ioc_value": "8b603a8efac1630470cb8313b47289bd472e249a8f77b057c7ce4dec9787b14a",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 13:46:17",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839668": [
        {
            "ioc_value": "af8312bcc2d968c24ae8942be15d43421363aa326685370852468d7cd9a5a39b",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 13:46:15",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839667": [
        {
            "ioc_value": "2157a11050dd3813771aa70d090e16b02733f659b9d6d5ddce3ec2fe2b59c7e9",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 13:46:13",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839666": [
        {
            "ioc_value": "d226eb2de39a752bb8184350301b90b8f8ca992eca59fe29ebb3361c7084a05e",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 13:46:12",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839665": [
        {
            "ioc_value": "alobet.pro",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 13:46:10",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839664": [
        {
            "ioc_value": "6f70383fce624b1d23bbc2faacaa107f9ddb791a9636b9b552dc1fbafed1c588",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 13:46:08",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839663": [
        {
            "ioc_value": "37075e36950eaec07d207870fdb8e89ba6635222769f298d6a324de341cd0ccf",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 13:46:06",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839662": [
        {
            "ioc_value": "7edf28fd45f03213328265875e3d2c52b96e3a11c0e794b4d4c6d10f21be1249",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 13:46:05",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839661": [
        {
            "ioc_value": "603836c3723118b10c98962a2a1f2ffe2591dd50d0c6ddbf0109a70765c367a5",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 13:46:02",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839660": [
        {
            "ioc_value": "73cc918e200d1816f0fb0437f3d7c68c8d09296e942e3eab29c775b19c8667e6",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 13:46:00",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839659": [
        {
            "ioc_value": "5be4a77129c44dd8db0b12ce5ce97423a9420b85ecdeb1afb005a999aa8049a1",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 13:45:58",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839658": [
        {
            "ioc_value": "79ae4c51a7dc322598a9bdc428b04b0e649e82a5530308ca22fe920955227824",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 13:45:56",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839657": [
        {
            "ioc_value": "b187458423a6bcfb33ff615b47cabe42c2fd1408f77d4d70efef9eb936ecc72a",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 13:45:54",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839656": [
        {
            "ioc_value": "be5bf9fae90a88dcbc764ffddecb34bf0cbdfc9a90ab08f8666473b7f2214cba",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 13:45:53",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839655": [
        {
            "ioc_value": "2dc79e549f60bc02c43210823741ca69a9efb71b5a44243768f4f2452b669a68",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 13:45:51",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839654": [
        {
            "ioc_value": "bb9a388134d418a2e362f1cbe11fbe5545e17af925c43a2cf69779950cb6031b",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 13:45:49",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839653": [
        {
            "ioc_value": "2a7fb245ffdd65a62b4c29a5af8eb0e7df37b3fd1f39097905f863a237b296fe",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 13:45:47",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839652": [
        {
            "ioc_value": "2c42c449a84a7b23d3d91a5f7e382b1718ecb39d0d84cc8407b22d2464f67e2c",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 13:45:46",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839651": [
        {
            "ioc_value": "323d5ae5950450365e8d908e190d7d4ae4f08e9a420683fcaaa54fe50465c4cc",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 13:45:44",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839650": [
        {
            "ioc_value": "58a5edafe9913698b4deae999ad59df1b6191d6a622b7f3844a08fb537868101",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 13:45:42",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839649": [
        {
            "ioc_value": "c733f78c80d027d037c8ebc6f21117df63acab83897d2342a9c305f986d78aca",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 13:45:40",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839648": [
        {
            "ioc_value": "192d2ce20ca06398b5de1df16f94af68a27d89595c58e749c53c6dcadf63662c",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 13:45:39",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839647": [
        {
            "ioc_value": "86a28961d0301706c09ec74ccf9d4c15404a3adc9235306333577c147edb3afa",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 13:45:37",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839646": [
        {
            "ioc_value": "2fffe49dc379b3d525b69b792dabdced5d95a133da59c2e5d9db605c5f1e1cd8",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 13:45:35",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839645": [
        {
            "ioc_value": "ac56862ba982309ae1e4b46df7af4cb16364c55d2e2485a106631f1888aa5840",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 13:45:33",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839644": [
        {
            "ioc_value": "7e5ba27700f835afed4b04390f935e15bc9b7eef1979e28ba1e2118614132e34",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 13:45:32",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839643": [
        {
            "ioc_value": "98c084f01044b8174d6ace1f512da6a06933c4fdc6f858d32ce9b07279dc82a7",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 13:45:30",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839642": [
        {
            "ioc_value": "4d256667bb0ecaad1d2c6704598570301b8eb7694612487bd9ddc7f635f8b1b6",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 13:45:28",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839641": [
        {
            "ioc_value": "66e15854ca2d96814302477e2d596d96285c43de93514467e1c0e04b942844d7",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 13:45:26",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839640": [
        {
            "ioc_value": "342609843717ec79a3eb53a381ab0743c57c70e4e86a1ae20ec85008f6a5554b",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 13:45:25",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839639": [
        {
            "ioc_value": "e4bd493473fb2f71a83674b3d44865740657438ab22510f37121583f83225c5b",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 13:45:23",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839638": [
        {
            "ioc_value": "a55657bee94a9748f0c21e859e7371ed6e46aef296cd0e3d89f90ff8c79d553f",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 13:45:21",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839637": [
        {
            "ioc_value": "329a446d1cacfa1615f000937907d600ae4dff63e60d2b0f5b4809f0d56a9b7e",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 13:45:19",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839636": [
        {
            "ioc_value": "925d2ab18be0e8b3e85bb9968e5c999c32dbfeaec8faf617ccf2e619088ce63c",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 13:45:17",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839635": [
        {
            "ioc_value": "c1dc31974713b63ad513f65dcebf049333d280930493ee663181570b2182c7e5",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 13:45:16",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839634": [
        {
            "ioc_value": "2c5554fc01f652daad55bc308d077b8d49eccbdb9f0d4c2a0061ca1e08f96771",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 13:45:14",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839633": [
        {
            "ioc_value": "0e5d483b1173972ea86da6384547d600d7bae9e9204007b683fb45703f2ba9cb",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 13:45:12",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839632": [
        {
            "ioc_value": "8a51e06878717602cb4cc3982cb983922c2acd9f7b869125bf0e5dbe8c6b92d0",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 13:45:10",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839631": [
        {
            "ioc_value": "3b7756cdad3fc20f3d5273f5f4cec4404ab7f2c134252c2619cbf485c65a7dcc",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 13:45:08",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839630": [
        {
            "ioc_value": "e78ae391dbcc509d67031b8eacc8809027776c049a005d9d4a0ca6ae31f878f1",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 13:45:07",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839629": [
        {
            "ioc_value": "93fb152bb0c07db4463c881b4daf17bd5c007e2fe097f096297499253efa18f0",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 13:45:05",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839628": [
        {
            "ioc_value": "e79b655671ec492d625e66f1537dceb45a4ef7d2517c58af2e16ad3b224d099e",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 13:45:02",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839627": [
        {
            "ioc_value": "095aeb362e5b8fe2c095b47cedfeab7fbea9bb866dc759aa5bcb44bc9123b49a",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 13:45:00",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839626": [
        {
            "ioc_value": "0bcf5f10b1d7a7db764b3b562bad683e2d5e6e863e63a6766b62569a3e4d16bf",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 13:44:58",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839625": [
        {
            "ioc_value": "84a62ab8aa23344c15ed50c3e6d78886f54dc1c4ab001374963ad6f92f02ed0b",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 13:44:56",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839624": [
        {
            "ioc_value": "1de1be23bb05a54e155a141e898a0c8aaf09cbc1285c5e6a71c10b058ac3acf6",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 13:44:54",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839623": [
        {
            "ioc_value": "08de7eacd549a59b6d3d7afbe40064ad981cfedf192fb850178570c945b6f238",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 13:44:53",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839622": [
        {
            "ioc_value": "bd8ec086cc4df4a53fbd41c4490656f962cf4b41d88a4a54539cb166fd06a625",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 13:44:51",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839621": [
        {
            "ioc_value": "0c6478d0fd592b465f98d1887a671b80fcaad145357d1bc698b827424bd2ccae",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 13:44:49",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839620": [
        {
            "ioc_value": "b0ae4e445adc5c3a1e3c987dba4948bc4651efd45b517f9fbdc8a9f65dbd1522",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 13:44:47",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839619": [
        {
            "ioc_value": "685828afaffa37efe8aabb8f09222c33a5325d73d8ba8e1ceb4761e94dfce105",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 13:44:46",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839618": [
        {
            "ioc_value": "1281bbddcebead31850b639a69496a410c6fe32aa3a3de73ba4c7a4ff87013db",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 13:44:44",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839617": [
        {
            "ioc_value": "3aa3df054514f530fee7bb78a012ce6a02c2bef45e988424fba534b9408c8d05",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 13:44:42",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839616": [
        {
            "ioc_value": "790f77de5c970f22a373fc1fc3a9c492229fc9ede18225d0dbc4740643b2864f",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 13:44:40",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839615": [
        {
            "ioc_value": "persiana.bet",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 13:44:39",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839614": [
        {
            "ioc_value": "cc7eb9c8d37e29497ae2c4faff7ac9ac2f0a491ea5499bd0d3eac675de529ab5",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 13:44:37",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839613": [
        {
            "ioc_value": "28b9b79d18af17fc53d21c0c58bf41bd6697f044d7c0dcf806e00a19ae7d7da2",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 13:44:35",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839612": [
        {
            "ioc_value": "0afce4a5acf139726bf479dcc41877b4fcd4138b9f395bdc70b219ba81983311",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 13:44:33",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839611": [
        {
            "ioc_value": "445dd498114c523c0b6a1d69f9860ea64a0a01f381e6935d071e1088609e8c30",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 13:44:32",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839610": [
        {
            "ioc_value": "41af7b9c1d3b467cda30cb48c6a37cf6805894aa18ec30b5f80000e1b8f9714c",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 13:44:30",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839609": [
        {
            "ioc_value": "14f689c52602325c71ec5d13eaf29a890f4f1cf86a95eb8fec0cae1af91d5e2e",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 13:44:28",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839608": [
        {
            "ioc_value": "226abb00d0d942c40b12022d86b1f73b81756fd9f9588b436ac5a87b428211df",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 13:44:26",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839607": [
        {
            "ioc_value": "08f440ee1659991acee984e6a266d53cfc56a409d030bf99b58ea54b268fb8e3",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 13:44:25",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839606": [
        {
            "ioc_value": "34061315cdb26d64d2eb58b85adbf72ebc535fe217739738af27f5bddb612483",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 13:44:23",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839605": [
        {
            "ioc_value": "ffbd3d22a61a837418d3065686d401f439f31a00a5d57b24cf9de86c3b44caf2",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 13:44:21",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839604": [
        {
            "ioc_value": "a3ef4bb67f92383fd6573d950c0da828992ae081ffe78d15b978575aab3b59e8",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 13:44:19",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839603": [
        {
            "ioc_value": "3fcee4743da0b69f5d036a545cbe2f89bf5666949b9ad667ffe29dc48a0e3d9e",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 13:44:18",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839602": [
        {
            "ioc_value": "da4944e4384d42da5fe60a527d530380248f0a64e3f13d185e262a130e08ee9a",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 13:44:16",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839601": [
        {
            "ioc_value": "119819df010ab85678ee4b98e6e072d2d89bc1694ce6a44da05ac8a263ba8242",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 13:44:14",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839600": [
        {
            "ioc_value": "7f549f9ced4340acd00c91af78f5ad8f18a31a401bc3605705468aabb5830389",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 13:44:12",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839599": [
        {
            "ioc_value": "b47d96527c1a0093553b19e86689c4d00d016dfb745e8a6bf473c4a6d2c142f9",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 13:44:11",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839598": [
        {
            "ioc_value": "318334eb727c1e2dc3b55e375a02c3dab34623b00da0599a3fec5a23d33d1eb7",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 13:44:09",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839597": [
        {
            "ioc_value": "34599e347fe26274530c72837dde3e0863f4580183c810ede147451c2ce09296",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 13:44:07",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839596": [
        {
            "ioc_value": "5bf1e723ddb4b40a06f219c54744e320203470552d3dff10faf5cad5b5bd0594",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 13:44:05",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839595": [
        {
            "ioc_value": "b5ec3792db03894b0d53b5b622d65b240f91e9719be10e26e2ae54e4787c7b35",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 13:44:04",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839594": [
        {
            "ioc_value": "e6eb81ceffe4d2da7f5abb14935949a8a8fb532d728bde9a0619d4844c1379df",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 13:44:01",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839593": [
        {
            "ioc_value": "af407cdca6cca6f89eb724570043c397e7e80f571bae1a9ffdcafb96581bf184",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 13:43:59",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839592": [
        {
            "ioc_value": "841fa9387b613794a777a69ca981a68cc7e6759e75413d39b0efae1650bfd765",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 13:43:58",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839591": [
        {
            "ioc_value": "4daff2f890ba8ee9f81acb6990cc8176eaf13c9837dc19ca91022e8d2b0430d9",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 13:43:56",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839590": [
        {
            "ioc_value": "4df6389bca569490a69b1767f6fea270aa75f5fd228c3df57c5671709957f61c",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 13:43:54",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839589": [
        {
            "ioc_value": "f1fdd609cd195d741589de152285f3e0d8ff3ae2e8a3b347613816f3972fce5e",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 13:43:52",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839588": [
        {
            "ioc_value": "809600841a77234d48f4673c3d1483e71181ca6211e28d74d000204830753b9f",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 13:43:50",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839587": [
        {
            "ioc_value": "5b109aed6bd06b368dc575b29d5521bbcb32da942677ba4454704a941dc362fa",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 13:43:49",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839586": [
        {
            "ioc_value": "6e9a1942ff912a8d8a01b498f5365e06d1e64379d900b0f6f0a5a589ece76746",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 13:43:47",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839585": [
        {
            "ioc_value": "perspolis.pro",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 13:43:45",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839584": [
        {
            "ioc_value": "68436ac984740ab03ff5f0c198d3622150fec050989c54df036190a7a4349d05",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 13:43:43",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839583": [
        {
            "ioc_value": "b0e405b7969d79c95e85cdbf48ec8db4bfe5222b3d6ef116777c14d0524bbc76",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 13:43:42",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839582": [
        {
            "ioc_value": "1xdlbet.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 13:43:40",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839581": [
        {
            "ioc_value": "26e27313a713e26b71566d81e8b506831bb35cdf6901a7884b1078daaaad256e",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 13:43:38",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839580": [
        {
            "ioc_value": "90be7b9a7efaee3ee835fa37fcc7e26cecf316a0f0d03cf5f96cd85c6b81530d",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 13:43:36",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839579": [
        {
            "ioc_value": "60b0adc84b36b5370ca63eb7101bd2d342b1dfada35903ca1efc563d9640afa5",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 13:43:34",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839578": [
        {
            "ioc_value": "12a625b3b98a1ae59b3fa7dddbcd2fdb489dd5f1876f21bb69642f13cd1c6d19",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 13:43:33",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839577": [
        {
            "ioc_value": "027c4491da7279ef0c28f0e7b5bf4c103a2df1a3eab895ab3f46617fe2d7f396",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 13:43:31",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839576": [
        {
            "ioc_value": "6d31d8c7017bc3fc7b8589e03e90effcd5a9b64950a2ea6c2eaebdfcbc5087bb",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 13:43:29",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839575": [
        {
            "ioc_value": "31784b99a423d7d1c292bb673ff136f62125f030ad1887127ed06a0080b69eac",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 13:43:27",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839574": [
        {
            "ioc_value": "c00335daffc6d8dda56d6dafe6551d1f7ca26afa8f929c24db9d0431b81218a6",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 13:43:26",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839573": [
        {
            "ioc_value": "af8127cc83b6b7da5ae28ad3eea96174200edfcc5aa45b2ab7925187dac2d36a",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 13:43:24",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839572": [
        {
            "ioc_value": "d43205e1ca5f39e2d38d02ba0b222a0d20411626fee0590459a346c67c119dd7",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 13:43:22",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839571": [
        {
            "ioc_value": "8de1757b00b31e1c26229768be740f3e9493145261245b057ee98229970faa75",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 13:43:20",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839570": [
        {
            "ioc_value": "b07d7eaef7316e9866faa602c360c46c6cfdc3cbee145de77fbcacd63f640214",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 13:43:19",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839569": [
        {
            "ioc_value": "42e4659714519f1f7a12695b5f7df203440bb08954f5f6f84bb1491cdf74e4f9",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 13:43:17",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839568": [
        {
            "ioc_value": "a5fb0f40715d9c4524d9c1c334719e36668ac48bb9ad8be8f503e1a6f1f04d7c",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 13:43:15",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839567": [
        {
            "ioc_value": "9c4e285c0e35294e5f1336cdf48104e505b960bcf99532992cb54f8f5ca2c5f9",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 13:43:13",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839566": [
        {
            "ioc_value": "48ca7d574ff68e03deea2a4858dd7b1ca66779fdca1f454054efcd31787f7937",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 13:43:12",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839565": [
        {
            "ioc_value": "b6bc8273370510fffea71ae09b9f560de201c6aeb28c4ed654ddc3757795f5fe",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 13:43:10",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839564": [
        {
            "ioc_value": "f4d64d73113d5ec2bbacaa6e2c0ccd8ede0a1ff7edf82724b654d367d7c32695",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 13:43:08",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839563": [
        {
            "ioc_value": "8f0bb1285c7e74d5cf735ea3e1b81f19af7bb66ce0fbc20ef0ee3d0cc2af81eb",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 13:43:06",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839562": [
        {
            "ioc_value": "b24acb0323702ab6211d419f31461b439ee26bdc0e30f25ccda2c8fd0f9b0d77",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 13:43:05",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839561": [
        {
            "ioc_value": "8c9c44d251459cdd066bea683a01af4633eec6c86e719172045e72dd2614fe02",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 13:43:02",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839560": [
        {
            "ioc_value": "bbf309009e1fb66866589176949d9e6a3c6ba13d6e6727f91c255730bcd1f7cb",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 13:43:00",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839559": [
        {
            "ioc_value": "2b639ad209bc9363dbce8cd57dd6270c65740ca44375a8571b91de09e165a765",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 13:42:58",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839558": [
        {
            "ioc_value": "3247c537d03122555bd73b70ef56fd898064a87231ae5f9a3abb8dd83984225d",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 13:42:56",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839557": [
        {
            "ioc_value": "de3ad35d58bce028653189234464f208af3eab813c00d2239dbd3e4aaee04823",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 13:42:55",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839556": [
        {
            "ioc_value": "c04f175ff36ec2876115428b24a12163c6a217dcabb53b5323cc8c02b7f0782e",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 13:42:53",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839555": [
        {
            "ioc_value": "fe3278cc70a425a9828203206901d669263714b22bce0c64462a044b2426ed7b",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 13:42:51",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839554": [
        {
            "ioc_value": "61ac3e1e2c1a0454b798ed0fbc828b546423a8dc9fbc8237de82372b5381da5a",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 13:42:49",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839553": [
        {
            "ioc_value": "0ca79a99e57a7e4a45d489d679cc36e5e8771eb5a5af52fb1353b827ffc224c4",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 13:42:48",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839552": [
        {
            "ioc_value": "1d092d05264c92d0a9b1eae7150c074ff71fe3a463476efcfa1c60276829865e",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 13:42:46",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839551": [
        {
            "ioc_value": "4e3cc984819d56ad857cc4f93d86057a639f812aa20d48451c31c0b6894eb62b",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 13:42:44",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839550": [
        {
            "ioc_value": "95970cdc48e9404ecb9b3a0368b1f31e047bb586b31086d8e45baeccd84febca",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 13:42:42",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839549": [
        {
            "ioc_value": "78b97b069a00375c63a70cb9954578c3cf9bc3f6f139094bb45054a350392d73",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 13:42:41",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839548": [
        {
            "ioc_value": "0a47701df259fdd10cfc0135819223158ce2b69f8e96c168576067fa2bff6448",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 13:42:39",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839547": [
        {
            "ioc_value": "fab3dfd516c69911e1695772c47a4affd6c199a9de8755ecf58f4cd268853e0f",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 13:42:37",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839546": [
        {
            "ioc_value": "a70a678ea4e494560339a21c449334fbb66860de6edd144bc4901b44b1bf4b4c",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 13:42:35",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839545": [
        {
            "ioc_value": "37d2aba18a98d7fb8b871286632d5ed14df199ff5a9aa8f1fb0494060c41cd45",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 13:42:34",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839544": [
        {
            "ioc_value": "1d5f9df365648f47db3db692f3bceb69abf534da058d88dbf7108d7ad45f12a5",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 13:42:32",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839543": [
        {
            "ioc_value": "8f4aaee9a0badd34cfde16ccbb6c31ef7bef714ddb8867e620e760f721b7e2a9",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 13:42:30",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839542": [
        {
            "ioc_value": "4c77c9f363c981a01a4f158b734bd4b7a0f560e1fefbaf79b9118ded34cc85ff",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 13:42:28",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839541": [
        {
            "ioc_value": "838e73a12345f9238ed8028213ed1a066e66a44518f76629bfbd47cf62047dab",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 13:42:26",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839540": [
        {
            "ioc_value": "f3cf50681b9a2c9c52aa149e0f4a8480c51f55e1a33894e3197b8f97b68b9eb7",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 13:42:25",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839539": [
        {
            "ioc_value": "66406130c77059a3ec991a0d4589a9a012647441f960393709d8f5b4e713d504",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 13:42:23",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839538": [
        {
            "ioc_value": "bee512e41ca7059ea138ccfd935821c50268dd46dd068fbdb43d9391149d2010",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 13:42:21",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839537": [
        {
            "ioc_value": "1f1e9e894034cc42e5763302c29651009b60b6fc6264ed3417164d70b8f001ca",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 13:42:19",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839536": [
        {
            "ioc_value": "fb8d0e1a1cff22efe0bf453262120ca73fc163e1e7e0b00b29f8c8b2da66799a",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 13:42:17",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839535": [
        {
            "ioc_value": "71a699c8f9baf9f3edc0552449ef67e75d24945c7f927d9e4160daaad5e3e2d1",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 13:42:16",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839534": [
        {
            "ioc_value": "6115e0c365f3cc55930a66072e94652288d9b7ea1e43058dcd9d59c154fe070c",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 13:42:14",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839533": [
        {
            "ioc_value": "baea8fc383ea6a60053c5f3e818c8b2cebfca06620c50f77395aff119606163d",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 13:42:12",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839532": [
        {
            "ioc_value": "f995250dae5d395a2773c89f45811438a7ddeef81bfc507cc27efd9b2f9747cc",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 13:42:10",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839531": [
        {
            "ioc_value": "25ff351860f87bc46f51b057cc477e5c9b3ccffffe580722503c31d909a0928d",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 13:42:09",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839530": [
        {
            "ioc_value": "fcbca46952dfcaa8e2168c9af88c63868485e0fcb1268eba50ca525a60a324f6",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 13:42:07",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839529": [
        {
            "ioc_value": "5689cf5549ee44dd64ff1a5cb5ec991f5969faf9da3e296071e888963d1bfa61",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 13:42:05",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839528": [
        {
            "ioc_value": "b1fc61b373e74d936f76dc0094b6be9b8acb25bbf4e44a9beadbd730d237c703",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 13:42:02",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839527": [
        {
            "ioc_value": "70e3b0ee50ef4c2fd7fa66e7ec4804d675f160066e252c9aeafc65815aedb222",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 13:42:00",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839526": [
        {
            "ioc_value": "00714edd01306c6528d6d31e9aaf3b9ae0e7ef23102d99e892c705d49da260ea",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 13:41:58",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839525": [
        {
            "ioc_value": "a51f8c071270354e6aee544de2ad3dd8dcc3fc4424226d5599e00916ad81be99",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 13:41:57",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839524": [
        {
            "ioc_value": "6d8bfcffcb19e21cefda5f1a79fa332e4273cb0282f7741e69707c809b8396de",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 13:41:55",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839523": [
        {
            "ioc_value": "324d7d52c708c0b6b1f45a19b4c1a42d6e6affb79053c8ab9470454ee3ad4296",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 13:41:53",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839522": [
        {
            "ioc_value": "e947300b142e4a3ad1a4a9879a4b835277bce783ca3176e9b42b0cd46a035557",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 13:41:52",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839521": [
        {
            "ioc_value": "65c64c33f378b0e81a073cf918b1b72a3e6259f811aec8d5cd007171a15ccf78",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 13:41:50",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839520": [
        {
            "ioc_value": "6264a5ea18a9e322091f97896f45f3da6d5ca8a788e01d3c74d12ef524361744",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 13:41:48",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839519": [
        {
            "ioc_value": "da180ca961b9acc2dccbfccb68f0bd5acddd2658fb77bd1495b826c71a5a12df",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 13:41:46",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839518": [
        {
            "ioc_value": "8186041eef61d4e4fe4816aec2176399ed26242bd171c9792ef009f2f3a19460",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 13:41:45",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839517": [
        {
            "ioc_value": "9e1a0efff2255bc8f7935374b962147c30b2ceffb25ec7211886ac375778e872",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 13:41:43",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839516": [
        {
            "ioc_value": "7ac1baedbfedac58a53fa8f0797fa5fda1569dfa3ac892076d53ced667ec0006",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 13:41:41",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839515": [
        {
            "ioc_value": "78d0a38af1400fe5420e13b7a19bf1fc4e8e89f81a786b339132cdd10780676e",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 13:41:39",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839514": [
        {
            "ioc_value": "34f190408932922582014839d495222b25a96c54bbf761429ee2dfbd96f7884b",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 13:41:38",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839513": [
        {
            "ioc_value": "b4d92af2eaf8e863909cb1224048987406ebb850f88b9db1d19e2ab2ec63bd36",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 13:41:36",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839512": [
        {
            "ioc_value": "7388844112b97c2915f15a2b52ea169fce9d42dfa9b77235060328a6bf9aff65",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 13:41:34",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839511": [
        {
            "ioc_value": "42f3770fe595e84b5c5ef2ae07fd1ca822678d1fe65c2cae6cb345ba8db86b48",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 13:41:32",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839510": [
        {
            "ioc_value": "cc429884cb3742aae383942530592ef8a4964e484f51d9467f7b8ec8352ab4f4",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 13:41:31",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839509": [
        {
            "ioc_value": "0116d85f1d356ede1353a834d543b0b72bdadc557e475292cc146b4b2dc1ba75",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 13:41:29",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839508": [
        {
            "ioc_value": "2a6528347432f410bf4a961fbb50571b65f5998e6390ee38eaa8960830fc6f82",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 13:41:27",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839507": [
        {
            "ioc_value": "e7d14cfd4f8b45cad80901f57d582c2841df729847cb794ea465e6ba34efe999",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 13:41:25",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839506": [
        {
            "ioc_value": "13f925f0219f5309f49dc851ec39c26565f89b5405fda42c2ee142b0f1048d4b",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 13:41:24",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839505": [
        {
            "ioc_value": "48eb97efd3e3e211b425292e939e99a1d06d142cb9a53b13065641ff92431118",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 13:41:22",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839504": [
        {
            "ioc_value": "8343e254b3a9e9d7f64eab23fc5ba9def80702993e00de22c34df6efa2f4763e",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 13:41:20",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839503": [
        {
            "ioc_value": "724b129fa7ff06e95349d7d63b9b5bf109d1ac30d457dd53c1408becf20f4e29",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 13:41:18",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839502": [
        {
            "ioc_value": "671bd644e938f22c30ba8a90a244f0d2169b3e6d88d3ecc5f1f6631d0fc720a1",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 13:41:16",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839501": [
        {
            "ioc_value": "4c7a76f7163dda816593eecfff94da7074eaffd617d06a6d96d63c01aa5f04dc",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 13:41:15",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839500": [
        {
            "ioc_value": "667e19d7c08f44ab9f3a80916120d153a8a0bbc32b187e547b8eff3d7236c639",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 13:41:13",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839499": [
        {
            "ioc_value": "ddfefdfd08832a727ed070b3edd3d688787fac6396ec31c99215b4a41f166fa7",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 13:41:11",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839498": [
        {
            "ioc_value": "8c825cbe0e7ed81c4b03a88c5dff945bcd6e13a03f8f53a40410c5b6fa269b86",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 13:41:09",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839497": [
        {
            "ioc_value": "86c6f49546cc30759ee2e8d61aab50fb4224dc6ed95a4ae57ad21e36610dfb48",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 13:41:08",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839496": [
        {
            "ioc_value": "b3c918289700c93eb750019d8be29bec1d37b7b81fb1ef07a519024d8b0f09e1",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 13:41:06",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839495": [
        {
            "ioc_value": "fagaheestedlali.xyz",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 13:41:04",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839494": [
        {
            "ioc_value": "79df00e83284bb595b4cac69469a13eb0bca11fc372d922ec4ae4bf71b984fd9",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 13:41:01",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839493": [
        {
            "ioc_value": "813ec0783de84f38dd7068da62fa4447c70ae0a06f4635adcffe22e3b76a3b8c",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 13:40:59",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839492": [
        {
            "ioc_value": "245563c4bb30f6c72616fa4c72d3d81375a1414443e8c6eb534dcad52161aae7",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 13:40:58",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839491": [
        {
            "ioc_value": "5625f657d305c8447f4a7f672ac93aa505ced15d64a7e59db75798f85d37603b",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 13:40:56",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839490": [
        {
            "ioc_value": "44dc5e00cc396fbbc96f6a806c086c17aa053ad68fcc78cb0e9927ea77be5362",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 13:40:54",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839489": [
        {
            "ioc_value": "10d07eba8bc5f480f10cbc3760be001f99310905be8ce570b949d50d49f20368",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 13:40:52",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839488": [
        {
            "ioc_value": "3394b6df051021f4dfe524b79e6f9dc89f3af1cae34ba05c865239238bcae9a4",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 13:40:51",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839487": [
        {
            "ioc_value": "cc4a10d8c63e14b84e159db36c46f19f26a75bb3aee7ef753e0aa3e090d1039a",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 13:40:49",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839486": [
        {
            "ioc_value": "fce543be52c93a9dcf579ecaa762e6cbaa441294689b6030b693c23478b5f793",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 13:40:47",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839485": [
        {
            "ioc_value": "be655712b59af79f0f654eeaef22e66fa30da6ee635fcf5627caf5caf3a9eae4",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 13:40:45",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839484": [
        {
            "ioc_value": "6e3653a3e9a72753b8945a8f735fc04502703b05967a407846908863576681e9",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 13:40:44",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839483": [
        {
            "ioc_value": "iranfitness.top",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 13:40:42",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839482": [
        {
            "ioc_value": "a1e3eb31cbb58f41a30293286b0393d7b24deacea24881248c8acfe615e22278",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 13:40:40",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839481": [
        {
            "ioc_value": "jarayemaleyhamval.xyz",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 13:40:31",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839480": [
        {
            "ioc_value": "6fd543bd45878c56418593990fd798629098f9fbe277214875445e5ed9129b65",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 13:40:15",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839479": [
        {
            "ioc_value": "mokatebatedari.xyz",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 13:40:06",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839478": [
        {
            "ioc_value": "antigravity.study",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 13:39:55",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,ErrTraffic,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839477": [
        {
            "ioc_value": "chatgpt-web.vip",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 13:39:53",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,ErrTraffic,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839476": [
        {
            "ioc_value": "defi-xstocks.vip",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 13:39:51",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,ErrTraffic,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839475": [
        {
            "ioc_value": "clacndjsvulnarbi.beer",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 13:39:48",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,ErrTraffic,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839474": [
        {
            "ioc_value": "194.76.227.172:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 13:39:43",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,ErrTraffic,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839473": [
        {
            "ioc_value": "2.27.5.153:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 13:39:41",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,ErrTraffic,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839472": [
        {
            "ioc_value": "https://devltd.top/flomowk2.zip",
            "ioc_type": "url",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 13:39:37",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,ErrTraffic,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839471": [
        {
            "ioc_value": "83264e9216fb747d9e0048c6559d66dfca05cf50a1d415ecf212c879d08741ce",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 13:39:36",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,ErrTraffic,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839470": [
        {
            "ioc_value": "nero-ns-cdns.sbs",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 13:39:30",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,ErrTraffic,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839469": [
        {
            "ioc_value": "cash-js-server.sbs",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 13:39:29",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,ErrTraffic,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839468": [
        {
            "ioc_value": "ns-server-isdjs-icons.sbs",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 13:39:27",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,ErrTraffic,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839467": [
        {
            "ioc_value": "ns-cyber-server.sbs",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 13:39:25",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,ErrTraffic,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839466": [
        {
            "ioc_value": "lcates-vs.beer",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 13:39:23",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,ErrTraffic,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839465": [
        {
            "ioc_value": "cloud-save-image.sbs",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 13:39:22",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,ErrTraffic,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839464": [
        {
            "ioc_value": "verification-cdn-cloud.beer",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 13:39:20",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,ErrTraffic,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839463": [
        {
            "ioc_value": "ssg-cdn.beer",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 13:39:15",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,ErrTraffic,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839462": [
        {
            "ioc_value": "stabcdnvlc.beer",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 13:39:13",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,ErrTraffic,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839461": [
        {
            "ioc_value": "lckcdnjs.beer",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 13:39:09",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,ErrTraffic,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839460": [
        {
            "ioc_value": "teamcss.beer",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 13:39:06",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,ErrTraffic,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839459": [
        {
            "ioc_value": "vsbnsbootstrup.beer",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 13:39:04",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,ErrTraffic,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839458": [
        {
            "ioc_value": "dncloteam.beer",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 13:39:01",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,ErrTraffic,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839457": [
        {
            "ioc_value": "exdanteam.beer",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 13:38:57",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,ErrTraffic,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839456": [
        {
            "ioc_value": "neiwteamcdn.beer",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 13:38:55",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,ErrTraffic,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839455": [
        {
            "ioc_value": "vnmstokns.beer",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 13:38:52",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,ErrTraffic,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839454": [
        {
            "ioc_value": "bnsclod.beer",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 13:38:50",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,ErrTraffic,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839453": [
        {
            "ioc_value": "mnoskemp.beer",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 13:38:48",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,ErrTraffic,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839452": [
        {
            "ioc_value": "bnnsbdsdn-js.beer",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 13:38:47",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,ErrTraffic,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839451": [
        {
            "ioc_value": "bilfojsclod.beer",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 13:38:41",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,ErrTraffic,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839450": [
        {
            "ioc_value": "fijscdn.beer",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 13:38:40",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,ErrTraffic,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839449": [
        {
            "ioc_value": "77.239.114.108:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 13:38:30",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,ErrTraffic,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839448": [
        {
            "ioc_value": "94.154.35.155:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 13:38:26",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,ErrTraffic,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839447": [
        {
            "ioc_value": "94.154.35.157:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 13:38:24",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,ErrTraffic,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839446": [
        {
            "ioc_value": "94.154.35.164:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 13:38:22",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,ErrTraffic,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839445": [
        {
            "ioc_value": "anlytic-js-cloud.beer",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 13:38:19",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,ErrTraffic,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839444": [
        {
            "ioc_value": "api-server-cdn.sbs",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 13:38:17",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,ErrTraffic,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839443": [
        {
            "ioc_value": "awesomeisojs.beer",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 13:38:15",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,ErrTraffic,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839442": [
        {
            "ioc_value": "bkscndclou.beer",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 13:38:09",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,ErrTraffic,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839441": [
        {
            "ioc_value": "bootstrap-maxcdn.beer",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 13:38:07",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,ErrTraffic,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839440": [
        {
            "ioc_value": "bootstrup-cdnmaper.beer",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 13:38:05",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,ErrTraffic,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839439": [
        {
            "ioc_value": "bootstrup-framework-js.beer",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 13:38:03",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,ErrTraffic,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839438": [
        {
            "ioc_value": "buck-cdns-server.sbs",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 13:38:01",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,ErrTraffic,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839437": [
        {
            "ioc_value": "capcha-cdn-js.beer",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 13:37:59",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,ErrTraffic,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839436": [
        {
            "ioc_value": "cdn-compress-image.sbs",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 13:37:57",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,ErrTraffic,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839435": [
        {
            "ioc_value": "cdn-plugin-js.beer",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 13:37:55",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,ErrTraffic,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839434": [
        {
            "ioc_value": "0150605913e5cc05dbe79ed8f488d58140ac7c2853ca7853a7a78e9885628b9a",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 13:37:47",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,ErrTraffic,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839433": [
        {
            "ioc_value": "ldt.sequareeus.online",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 13:37:43",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,ErrTraffic,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839432": [
        {
            "ioc_value": "https://telegram.me/nwwfh8",
            "ioc_type": "url",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 13:37:36",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,ErrTraffic,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839431": [
        {
            "ioc_value": "https://steamcommunity.com/profiles/76561198719385745",
            "ioc_type": "url",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 13:37:34",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,ErrTraffic,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839430": [
        {
            "ioc_value": "18ac4062d773325076eaea0844bebb295b18100bbb669c351b02ed79354da157",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 13:37:31",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,ErrTraffic,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839429": [
        {
            "ioc_value": "www.robinamedicalcentre.com.au",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 13:37:22",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,ErrTraffic,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839428": [
        {
            "ioc_value": "www.mcttt.gov.fj",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 13:37:19",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,ErrTraffic,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839427": [
        {
            "ioc_value": "www.woodwardlg.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 13:37:17",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,ErrTraffic,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839426": [
        {
            "ioc_value": "www.hotelmontenegro.cz",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 13:37:15",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,ErrTraffic,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839425": [
        {
            "ioc_value": "insta360.co.id",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 13:36:36",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,ErrTraffic,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839424": [
        {
            "ioc_value": "bca.edu.pk",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 13:36:33",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,ErrTraffic,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839423": [
        {
            "ioc_value": "opportunitiesforeveryone.net",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 13:36:29",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,ErrTraffic,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839422": [
        {
            "ioc_value": "6bfb75b0f69099db4778abbdad7bb65f3661d2d23cba6552cced9002f1440ae7",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 13:36:28",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,ErrTraffic,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839421": [
        {
            "ioc_value": "gustoantico.ch",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 13:36:26",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,ErrTraffic,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839420": [
        {
            "ioc_value": "lastoriadelcaffe.ch",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 13:36:24",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,ErrTraffic,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839419": [
        {
            "ioc_value": "meierhealthcare.ch",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 13:36:22",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,ErrTraffic,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839418": [
        {
            "ioc_value": "sparkleup.ch",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 13:36:21",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,ErrTraffic,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839417": [
        {
            "ioc_value": "650ded564d3297b2c4dd55fb9e85e67355a43923c17767788fa6f441a59391c4",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 13:36:19",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,ErrTraffic,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839416": [
        {
            "ioc_value": "initial-scale=1.0",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 13:36:17",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,ErrTraffic,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839414": [
        {
            "ioc_value": "ae77b39f852383ae85c438497d7b528b9e60d082e9c6abc80962d914736f8174",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 13:36:14",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839415": [
        {
            "ioc_value": "890193eca05d38dffc646205959a67d0dd6e9b4d0a537f68d515b69646caf17c",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 13:36:14",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,ErrTraffic,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839413": [
        {
            "ioc_value": "435774098eaebc446f24f977b26cfc432a8b04d4bc9c10c96f802214707d32bd",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 13:36:12",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,ErrTraffic,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839412": [
        {
            "ioc_value": "deae4e644e8025371cee37a3562975c46de03ab742aa3b74c026812a747efcf9",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 13:36:10",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,ErrTraffic,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839411": [
        {
            "ioc_value": "4162dfc409dd2855deb33cdc2828e9aa866985d187b1463550feb359f3cbd954",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 13:36:08",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,ErrTraffic,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839410": [
        {
            "ioc_value": "e5be3d8543f00a59e9694d68bd1ea3b085b654a24a6113444bbc0ef8640343e5",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 13:36:06",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,ErrTraffic,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839409": [
        {
            "ioc_value": "50482c70750d30c2d8ad24c5f6ee46ecb6cd28162de7a6d2d23876ca17d4ed89",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 13:36:05",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,ErrTraffic,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839408": [
        {
            "ioc_value": "994a5f1d261229dcb3b89233d540b9edb5015c62780171ad1fcf40646d206f61",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 13:36:02",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,ErrTraffic,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839407": [
        {
            "ioc_value": "f6468f29494501aaaee6df60e848aca18774611c9fa3a76e659e686c8c25954b",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 13:35:59",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,ErrTraffic,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839406": [
        {
            "ioc_value": "ad63118ec4e540d2f4c0419d4d6f253fc378611aa82c78677a9eabe3489cbc7e",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 13:35:57",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,ErrTraffic,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839405": [
        {
            "ioc_value": "d6c7108abcfa11e5e20e5c80d6bbf6fbeaf0695f5e13d25ef3c16779e38118f3",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 13:35:56",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,ErrTraffic,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839404": [
        {
            "ioc_value": "ec59831e37a33f9206c1545125d4ccfd64da2ccc52f0962bbcc6a4fa1af7ea65",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 13:35:54",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,ErrTraffic,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839403": [
        {
            "ioc_value": "71f413c994c2440f30bf04dc27c5267c5bb033d38ad1fd0f25d32de4f27e95da",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 13:35:52",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,ErrTraffic,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839402": [
        {
            "ioc_value": "bc56317243189038f87628f895aa739b1fd5fede6b3ea98e02dbbe634e0bd7e4",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 13:35:50",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,ErrTraffic,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839401": [
        {
            "ioc_value": "aa89ad65c2434a64ad5482dfccf0d9b2a799e077141be3f9daf573793d96d528",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 13:35:49",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,ErrTraffic,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839400": [
        {
            "ioc_value": "ed257c6c25bf11eeb7c43db19686f5d846dc082013bc152b3694d819d64c7e5a",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 13:35:47",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,ErrTraffic,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839399": [
        {
            "ioc_value": "7b73d35a97658a13599a8233ae1c2d9dbf25f5b672865b32a80f98e22671dd94",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 13:35:45",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,ErrTraffic,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839398": [
        {
            "ioc_value": "8aa06f1bb5a4aa843d803bcf0a646f9ab094b8afc9dfa4cf639ea3118e6c6bb9",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 13:35:44",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839397": [
        {
            "ioc_value": "d78d9fb3655e9a82462b84bb1da4a167d2c7fb43a334e2575e3c3d5a9cf1355b",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 13:35:43",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,ErrTraffic,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839396": [
        {
            "ioc_value": "409c84781854d26a3b4a0e61b7873dca642dd0f848f1bcc75d95beacf3f0ad9a",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 13:35:42",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,ErrTraffic,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839395": [
        {
            "ioc_value": "55b45570bae5a8268fe1cbf943f3cd2615c80234ffde342569d0e44ad58b2dad",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 13:35:40",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,ErrTraffic,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839394": [
        {
            "ioc_value": "59466a6f6e4471e68ca42a85e3bda70794d023c541013fa2df357b8e4d238e61",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 13:35:38",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,ErrTraffic,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839393": [
        {
            "ioc_value": "1dcaf8ff52269dca2c224e2f6d868576155cdd9d2ceab2f206d0c37b59ed38db",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 13:35:36",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,ErrTraffic,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839392": [
        {
            "ioc_value": "0ab2fe60e6a9c59a3c2a645653883151b80883079d78099179d4a256c10c554b",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 13:35:35",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,ErrTraffic,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839391": [
        {
            "ioc_value": "b830f043076a12748b6a2dc0810ece85439ee77434d991ae7d84201b09ead756",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 13:35:33",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,ErrTraffic,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839390": [
        {
            "ioc_value": "454850749d874755a8e1e43e5a128a9fa39ffe49f5ffdbe9f264b5997ccb039c",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 13:35:29",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,ErrTraffic,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839389": [
        {
            "ioc_value": "acc38d4b54fbcfd60d86551b4a06771f4b29f1ac7dc4392d86ddeded18b110d5",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 13:35:28",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,ErrTraffic,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839388": [
        {
            "ioc_value": "4039f4b7894969cd03b96e0e004b2da18445e24eb6dbfdec09a1a0de685e4215",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 13:35:21",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,ErrTraffic,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839387": [
        {
            "ioc_value": "3ddd8f09dc777f42558989e0e32631982ecdb93300dfbd7f9bbfb8f462c14022",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 13:35:16",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,ErrTraffic,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839386": [
        {
            "ioc_value": "1e2e4e41198b8497b8e8a2853645fc10f763b0e4e299a68f614b8a22b3e30022",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 13:35:14",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,ErrTraffic,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839385": [
        {
            "ioc_value": "b6912c23cccc4b0964d55608916297f6978f0b38c80a4beac472004a786fcef7",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 13:35:10",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,ErrTraffic,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839384": [
        {
            "ioc_value": "f7ae66c8b93850663c6c20d6a405189e4fdef2c9de46dee7c283de24bf0c2137",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 13:35:06",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839382": [
        {
            "ioc_value": "0741ef664b10674534eba0e77c162b901d1efdb2863e2f8046ed4adc2ac6865f",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 13:35:05",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839383": [
        {
            "ioc_value": "df15eaf4f30afa77031861ce664291dc880977506b09e747a065edf41a6faf3b",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 13:35:05",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,ErrTraffic,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839381": [
        {
            "ioc_value": "9e6b554e7a442878b6d5f60bd82ca28cb22ef29e41f2bd13e8fcb05dd81d4562",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 13:35:03",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839380": [
        {
            "ioc_value": "fa868603841380979823c72d0eb9c18fdf4bc877f0f8f0982bb647151fad9906",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 13:35:02",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,ErrTraffic,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839379": [
        {
            "ioc_value": "4dc8daeb8563b9fe0eec40ce0d32d9987d1280cb69a588dd4f6ea41b6fefc218",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 13:35:01",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839378": [
        {
            "ioc_value": "f609202eaeec428706aec08f32c50978bc49515fe11e9146afa03e8e472a8883",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 13:34:58",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839377": [
        {
            "ioc_value": "b4d18f3e85c518921941aff9cbc10d92c48087fb013fec78b41907223662163c",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 13:34:56",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839376": [
        {
            "ioc_value": "41c6a9b7cc368a6f5e4d63ec7dc407eb66b1ccdb2dc727f2520b894c87b0ae3d",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 13:34:55",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,ErrTraffic,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839375": [
        {
            "ioc_value": "924138f5d487abd853e2d6bd792736112054504b7c8e324556f5ee01f54d2fbc",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 13:34:54",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839374": [
        {
            "ioc_value": "fcd3b80ec4b61eebdec2785ea74fefffdf1e5b580f329a1717972225c78b8133",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 13:34:52",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839373": [
        {
            "ioc_value": "fd7a3cdd0fa8481dab663c5d58d63667011e8dc3fba310f83e59b26c74521fe4",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 13:34:50",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839371": [
        {
            "ioc_value": "2b977fcbd6f3587d1f680d26eeed21981a9029bd57874a0d526f3f4d0d122da1",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 13:34:49",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,ErrTraffic,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839372": [
        {
            "ioc_value": "b751b3e82e1fe57e8c32fef2373694ff889bfe4336124ec9ec61d22920e26d23",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 13:34:49",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839370": [
        {
            "ioc_value": "2d3200584452bf1e11a3f00373ee82fdd419cc0ec455d720ebf6d1c414e46275",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 13:34:45",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839369": [
        {
            "ioc_value": "0f7a4ed93500ae446ab6cb923125c4bd220b9bae4ab0ad418599aceec324d04e",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 13:34:44",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839368": [
        {
            "ioc_value": "514a4732ccf9faf6f43478e0424a3f8803e261fea97ffd428cb8329a61226659",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 13:34:42",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839367": [
        {
            "ioc_value": "chicago-bbq.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 13:34:06",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,ErrTraffic,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839366": [
        {
            "ioc_value": "clainasns.beer",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 13:34:04",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,ErrTraffic,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839365": [
        {
            "ioc_value": "claudesave.beer",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 13:34:02",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,ErrTraffic,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839364": [
        {
            "ioc_value": "claudjaframework.beer",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 13:34:00",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,ErrTraffic,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839363": [
        {
            "ioc_value": "cloudcdnginx.beer",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 13:33:58",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,ErrTraffic,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839362": [
        {
            "ioc_value": "cloude-js-server.beer",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 13:33:56",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,ErrTraffic,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839361": [
        {
            "ioc_value": "createbeer.beer",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 13:33:55",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,ErrTraffic,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839360": [
        {
            "ioc_value": "darndcs-js.beer",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 13:33:53",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,ErrTraffic,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839359": [
        {
            "ioc_value": "dhnsdns.beer",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 13:33:51",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,ErrTraffic,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839358": [
        {
            "ioc_value": "exp.in",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 13:33:49",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,ErrTraffic,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839357": [
        {
            "ioc_value": "fetestjs.beer",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 13:33:48",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,ErrTraffic,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839356": [
        {
            "ioc_value": "fontawesome-js-cdn.beer",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 13:33:46",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,ErrTraffic,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839355": [
        {
            "ioc_value": "fonts-fontawesome.click",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 13:33:41",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,ErrTraffic,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839354": [
        {
            "ioc_value": "framework-jsoncdn.beer",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 13:33:39",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,ErrTraffic,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839353": [
        {
            "ioc_value": "frameworkjsbns.beer",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 13:33:37",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,ErrTraffic,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839352": [
        {
            "ioc_value": "fredcreate.beer",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 13:33:35",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,ErrTraffic,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839351": [
        {
            "ioc_value": "gdnssljs.beer",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 13:33:33",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,ErrTraffic,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839350": [
        {
            "ioc_value": "graciasdenada.beer",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 13:33:30",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,ErrTraffic,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839349": [
        {
            "ioc_value": "hahletsgoagain.beer",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 13:33:28",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,ErrTraffic,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839348": [
        {
            "ioc_value": "hcountry-cdn.cfd",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 13:33:27",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,ErrTraffic,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839347": [
        {
            "ioc_value": "hpscdn.beer",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 13:33:25",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,ErrTraffic,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839346": [
        {
            "ioc_value": "las-js-claud.beer",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 13:33:18",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,ErrTraffic,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839345": [
        {
            "ioc_value": "ldnscreatejs.beer",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 13:33:15",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,ErrTraffic,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839344": [
        {
            "ioc_value": "lmstles-bootstrapped.click",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 13:33:13",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,ErrTraffic,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839343": [
        {
            "ioc_value": "lnfcdnclad.beer",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 13:33:11",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,ErrTraffic,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839342": [
        {
            "ioc_value": "mcdns-imager.click",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 13:33:07",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,ErrTraffic,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839341": [
        {
            "ioc_value": "mistraljs.beer",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 13:33:06",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,ErrTraffic,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839340": [
        {
            "ioc_value": "ns-claude-js.beer",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 13:33:01",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,ErrTraffic,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839339": [
        {
            "ioc_value": "ns1cdnclaude.beer",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 13:32:59",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,ErrTraffic,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839338": [
        {
            "ioc_value": "nshtjscdn.beer",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 13:32:57",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,ErrTraffic,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839337": [
        {
            "ioc_value": "nsserdns.beer",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 13:32:55",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,ErrTraffic,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839336": [
        {
            "ioc_value": "nsserv-bootstru.beer",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 13:32:53",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,ErrTraffic,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839335": [
        {
            "ioc_value": "nsservclod.beer",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 13:32:52",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,ErrTraffic,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839334": [
        {
            "ioc_value": "nstdcs.beer",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 13:32:50",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,ErrTraffic,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839333": [
        {
            "ioc_value": "nvbfcdnclaud.beer",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 13:32:48",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,ErrTraffic,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839332": [
        {
            "ioc_value": "olnsclaud.beer",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 13:32:46",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,ErrTraffic,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839331": [
        {
            "ioc_value": "oplod-cdn-bootstrap-28.sbs",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 13:32:45",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,ErrTraffic,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839330": [
        {
            "ioc_value": "panelwork.cfd",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 13:32:43",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,ErrTraffic,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839329": [
        {
            "ioc_value": "polygon-cnd-stats.sbs",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 13:32:41",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,ErrTraffic,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839328": [
        {
            "ioc_value": "sane-cdn-js.beer",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 13:32:36",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,ErrTraffic,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839327": [
        {
            "ioc_value": "sbnsdns.beer",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 13:32:34",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,ErrTraffic,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839326": [
        {
            "ioc_value": "sccdnd-ltyles.click",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 13:32:32",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,ErrTraffic,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839325": [
        {
            "ioc_value": "slndcdnclaud.beer",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 13:32:29",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,ErrTraffic,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839324": [
        {
            "ioc_value": "slngftr.beer",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 13:32:27",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,ErrTraffic,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839323": [
        {
            "ioc_value": "smetana-js.beer",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 13:32:25",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,ErrTraffic,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839322": [
        {
            "ioc_value": "smfcdnbb.beer",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 13:32:23",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,ErrTraffic,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839321": [
        {
            "ioc_value": "sns-clauder-cdn.beer",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 13:32:20",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,ErrTraffic,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839320": [
        {
            "ioc_value": "sr-hostes-js.beer",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 13:32:18",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,ErrTraffic,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839319": [
        {
            "ioc_value": "ssjscrybootstrup.beer",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 13:32:16",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,ErrTraffic,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839318": [
        {
            "ioc_value": "ssns-cdn-ns.beer",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 13:32:15",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,ErrTraffic,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839317": [
        {
            "ioc_value": "testesclaus.beer",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 13:32:11",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,ErrTraffic,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839316": [
        {
            "ioc_value": "travel-js-ns.beer",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 13:32:09",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,ErrTraffic,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839315": [
        {
            "ioc_value": "unacerveza.beer",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 13:32:08",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,ErrTraffic,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839314": [
        {
            "ioc_value": "virtual-cdncloud.sbs",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 13:32:02",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,ErrTraffic,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839313": [
        {
            "ioc_value": "viscdnclaud.beer",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 13:32:00",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,ErrTraffic,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839312": [
        {
            "ioc_value": "vlns-andb-cdn.sbs",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 13:31:56",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,ErrTraffic,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839311": [
        {
            "ioc_value": "vrfimgjs.click",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 13:31:55",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,ErrTraffic,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839310": [
        {
            "ioc_value": "vsactivens.beer",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 13:31:53",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,ErrTraffic,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839309": [
        {
            "ioc_value": "09120c6637578e163ebad21e650c77bf0a23d8b48aaf887d72fb971a17e0327c",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 13:30:39",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,ErrTraffic,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839308": [
        {
            "ioc_value": "caea180952b57ccf9ce66b81578fa3096bc877ec6a6a7a1ac8352eba3100edd6",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 13:30:34",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,ErrTraffic,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839307": [
        {
            "ioc_value": "0b1f3390d9fc8cba8725e19adcf30bd6fef8651fb85c5cb919775eb14286d599",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 13:30:32",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,ErrTraffic,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839306": [
        {
            "ioc_value": "d7396fd0f9509212d99d653cc91bc99d64281447af4aa7db66a7c049a3b75b67",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 13:27:17",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,ErrTraffic,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839305": [
        {
            "ioc_value": "gasshopper.sale",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 13:26:12",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,ErrTraffic,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839304": [
        {
            "ioc_value": "matrix-config.net",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 13:25:37",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839303": [
        {
            "ioc_value": "openandopen.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 13:25:35",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839302": [
        {
            "ioc_value": "meetinformation.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 13:25:33",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839301": [
        {
            "ioc_value": "getimageinformation.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 13:25:31",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839300": [
        {
            "ioc_value": "tryinformation.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 13:25:30",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839299": [
        {
            "ioc_value": "documentmanagement.sbs",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 13:25:28",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839298": [
        {
            "ioc_value": "45.143.166.36:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 13:25:26",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839297": [
        {
            "ioc_value": "188.119.122.123:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 13:25:24",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839296": [
        {
            "ioc_value": "51.222.96.111:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 13:25:23",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839295": [
        {
            "ioc_value": "153.75.90.37:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 13:25:21",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839294": [
        {
            "ioc_value": "153.75.90.64:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 13:25:19",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839293": [
        {
            "ioc_value": "153.75.90.66:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 13:25:17",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839292": [
        {
            "ioc_value": "153.75.90.67:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 13:25:16",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839291": [
        {
            "ioc_value": "1-you.njalla.no",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 13:25:14",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839290": [
        {
            "ioc_value": "2-can.njalla.in",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 13:25:12",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839289": [
        {
            "ioc_value": "3-get.njalla.fo",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 13:25:10",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839288": [
        {
            "ioc_value": "c23bf7fd69a2cd8c3d5eb8bd1e7dac371a207e95b77ce05047193764cbc0a897",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 13:25:08",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839287": [
        {
            "ioc_value": "findyoursoftupdate.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 13:24:56",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839286": [
        {
            "ioc_value": "personalprogrammupdater.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 13:24:54",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839285": [
        {
            "ioc_value": "popularsoftupdates.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 13:24:53",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839284": [
        {
            "ioc_value": "captchadefence.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 13:24:51",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839283": [
        {
            "ioc_value": "gatekeepernet.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 13:24:49",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839282": [
        {
            "ioc_value": "topclouddefence.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 13:24:47",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839281": [
        {
            "ioc_value": "cloudbreachdetection.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 13:24:46",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839280": [
        {
            "ioc_value": "cloudsupergatekeeper.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 13:24:44",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839279": [
        {
            "ioc_value": "premiumcloudguard.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 13:24:42",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839278": [
        {
            "ioc_value": "perfectcloudgate.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 13:24:41",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839277": [
        {
            "ioc_value": "powerfireguard.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 13:24:39",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839276": [
        {
            "ioc_value": "powerfullcloudflare.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 13:24:37",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839275": [
        {
            "ioc_value": "cdnstatus.us.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 13:24:35",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839274": [
        {
            "ioc_value": "5f1b5a914ec38e997b077a93a9c7d174165756b8b5f8dd731dc2f98f14f06cde",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 13:24:34",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839273": [
        {
            "ioc_value": "fc76860e01af5e28fa484927559f9a5138d64d8dcea4c23bf1e361f046e2e156",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 13:24:30",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839272": [
        {
            "ioc_value": "50868954dbd4daa70e117c58ae8426cb9f5c13ed96d0f60d764590517e95e7cc",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 13:24:28",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839271": [
        {
            "ioc_value": "08e8efef3bd0fbb1ec1e098ec83563314dddbf28d8801b1ab3c77cb86c1b3838",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 13:24:25",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHide,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839270": [
        {
            "ioc_value": "2362ed8f4009e137a598ae749dacee4612560fdee4b2cc8b71d712fe0c7d1dcc",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 13:24:23",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding,EtherHidingMagecart",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839269": [
        {
            "ioc_value": "b9befdb3bd01faf9dc6cdc1f6f5ec5931a4f4560f2917c1e6ce97208c0504747",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 13:24:21",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding,EtherHidingMagecart",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839268": [
        {
            "ioc_value": "1d4dab0bc6e3d654d4f7cd3be4a2153d1b4821199765d77cb0de48a0d533f122",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 13:24:15",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding,EtherHidingMagecart",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839267": [
        {
            "ioc_value": "881be71c4df6c699d18688b98e554d9c63374b1409ecd8ac63d3562288dac53c",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 13:24:13",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding,EtherHidingMagecart",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839266": [
        {
            "ioc_value": "91359861a6912d074603eaba0cbe61dd2a5e6800df9db4b8942ddaf50ef042bc",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 13:24:11",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding,EtherHidingMagecart",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839265": [
        {
            "ioc_value": "cd8b89cac64af045e8720d959016027bbe3f4a6e893fc0611a934fe7f0b1eddd",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 13:24:10",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding,EtherHidingMagecart",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839264": [
        {
            "ioc_value": "b421e8f0903263e37fe4d9830e67afec9f69d7c80d76c1a5f446944715d6f8db",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 13:24:04",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding,EtherHidingMagecart",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839263": [
        {
            "ioc_value": "154.12.19.70:22012",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.valley_rat",
            "malware_alias": "Winos",
            "malware_printable": "ValleyRAT",
            "first_seen_utc": "2026-06-29 13:15:49",
            "last_seen_utc": null,
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://bazaar.abuse.ch/sample/ffe98374173d7c2084a1a6953b308c13a8b9493294af831c23542b0d88654036/",
            "tags": "valleyrat_s2",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1839262": [
        {
            "ioc_value": "154.12.19.70:22011",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.valley_rat",
            "malware_alias": "Winos",
            "malware_printable": "ValleyRAT",
            "first_seen_utc": "2026-06-29 13:15:48",
            "last_seen_utc": null,
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://bazaar.abuse.ch/sample/ffe98374173d7c2084a1a6953b308c13a8b9493294af831c23542b0d88654036/",
            "tags": "valleyrat_s2",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1839257": [
        {
            "ioc_value": "https://caribe-lawyers.com/",
            "ioc_type": "url",
            "threat_type": "payload_delivery",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-06-29 13:15:02",
            "last_seen_utc": null,
            "confidence_level": 75,
            "is_compromised": true,
            "reference": null,
            "tags": "ClickFix,compromised,EtherHiding,Polygon,Vidar,WordPress",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839250": [
        {
            "ioc_value": "39.107.238.247:5666",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.vshell",
            "malware_alias": null,
            "malware_printable": "VShell",
            "first_seen_utc": "2026-06-29 13:05:09",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "vshell",
            "anonymous": "1",
            "reporter": "_ik_"
        }
    ],
    "1839248": [
        {
            "ioc_value": "83.228.214.187:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.quasar_rat",
            "malware_alias": "CinaRAT,QuasarRAT,Yggdrasil",
            "malware_printable": "Quasar RAT",
            "first_seen_utc": "2026-06-29 13:05:07",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "quasarrat",
            "anonymous": "1",
            "reporter": "_ik_"
        }
    ],
    "1839249": [
        {
            "ioc_value": "110.42.252.147:8084",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.vshell",
            "malware_alias": null,
            "malware_printable": "VShell",
            "first_seen_utc": "2026-06-29 13:05:07",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "vshell",
            "anonymous": "1",
            "reporter": "_ik_"
        }
    ],
    "1839247": [
        {
            "ioc_value": "102.220.160.222:6666",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-06-29 13:05:05",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "asyncrat",
            "anonymous": "1",
            "reporter": "_ik_"
        }
    ],
    "1839245": [
        {
            "ioc_value": "https://alphakey.ae/",
            "ioc_type": "url",
            "threat_type": "payload_delivery",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-06-29 12:38:11",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": "https://clickfix.carsonww.com/domains/alphakey.ae",
            "tags": "ClickFix",
            "anonymous": "0",
            "reporter": "CarsonWilliams"
        }
    ],
    "1839237": [
        {
            "ioc_value": "751.lol",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-06-29 12:38:10",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://bazaar.abuse.ch/sample/bee4e24128c232853bc1decc9e5db2cf0fcb14538936adf01d6356beb4ac820c/",
            "tags": "751Stealer,c2",
            "anonymous": "0",
            "reporter": "burger"
        }
    ],
    "1839242": [
        {
            "ioc_value": "https://crown-seema.com/",
            "ioc_type": "url",
            "threat_type": "payload_delivery",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-06-29 12:38:09",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": "https://clickfix.carsonww.com/domains/crown-seema.com",
            "tags": "ClickFix",
            "anonymous": "0",
            "reporter": "CarsonWilliams"
        }
    ],
    "1839243": [
        {
            "ioc_value": "plaguec2.cc",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-06-29 12:38:09",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://bazaar.abuse.ch/sample/bee4e24128c232853bc1decc9e5db2cf0fcb14538936adf01d6356beb4ac820c/",
            "tags": "c2,PlagueStealer",
            "anonymous": "0",
            "reporter": "burger"
        }
    ],
    "1839244": [
        {
            "ioc_value": "51.195.202.236:5173",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.overlord",
            "malware_alias": null,
            "malware_printable": "Overlord RAT",
            "first_seen_utc": "2026-06-29 12:38:08",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://bazaar.abuse.ch/sample/db29882c1be518e6addf815fd941d3c29c60d3c225dc693afb5adefb07831ce9/",
            "tags": "c2,OverlordRAT",
            "anonymous": "0",
            "reporter": "burger"
        }
    ],
    "1839246": [
        {
            "ioc_value": "https://www.sosolidworld.com/",
            "ioc_type": "url",
            "threat_type": "payload_delivery",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-06-29 12:38:08",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": "https://clickfix.carsonww.com/domains/www.sosolidworld.com",
            "tags": "ClickFix",
            "anonymous": "0",
            "reporter": "CarsonWilliams"
        }
    ],
    "1839241": [
        {
            "ioc_value": "209.200.246.194:35885",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-06-29 11:46:48",
            "last_seen_utc": "2026-06-30 10:46:57",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1839240": [
        {
            "ioc_value": "116.213.42.110:5006",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-06-29 11:46:28",
            "last_seen_utc": "2026-06-30 10:46:37",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1839238": [
        {
            "ioc_value": "updatesrv.net",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-06-29 11:46:18",
            "last_seen_utc": "2026-06-30 10:46:28",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1839239": [
        {
            "ioc_value": "web-analyzer-serv32.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-06-29 11:46:18",
            "last_seen_utc": "2026-06-30 10:46:28",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1839236": [
        {
            "ioc_value": "https://jasyn.kz/",
            "ioc_type": "url",
            "threat_type": "payload_delivery",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-06-29 11:15:03",
            "last_seen_utc": "2026-06-29 13:31:03",
            "confidence_level": 75,
            "is_compromised": true,
            "reference": null,
            "tags": "ClickFix,compromised,EtherHiding,Polygon,Vidar,WordPress",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839165": [
        {
            "ioc_value": "178.62.3.223:8443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-06-29 10:54:05",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "c2,erebus-v14,nation-state-hunter,t1055,t1059_003",
            "anonymous": "0",
            "reporter": "Erebu"
        }
    ],
    "1839170": [
        {
            "ioc_value": "111.229.114.105:6379",
            "ioc_type": "ip:port",
            "threat_type": "payload_delivery",
            "malware": "elf.xmrig",
            "malware_alias": null,
            "malware_printable": "XMRIG",
            "first_seen_utc": "2026-06-29 10:54:05",
            "last_seen_utc": null,
            "confidence_level": 80,
            "is_compromised": false,
            "reference": "https://twitter.com/NullBlue67",
            "tags": "rce,redis",
            "anonymous": "0",
            "reporter": "nullblue67"
        }
    ],
    "1839171": [
        {
            "ioc_value": "172.104.173.62:6379",
            "ioc_type": "ip:port",
            "threat_type": "payload_delivery",
            "malware": "elf.xmrig",
            "malware_alias": null,
            "malware_printable": "XMRIG",
            "first_seen_utc": "2026-06-29 10:54:05",
            "last_seen_utc": null,
            "confidence_level": 80,
            "is_compromised": false,
            "reference": "https://twitter.com/NullBlue67",
            "tags": "rce,redis",
            "anonymous": "0",
            "reporter": "nullblue67"
        }
    ],
    "1839172": [
        {
            "ioc_value": "23.234.72.111:6379",
            "ioc_type": "ip:port",
            "threat_type": "payload_delivery",
            "malware": "elf.xmrig",
            "malware_alias": null,
            "malware_printable": "XMRIG",
            "first_seen_utc": "2026-06-29 10:54:04",
            "last_seen_utc": null,
            "confidence_level": 80,
            "is_compromised": false,
            "reference": "https://twitter.com/NullBlue67",
            "tags": "rce,redis",
            "anonymous": "0",
            "reporter": "nullblue67"
        }
    ],
    "1839173": [
        {
            "ioc_value": "59.110.241.158:6379",
            "ioc_type": "ip:port",
            "threat_type": "payload_delivery",
            "malware": "elf.xmrig",
            "malware_alias": null,
            "malware_printable": "XMRIG",
            "first_seen_utc": "2026-06-29 10:54:04",
            "last_seen_utc": null,
            "confidence_level": 80,
            "is_compromised": false,
            "reference": "https://twitter.com/NullBlue67",
            "tags": "rce,redis",
            "anonymous": "0",
            "reporter": "nullblue67"
        }
    ],
    "1839174": [
        {
            "ioc_value": "95.182.96.193:6379",
            "ioc_type": "ip:port",
            "threat_type": "payload_delivery",
            "malware": "elf.xmrig",
            "malware_alias": null,
            "malware_printable": "XMRIG",
            "first_seen_utc": "2026-06-29 10:54:04",
            "last_seen_utc": null,
            "confidence_level": 80,
            "is_compromised": false,
            "reference": "https://twitter.com/NullBlue67",
            "tags": "rce,redis",
            "anonymous": "0",
            "reporter": "nullblue67"
        }
    ],
    "1839175": [
        {
            "ioc_value": "95.173.222.59:5432",
            "ioc_type": "ip:port",
            "threat_type": "payload_delivery",
            "malware": "elf.xmrig",
            "malware_alias": null,
            "malware_printable": "XMRIG",
            "first_seen_utc": "2026-06-29 10:54:03",
            "last_seen_utc": null,
            "confidence_level": 80,
            "is_compromised": false,
            "reference": "https://twitter.com/NullBlue67",
            "tags": "postgres,takeover",
            "anonymous": "0",
            "reporter": "nullblue67"
        }
    ],
    "1839176": [
        {
            "ioc_value": "3.129.187.38:5432",
            "ioc_type": "ip:port",
            "threat_type": "payload_delivery",
            "malware": "elf.xmrig",
            "malware_alias": null,
            "malware_printable": "XMRIG",
            "first_seen_utc": "2026-06-29 10:54:03",
            "last_seen_utc": null,
            "confidence_level": 80,
            "is_compromised": false,
            "reference": "https://twitter.com/NullBlue67",
            "tags": "postgres,takeover",
            "anonymous": "0",
            "reporter": "nullblue67"
        }
    ],
    "1839177": [
        {
            "ioc_value": "112.52.34.18:2375",
            "ioc_type": "ip:port",
            "threat_type": "payload_delivery",
            "malware": "elf.redtail",
            "malware_alias": null,
            "malware_printable": "RedTail",
            "first_seen_utc": "2026-06-29 10:54:02",
            "last_seen_utc": null,
            "confidence_level": 80,
            "is_compromised": false,
            "reference": "https://twitter.com/NullBlue67",
            "tags": "docker-api",
            "anonymous": "0",
            "reporter": "nullblue67"
        }
    ],
    "1839178": [
        {
            "ioc_value": "134.209.202.49:2375",
            "ioc_type": "ip:port",
            "threat_type": "payload_delivery",
            "malware": "elf.redtail",
            "malware_alias": null,
            "malware_printable": "RedTail",
            "first_seen_utc": "2026-06-29 10:54:02",
            "last_seen_utc": null,
            "confidence_level": 80,
            "is_compromised": false,
            "reference": "https://twitter.com/NullBlue67",
            "tags": "docker-api",
            "anonymous": "0",
            "reporter": "nullblue67"
        }
    ],
    "1839179": [
        {
            "ioc_value": "167.94.146.49:2375",
            "ioc_type": "ip:port",
            "threat_type": "payload_delivery",
            "malware": "elf.redtail",
            "malware_alias": null,
            "malware_printable": "RedTail",
            "first_seen_utc": "2026-06-29 10:54:02",
            "last_seen_utc": null,
            "confidence_level": 80,
            "is_compromised": false,
            "reference": "https://twitter.com/NullBlue67",
            "tags": "docker-api",
            "anonymous": "0",
            "reporter": "nullblue67"
        }
    ],
    "1839180": [
        {
            "ioc_value": "172.236.228.227:2375",
            "ioc_type": "ip:port",
            "threat_type": "payload_delivery",
            "malware": "elf.redtail",
            "malware_alias": null,
            "malware_printable": "RedTail",
            "first_seen_utc": "2026-06-29 10:54:01",
            "last_seen_utc": null,
            "confidence_level": 80,
            "is_compromised": false,
            "reference": "https://twitter.com/NullBlue67",
            "tags": "docker-api",
            "anonymous": "0",
            "reporter": "nullblue67"
        }
    ],
    "1839181": [
        {
            "ioc_value": "173.255.225.25:2375",
            "ioc_type": "ip:port",
            "threat_type": "payload_delivery",
            "malware": "elf.redtail",
            "malware_alias": null,
            "malware_printable": "RedTail",
            "first_seen_utc": "2026-06-29 10:54:01",
            "last_seen_utc": null,
            "confidence_level": 80,
            "is_compromised": false,
            "reference": "https://twitter.com/NullBlue67",
            "tags": "docker-api",
            "anonymous": "0",
            "reporter": "nullblue67"
        }
    ],
    "1839182": [
        {
            "ioc_value": "193.32.162.60:2375",
            "ioc_type": "ip:port",
            "threat_type": "payload_delivery",
            "malware": "elf.redtail",
            "malware_alias": null,
            "malware_printable": "RedTail",
            "first_seen_utc": "2026-06-29 10:54:00",
            "last_seen_utc": null,
            "confidence_level": 80,
            "is_compromised": false,
            "reference": "https://twitter.com/NullBlue67",
            "tags": "docker-api",
            "anonymous": "0",
            "reporter": "nullblue67"
        }
    ],
    "1839183": [
        {
            "ioc_value": "199.45.155.108:2375",
            "ioc_type": "ip:port",
            "threat_type": "payload_delivery",
            "malware": "elf.redtail",
            "malware_alias": null,
            "malware_printable": "RedTail",
            "first_seen_utc": "2026-06-29 10:54:00",
            "last_seen_utc": null,
            "confidence_level": 80,
            "is_compromised": false,
            "reference": "https://twitter.com/NullBlue67",
            "tags": "docker-api",
            "anonymous": "0",
            "reporter": "nullblue67"
        }
    ],
    "1839184": [
        {
            "ioc_value": "2.57.122.202:2375",
            "ioc_type": "ip:port",
            "threat_type": "payload_delivery",
            "malware": "elf.redtail",
            "malware_alias": null,
            "malware_printable": "RedTail",
            "first_seen_utc": "2026-06-29 10:53:59",
            "last_seen_utc": null,
            "confidence_level": 80,
            "is_compromised": false,
            "reference": "https://twitter.com/NullBlue67",
            "tags": "docker-api",
            "anonymous": "0",
            "reporter": "nullblue67"
        }
    ],
    "1839185": [
        {
            "ioc_value": "20.150.193.32:2375",
            "ioc_type": "ip:port",
            "threat_type": "payload_delivery",
            "malware": "elf.redtail",
            "malware_alias": null,
            "malware_printable": "RedTail",
            "first_seen_utc": "2026-06-29 10:53:59",
            "last_seen_utc": null,
            "confidence_level": 80,
            "is_compromised": false,
            "reference": "https://twitter.com/NullBlue67",
            "tags": "docker-api",
            "anonymous": "0",
            "reporter": "nullblue67"
        }
    ],
    "1839186": [
        {
            "ioc_value": "20.65.195.35:2375",
            "ioc_type": "ip:port",
            "threat_type": "payload_delivery",
            "malware": "elf.redtail",
            "malware_alias": null,
            "malware_printable": "RedTail",
            "first_seen_utc": "2026-06-29 10:53:58",
            "last_seen_utc": null,
            "confidence_level": 80,
            "is_compromised": false,
            "reference": "https://twitter.com/NullBlue67",
            "tags": "docker-api",
            "anonymous": "0",
            "reporter": "nullblue67"
        }
    ],
    "1839187": [
        {
            "ioc_value": "209.50.170.112:2375",
            "ioc_type": "ip:port",
            "threat_type": "payload_delivery",
            "malware": "elf.redtail",
            "malware_alias": null,
            "malware_printable": "RedTail",
            "first_seen_utc": "2026-06-29 10:53:57",
            "last_seen_utc": null,
            "confidence_level": 80,
            "is_compromised": false,
            "reference": "https://twitter.com/NullBlue67",
            "tags": "docker-api",
            "anonymous": "0",
            "reporter": "nullblue67"
        }
    ],
    "1839188": [
        {
            "ioc_value": "45.79.5.11:2375",
            "ioc_type": "ip:port",
            "threat_type": "payload_delivery",
            "malware": "elf.redtail",
            "malware_alias": null,
            "malware_printable": "RedTail",
            "first_seen_utc": "2026-06-29 10:53:57",
            "last_seen_utc": null,
            "confidence_level": 80,
            "is_compromised": false,
            "reference": "https://twitter.com/NullBlue67",
            "tags": "docker-api",
            "anonymous": "0",
            "reporter": "nullblue67"
        }
    ],
    "1839189": [
        {
            "ioc_value": "47.84.194.39:2375",
            "ioc_type": "ip:port",
            "threat_type": "payload_delivery",
            "malware": "elf.redtail",
            "malware_alias": null,
            "malware_printable": "RedTail",
            "first_seen_utc": "2026-06-29 10:53:56",
            "last_seen_utc": null,
            "confidence_level": 80,
            "is_compromised": false,
            "reference": "https://twitter.com/NullBlue67",
            "tags": "docker-api",
            "anonymous": "0",
            "reporter": "nullblue67"
        }
    ],
    "1839190": [
        {
            "ioc_value": "65.49.20.67:2375",
            "ioc_type": "ip:port",
            "threat_type": "payload_delivery",
            "malware": "elf.redtail",
            "malware_alias": null,
            "malware_printable": "RedTail",
            "first_seen_utc": "2026-06-29 10:53:56",
            "last_seen_utc": null,
            "confidence_level": 80,
            "is_compromised": false,
            "reference": "https://twitter.com/NullBlue67",
            "tags": "docker-api",
            "anonymous": "0",
            "reporter": "nullblue67"
        }
    ],
    "1839235": [
        {
            "ioc_value": "129.212.233.8:9034",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.aisuru",
            "malware_alias": null,
            "malware_printable": "Aisuru",
            "first_seen_utc": "2026-06-29 10:53:56",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "Aisuru,c2",
            "anonymous": "0",
            "reporter": "Bitsight"
        }
    ],
    "1839234": [
        {
            "ioc_value": "https://jiy.psgiran.news/",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-06-29 10:00:21",
            "last_seen_utc": "2026-06-29 13:25:51",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "vidar",
            "anonymous": "0",
            "reporter": "crep1x"
        }
    ],
    "1839233": [
        {
            "ioc_value": "jiy.psgiran.news",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-06-29 10:00:20",
            "last_seen_utc": "2026-06-29 13:25:51",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "vidar",
            "anonymous": "0",
            "reporter": "crep1x"
        }
    ],
    "1839232": [
        {
            "ioc_value": "https://jiy.jangkarsm188.top/",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-06-29 10:00:19",
            "last_seen_utc": "2026-06-29 13:25:39",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "vidar",
            "anonymous": "0",
            "reporter": "crep1x"
        }
    ],
    "1839231": [
        {
            "ioc_value": "jiy.jangkarsm188.top",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-06-29 10:00:18",
            "last_seen_utc": "2026-06-29 13:25:39",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "vidar",
            "anonymous": "0",
            "reporter": "crep1x"
        }
    ],
    "1839230": [
        {
            "ioc_value": "39p49guo.mokatebatedari.xyz",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 09:55:17",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "clearfake",
            "anonymous": "1",
            "reporter": "ttakvam"
        }
    ],
    "1839222": [
        {
            "ioc_value": "178.104.119.162:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-06-29 09:47:08",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "Vidar",
            "anonymous": "0",
            "reporter": "crep1x"
        }
    ],
    "1839223": [
        {
            "ioc_value": "77.42.88.66:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-06-29 09:47:08",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "Vidar",
            "anonymous": "0",
            "reporter": "crep1x"
        }
    ],
    "1839224": [
        {
            "ioc_value": "167.233.114.81:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-06-29 09:47:08",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "Vidar",
            "anonymous": "0",
            "reporter": "crep1x"
        }
    ],
    "1839225": [
        {
            "ioc_value": "167.233.207.52:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-06-29 09:47:08",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "Vidar",
            "anonymous": "0",
            "reporter": "crep1x"
        }
    ],
    "1839226": [
        {
            "ioc_value": "167.233.193.229:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-06-29 09:47:08",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "Vidar",
            "anonymous": "0",
            "reporter": "crep1x"
        }
    ],
    "1839227": [
        {
            "ioc_value": "91.98.87.85:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-06-29 09:47:08",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "Vidar",
            "anonymous": "0",
            "reporter": "crep1x"
        }
    ],
    "1839228": [
        {
            "ioc_value": "167.233.198.35:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-06-29 09:47:08",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "Vidar",
            "anonymous": "0",
            "reporter": "crep1x"
        }
    ],
    "1839229": [
        {
            "ioc_value": "167.233.204.162:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-06-29 09:47:08",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "Vidar",
            "anonymous": "0",
            "reporter": "crep1x"
        }
    ],
    "1839221": [
        {
            "ioc_value": "5.8.19.155:14646",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-06-29 09:45:40",
            "last_seen_utc": "2026-06-30 10:45:53",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1839220": [
        {
            "ioc_value": "45.92.158.150:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-06-29 09:45:31",
            "last_seen_utc": "2026-06-30 10:45:43",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1839219": [
        {
            "ioc_value": "45.74.7.168:2428",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-06-29 09:45:28",
            "last_seen_utc": "2026-06-30 10:45:41",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1839218": [
        {
            "ioc_value": "27.102.137.139:14645",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-06-29 09:45:08",
            "last_seen_utc": "2026-06-30 10:45:21",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1839215": [
        {
            "ioc_value": "fog.psgiran.news",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-06-29 09:45:07",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "Vidar",
            "anonymous": "0",
            "reporter": "crep1x"
        }
    ],
    "1839216": [
        {
            "ioc_value": "gpy.psgiran.news",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-06-29 09:45:07",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "Vidar",
            "anonymous": "0",
            "reporter": "crep1x"
        }
    ],
    "1839217": [
        {
            "ioc_value": "iii.psgiran.news",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-06-29 09:45:07",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "Vidar",
            "anonymous": "0",
            "reporter": "crep1x"
        }
    ],
    "1839212": [
        {
            "ioc_value": "fog.jangkarsm188.top",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-06-29 09:45:06",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "Vidar",
            "anonymous": "0",
            "reporter": "crep1x"
        }
    ],
    "1839213": [
        {
            "ioc_value": "gpy.jangkarsm188.top",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-06-29 09:45:06",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "Vidar",
            "anonymous": "0",
            "reporter": "crep1x"
        }
    ],
    "1839214": [
        {
            "ioc_value": "iii.jangkarsm188.top",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-06-29 09:45:06",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "Vidar",
            "anonymous": "0",
            "reporter": "crep1x"
        }
    ],
    "1839211": [
        {
            "ioc_value": "https://167.233.204.162/",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-06-29 09:44:45",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "Vidar",
            "anonymous": "0",
            "reporter": "crep1x"
        }
    ],
    "1839205": [
        {
            "ioc_value": "https://77.42.88.66/",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-06-29 09:44:44",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "Vidar",
            "anonymous": "0",
            "reporter": "crep1x"
        }
    ],
    "1839206": [
        {
            "ioc_value": "https://167.233.114.81/",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-06-29 09:44:44",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "Vidar",
            "anonymous": "0",
            "reporter": "crep1x"
        }
    ],
    "1839207": [
        {
            "ioc_value": "https://167.233.207.52/",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-06-29 09:44:44",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "Vidar",
            "anonymous": "0",
            "reporter": "crep1x"
        }
    ],
    "1839208": [
        {
            "ioc_value": "https://167.233.193.229/",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-06-29 09:44:44",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "Vidar",
            "anonymous": "0",
            "reporter": "crep1x"
        }
    ],
    "1839209": [
        {
            "ioc_value": "https://91.98.87.85/",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-06-29 09:44:44",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "Vidar",
            "anonymous": "0",
            "reporter": "crep1x"
        }
    ],
    "1839210": [
        {
            "ioc_value": "https://167.233.198.35/",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-06-29 09:44:44",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "Vidar",
            "anonymous": "0",
            "reporter": "crep1x"
        }
    ],
    "1839199": [
        {
            "ioc_value": "https://gpy.jangkarsm188.top/",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-06-29 09:44:43",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "Vidar",
            "anonymous": "0",
            "reporter": "crep1x"
        }
    ],
    "1839200": [
        {
            "ioc_value": "https://iii.jangkarsm188.top/",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-06-29 09:44:43",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "Vidar",
            "anonymous": "0",
            "reporter": "crep1x"
        }
    ],
    "1839201": [
        {
            "ioc_value": "https://fog.psgiran.news/",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-06-29 09:44:43",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "Vidar",
            "anonymous": "0",
            "reporter": "crep1x"
        }
    ],
    "1839202": [
        {
            "ioc_value": "https://gpy.psgiran.news/",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-06-29 09:44:43",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "Vidar",
            "anonymous": "0",
            "reporter": "crep1x"
        }
    ],
    "1839203": [
        {
            "ioc_value": "https://iii.psgiran.news/",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-06-29 09:44:43",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "Vidar",
            "anonymous": "0",
            "reporter": "crep1x"
        }
    ],
    "1839204": [
        {
            "ioc_value": "https://178.104.119.162/",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-06-29 09:44:43",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "Vidar",
            "anonymous": "0",
            "reporter": "crep1x"
        }
    ],
    "1839196": [
        {
            "ioc_value": "https://steamcommunity.com/profiles/76561198680197300",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-06-29 09:44:42",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "Vidar",
            "anonymous": "0",
            "reporter": "crep1x"
        }
    ],
    "1839197": [
        {
            "ioc_value": "https://telegram.me/af97ri",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-06-29 09:44:42",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "Vidar",
            "anonymous": "0",
            "reporter": "crep1x"
        }
    ],
    "1839198": [
        {
            "ioc_value": "https://fog.jangkarsm188.top/",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-06-29 09:44:42",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "Vidar",
            "anonymous": "0",
            "reporter": "crep1x"
        }
    ],
    "1839195": [
        {
            "ioc_value": "193.35.17.42:9956",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-06-29 09:44:11",
            "last_seen_utc": "2026-06-30 10:44:17",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1839194": [
        {
            "ioc_value": "192.162.199.149:8808",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-06-29 09:44:08",
            "last_seen_utc": "2026-06-30 10:44:14",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1839193": [
        {
            "ioc_value": "178.128.133.69:8080",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.evilginx",
            "malware_alias": null,
            "malware_printable": "Evilginx",
            "first_seen_utc": "2026-06-29 09:43:49",
            "last_seen_utc": "2026-06-30 10:43:53",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Evilginx,EvilGoPhish",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1839192": [
        {
            "ioc_value": "107.174.142.104:5543",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-06-29 09:43:13",
            "last_seen_utc": "2026-06-30 10:43:14",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1839191": [
        {
            "ioc_value": "104.168.38.165:4321",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-06-29 09:43:10",
            "last_seen_utc": "2026-06-30 10:43:11",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1839169": [
        {
            "ioc_value": "dsr.bet1forward.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 09:34:19",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake",
            "anonymous": "1",
            "reporter": "ttakvam"
        }
    ],
    "1839168": [
        {
            "ioc_value": "203.159.90.247:2404",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-06-29 09:30:42",
            "last_seen_utc": null,
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://bazaar.abuse.ch/sample/aff8f851155a1e45b120dfcf0ccd0ff9679ee0d3ae4284b09d01c88ff46b48bb/",
            "tags": "remcos",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1839167": [
        {
            "ioc_value": "151.239.25.40:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-06-29 09:05:07",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "cobaltstrike",
            "anonymous": "1",
            "reporter": "_ik_"
        }
    ],
    "1839166": [
        {
            "ioc_value": "idverification-cdn.info",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 08:19:40",
            "last_seen_utc": "2026-06-29 13:30:22",
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding,Polygon",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839164": [
        {
            "ioc_value": "137.220.140.4:8888",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.valley_rat",
            "malware_alias": "Winos",
            "malware_printable": "ValleyRAT",
            "first_seen_utc": "2026-06-29 08:11:17",
            "last_seen_utc": null,
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://bazaar.abuse.ch/sample/54ad3d4d8342ddea5cc6adea83d26a574a11d7e5133a04af6999a87adbbc2336/",
            "tags": "valleyrat_s2",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1839163": [
        {
            "ioc_value": "137.220.140.4:15443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.valley_rat",
            "malware_alias": "Winos",
            "malware_printable": "ValleyRAT",
            "first_seen_utc": "2026-06-29 08:11:16",
            "last_seen_utc": null,
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://bazaar.abuse.ch/sample/54ad3d4d8342ddea5cc6adea83d26a574a11d7e5133a04af6999a87adbbc2336/",
            "tags": "valleyrat_s2",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1839161": [
        {
            "ioc_value": "122.51.108.168:4444",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.vshell",
            "malware_alias": null,
            "malware_printable": "VShell",
            "first_seen_utc": "2026-06-29 08:05:06",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "vshell",
            "anonymous": "1",
            "reporter": "_ik_"
        }
    ],
    "1839162": [
        {
            "ioc_value": "192.243.120.239:8089",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.vshell",
            "malware_alias": null,
            "malware_printable": "VShell",
            "first_seen_utc": "2026-06-29 08:05:06",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "vshell",
            "anonymous": "1",
            "reporter": "_ik_"
        }
    ],
    "1839160": [
        {
            "ioc_value": "103.101.176.234:8084",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.vshell",
            "malware_alias": null,
            "malware_printable": "VShell",
            "first_seen_utc": "2026-06-29 08:05:05",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "vshell",
            "anonymous": "1",
            "reporter": "_ik_"
        }
    ],
    "1839159": [
        {
            "ioc_value": "38.38.250.68:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-06-29 08:05:04",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "cobaltstrike",
            "anonymous": "1",
            "reporter": "_ik_"
        }
    ],
    "1839082": [
        {
            "ioc_value": "27.133.154.218:8443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-06-29 07:53:26",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "c2,erebus-v14,nation-state-hunter,t1055,t1071_001",
            "anonymous": "0",
            "reporter": "Erebu"
        }
    ],
    "1839158": [
        {
            "ioc_value": "1j4lxwuu.1xboropartners.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 07:44:17",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "clearfake",
            "anonymous": "1",
            "reporter": "ttakvam"
        }
    ],
    "1839157": [
        {
            "ioc_value": "107.172.13.198:8080",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-06-29 07:40:45",
            "last_seen_utc": null,
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://bazaar.abuse.ch/sample/5b88eb2c33e9389324abd2f14064a0c1861bdccd5ee12c49e6620112c2c8dfaf/",
            "tags": "remcos",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1839155": [
        {
            "ioc_value": "backupper.pro",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 07:40:23",
            "last_seen_utc": "2026-06-29 13:24:08",
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "BSC,ClearFake,Magecart,WebSkimmer",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839156": [
        {
            "ioc_value": "cdn.api-middle-connect.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 07:40:23",
            "last_seen_utc": "2026-06-29 13:24:20",
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "BSC,ClearFake,Magecart,WebSkimmer",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839154": [
        {
            "ioc_value": "178.16.53.219:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 07:40:21",
            "last_seen_utc": "2026-06-29 16:01:48",
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "BSC,ClearFake,Magecart,WebSkimmer",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839153": [
        {
            "ioc_value": "wiciauth.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 07:40:19",
            "last_seen_utc": "2026-06-29 13:24:32",
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "BSC,ClearFake",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839144": [
        {
            "ioc_value": "be32773534e3d4cd7618194949f7628882992f3dfb048c37f4c960505a005b1c",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 07:40:14",
            "last_seen_utc": "2026-06-29 13:40:23",
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "BSC,ClearFake,ClickFix,EtherHiding,GoStealer",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839145": [
        {
            "ioc_value": "ada4690c212b7b983e65986c2528c9bdf7cff75589b043ee223a021465c43920",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 07:40:14",
            "last_seen_utc": "2026-06-29 13:40:25",
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "BSC,ClearFake,ClickFix,EtherHiding,GoStealer",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839146": [
        {
            "ioc_value": "833e888570c0873e3ce1f026bf6fe7d5abdc0efdd9e55399084ec6fabe9df21b",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 07:40:14",
            "last_seen_utc": "2026-06-29 13:40:26",
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "BSC,ClearFake,ClickFix,EtherHiding,GoStealer",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839147": [
        {
            "ioc_value": "0c86f5737476c1efc6dffed41e548e75ef9aa4b3dd36b59a30edd320bd65a429",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 07:40:14",
            "last_seen_utc": "2026-06-29 13:40:28",
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "BSC,ClearFake,ClickFix,EtherHiding,GoStealer",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839148": [
        {
            "ioc_value": "c6d22ebf9dce5fef2d5f1d87b3007457ef3c6d0193f121305b3d14e85441b43f",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 07:40:14",
            "last_seen_utc": "2026-06-29 13:40:30",
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "BSC,ClearFake,ClickFix,EtherHiding,GoStealer",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839149": [
        {
            "ioc_value": "5239a198297149ff5440bda18c94ce9c8cc2a2212bd95b3c4bedc197c1b9fb1c",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 07:40:14",
            "last_seen_utc": "2026-06-29 13:40:33",
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "BSC,ClearFake,ClickFix,EtherHiding,GoStealer",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839150": [
        {
            "ioc_value": "550fe153238e6a8c2cc6cf6a882bdc853fa4bb00721ebf5e7eae863124fd316b",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 07:40:14",
            "last_seen_utc": "2026-06-29 13:40:35",
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "BSC,ClearFake,ClickFix,EtherHiding,GoStealer",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839151": [
        {
            "ioc_value": "35f619453b4ab2c491b29d880c6bee8f3ae16700b293bbf31deeae975caa71c3",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 07:40:14",
            "last_seen_utc": "2026-06-29 13:40:36",
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "BSC,ClearFake,ClickFix,EtherHiding,GoStealer",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839152": [
        {
            "ioc_value": "c2ee091e95cdc4b4d677e55dc361d76867367a771b540dade1c698a05a2d5f0d",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 07:40:14",
            "last_seen_utc": "2026-06-29 13:40:38",
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "BSC,ClearFake,ClickFix,EtherHiding,GoStealer",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839135": [
        {
            "ioc_value": "ab101c1996f424300c3eddd06c10575585eeca9d2f7c892f3c45c50e9719c690",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 07:40:13",
            "last_seen_utc": "2026-06-29 13:40:04",
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "BSC,ClearFake,ClickFix,EtherHiding,GoStealer",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839136": [
        {
            "ioc_value": "acf4462915e81d81deac3f8e34de6b8cee64cc30dd9f57945794ba0f6dd0a0a8",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 07:40:13",
            "last_seen_utc": "2026-06-29 13:40:08",
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "BSC,ClearFake,ClickFix,EtherHiding,GoStealer",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839137": [
        {
            "ioc_value": "46a8a3d6131259e53ec07ac725c12dcf5a07d677ac35583982038ad397c19ad3",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 07:40:13",
            "last_seen_utc": "2026-06-29 13:40:10",
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "BSC,ClearFake,ClickFix,EtherHiding,GoStealer",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839138": [
        {
            "ioc_value": "42624224dfce7a43fcb9d806db2082c30227a815478b1feb74e8cf8cb64f71d2",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 07:40:13",
            "last_seen_utc": "2026-06-29 13:40:11",
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "BSC,ClearFake,ClickFix,EtherHiding,GoStealer",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839139": [
        {
            "ioc_value": "fa6e5f8bb72cc6b04bafe95f01d664b21c1654381b74154897c3efe32e01104b",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 07:40:13",
            "last_seen_utc": "2026-06-29 13:40:13",
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "BSC,ClearFake,ClickFix,EtherHiding,GoStealer",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839140": [
        {
            "ioc_value": "2d32bf0acaaf5ab032313ec4476774390ebc084d9b8459afd284223fcfb6021d",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 07:40:13",
            "last_seen_utc": "2026-06-29 13:40:16",
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "BSC,ClearFake,ClickFix,EtherHiding,GoStealer",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839141": [
        {
            "ioc_value": "3f6b065ed2f63b461f23880aee569b9522dd136c20c65bea450f305e9c93f22c",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 07:40:13",
            "last_seen_utc": "2026-06-29 13:40:18",
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "BSC,ClearFake,ClickFix,EtherHiding,GoStealer",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839142": [
        {
            "ioc_value": "0c964ea5e7a7809b665aa2517d078d50020ddc3b0868f11dc77e625ceb9e9712",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 07:40:13",
            "last_seen_utc": "2026-06-29 13:40:20",
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "BSC,ClearFake,ClickFix,EtherHiding,GoStealer",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839143": [
        {
            "ioc_value": "d18d2f76bc553fdecc640c00a548602979c0fcc281b5a626d394937951896822",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 07:40:13",
            "last_seen_utc": "2026-06-29 13:40:21",
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "BSC,ClearFake,ClickFix,EtherHiding,GoStealer",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839126": [
        {
            "ioc_value": "1fd793fc4db29dd42133cb20ea217f29b036d6d0a18d1753ebe56f4544537c32",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 07:40:12",
            "last_seen_utc": "2026-06-29 13:36:28",
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "BSC,ClearFake,ClickFix,EtherHiding,GoStealer",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839127": [
        {
            "ioc_value": "d92133d8434307a99c4c5bbbc905e65c330b38fe991fdcb5b14bd26f70333df9",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 07:40:12",
            "last_seen_utc": "2026-06-29 13:36:32",
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "BSC,ClearFake,ClickFix,EtherHiding,GoStealer",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839128": [
        {
            "ioc_value": "5071b6b49624a35b28f6cc66537be58e76daf2fa3de33a1b106bbd1c7c07561d",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 07:40:12",
            "last_seen_utc": "2026-06-29 13:36:33",
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "BSC,ClearFake,ClickFix,EtherHiding,GoStealer",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839129": [
        {
            "ioc_value": "b481fa88ec61057add0348646d4c703bf7ee3cfc3c98c8547371e6f3cd2ad0b9",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 07:40:12",
            "last_seen_utc": "2026-06-29 13:36:35",
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "BSC,ClearFake,ClickFix,EtherHiding,GoStealer",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839130": [
        {
            "ioc_value": "d0ab588b2b93e141b7dc39722f92711dd2de0ae5ad0e764f957ba01f92155820",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 07:40:12",
            "last_seen_utc": "2026-06-29 13:36:37",
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "BSC,ClearFake,ClickFix,EtherHiding,GoStealer",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839131": [
        {
            "ioc_value": "cd94f3a58d58d6c3e5c317fae03cc845d2368c42dba736386c1699c4c157d7f3",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 07:40:12",
            "last_seen_utc": "2026-06-29 13:39:57",
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "BSC,ClearFake,ClickFix,EtherHiding,GoStealer",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839132": [
        {
            "ioc_value": "9623feb7944da035d38aa653477951b809b4a1c2f6500cd20dd0492889b776f8",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 07:40:12",
            "last_seen_utc": "2026-06-29 13:39:59",
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "BSC,ClearFake,ClickFix,EtherHiding,GoStealer",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839133": [
        {
            "ioc_value": "8aaed4d47ae246059967342ee86a0420793c5751dcf86730e8800f31e26ec866",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 07:40:12",
            "last_seen_utc": "2026-06-29 13:40:00",
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "BSC,ClearFake,ClickFix,EtherHiding,GoStealer",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839134": [
        {
            "ioc_value": "c43c3397154a1f2d89b34cc4122842c2abbfeab139486e55e1e2b71b978959cf",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 07:40:12",
            "last_seen_utc": "2026-06-29 13:40:02",
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "BSC,ClearFake,ClickFix,EtherHiding,GoStealer",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839119": [
        {
            "ioc_value": "9afbc96639fa400657630e2a3cf4e021a0ab685215b18a03b808e9f27f19fac7",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 07:40:11",
            "last_seen_utc": "2026-06-29 13:36:15",
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "BSC,ClearFake,ClickFix,EtherHiding,GoStealer",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839120": [
        {
            "ioc_value": "55abd984d38cf05764b4c7ac4d636dfb827a379be7c975aae6d0a88d545fdf25",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 07:40:11",
            "last_seen_utc": "2026-06-29 13:36:17",
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "BSC,ClearFake,ClickFix,EtherHiding,GoStealer",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839121": [
        {
            "ioc_value": "7448dccda7b3a82c715869498870f0d0216b31f015fc1324aadf73636a9f0af1",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 07:40:11",
            "last_seen_utc": "2026-06-29 13:36:19",
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "BSC,ClearFake,ClickFix,EtherHiding,GoStealer",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839122": [
        {
            "ioc_value": "876f875e31e95dfc8b592594f17e6da1a271293de61fade030ea679b815ca817",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 07:40:11",
            "last_seen_utc": "2026-06-29 13:36:22",
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "BSC,ClearFake,ClickFix,EtherHiding,GoStealer",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839123": [
        {
            "ioc_value": "f95432faa54a492129454056a396b4b31b5211899d0f9611bee7189661ca3188",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 07:40:11",
            "last_seen_utc": "2026-06-29 13:36:23",
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "BSC,ClearFake,ClickFix,EtherHiding,GoStealer",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839124": [
        {
            "ioc_value": "3ed8020622796f70bdf3c16de772b8b45bb542f0af0d9fb639b1513c5c722b53",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 07:40:11",
            "last_seen_utc": "2026-06-29 13:36:25",
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "BSC,ClearFake,ClickFix,EtherHiding,GoStealer",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839125": [
        {
            "ioc_value": "3e2820527d8eb9a5396cc533f976a929ceb016168a5bce6150fc3ba061e04218",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 07:40:11",
            "last_seen_utc": "2026-06-29 13:36:27",
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "BSC,ClearFake,ClickFix,EtherHiding,GoStealer",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839111": [
        {
            "ioc_value": "4d24fab4342c0b19a2ea0d0ca36392f4053331ce57deeb7115eb34aeb35313ca",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 07:40:10",
            "last_seen_utc": "2026-06-29 13:35:58",
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "BSC,ClearFake,ClickFix,EtherHiding,GoStealer",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839112": [
        {
            "ioc_value": "6b3f8442d21103d11bb232c3dfb1dcbac8c576f3e4094c0542baed6b3e4fb657",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 07:40:10",
            "last_seen_utc": "2026-06-29 13:35:59",
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "BSC,ClearFake,ClickFix,EtherHiding,GoStealer",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839113": [
        {
            "ioc_value": "75c3961a5e1e88b1d8599111df547fe8bec37388eede78f121568417de635ffb",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 07:40:10",
            "last_seen_utc": "2026-06-29 13:36:01",
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "BSC,ClearFake,ClickFix,EtherHiding,GoStealer",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839114": [
        {
            "ioc_value": "8bfc5d83dd86d69937a22a091d8aacafbbf0fa7f0c7faa34674fccb1e5b6b657",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 07:40:10",
            "last_seen_utc": "2026-06-29 13:36:04",
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "BSC,ClearFake,ClickFix,EtherHiding,GoStealer",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839115": [
        {
            "ioc_value": "4004d3a14a3c7810c44b363927adea33cd55f4a28f6f0baacd937021fc8ed563",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 07:40:10",
            "last_seen_utc": "2026-06-29 13:36:07",
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "BSC,ClearFake,ClickFix,EtherHiding,GoStealer",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839116": [
        {
            "ioc_value": "6103c24bf10fa4e282d27d63c38934d66bf999b81eb880b9e5761da6496dd575",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 07:40:10",
            "last_seen_utc": "2026-06-29 13:36:08",
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "BSC,ClearFake,ClickFix,EtherHiding,GoStealer",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839117": [
        {
            "ioc_value": "efa24e6d66c558ef12539fbf615c8a607181e676b4da98e96203910fb9cc0e61",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 07:40:10",
            "last_seen_utc": "2026-06-29 13:36:10",
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "BSC,ClearFake,ClickFix,EtherHiding,GoStealer",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839118": [
        {
            "ioc_value": "af387603dc23f60d2bcd1269e6a1b18f4dceb90575f44b15b36e9c04170f14c8",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 07:40:10",
            "last_seen_utc": "2026-06-29 13:36:12",
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "BSC,ClearFake,ClickFix,EtherHiding,GoStealer",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839103": [
        {
            "ioc_value": "02e0fb035d480b199f0f2173ed4a8a7b8d6b8340bda05a2af7a20b166a716fe0",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 07:40:09",
            "last_seen_utc": "2026-06-29 13:35:41",
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "BSC,ClearFake,ClickFix,EtherHiding,GoStealer",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839104": [
        {
            "ioc_value": "18338778e3114e19b28f64e4c1bf9d4ccf0cfc4b2783b46b86862fb6bab12a80",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 07:40:09",
            "last_seen_utc": "2026-06-29 13:35:43",
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "BSC,ClearFake,ClickFix,EtherHiding,GoStealer",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839105": [
        {
            "ioc_value": "201c5e3d0a94d4ebe356e8280f430f87bdf6d04d8116aac59e04d7ee3951bae5",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 07:40:09",
            "last_seen_utc": "2026-06-29 13:35:46",
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "BSC,ClearFake,ClickFix,EtherHiding,GoStealer",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839106": [
        {
            "ioc_value": "627867b7897597d74d64f2f722771b87df1796f8a7e7bbff2e0941d25da96a87",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 07:40:09",
            "last_seen_utc": "2026-06-29 13:35:48",
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "BSC,ClearFake,ClickFix,EtherHiding,GoStealer",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839107": [
        {
            "ioc_value": "a2009f634a5dec6911655bb282d95487bf53100a72c70a62e56044a31594aefd",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 07:40:09",
            "last_seen_utc": "2026-06-29 13:35:49",
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "BSC,ClearFake,ClickFix,EtherHiding,GoStealer",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839108": [
        {
            "ioc_value": "425607e394b6da612043b6d91e485c3c4b12910af1c27c1df41397b59d832096",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 07:40:09",
            "last_seen_utc": "2026-06-29 13:35:51",
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "BSC,ClearFake,ClickFix,EtherHiding,GoStealer",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839109": [
        {
            "ioc_value": "e021ef11104505f017fad54273c00d29bf87f537dd102c6fc2f519f8bc6e3f64",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 07:40:09",
            "last_seen_utc": "2026-06-29 13:35:53",
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "BSC,ClearFake,ClickFix,EtherHiding,GoStealer",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839110": [
        {
            "ioc_value": "7c8f07dabe3eedee00f7de27fabc5689b699ea7c932c9c29bde9f5c3e59f9fd7",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 07:40:09",
            "last_seen_utc": "2026-06-29 13:35:54",
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "BSC,ClearFake,ClickFix,EtherHiding,GoStealer",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839095": [
        {
            "ioc_value": "cdc845c61341126fa2a784dfc27a11eef47d05cc323530be7b7a4515d202d838",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 07:40:08",
            "last_seen_utc": "2026-06-29 13:35:25",
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "BSC,ClearFake,ClickFix,EtherHiding,GoStealer",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839096": [
        {
            "ioc_value": "f62af451ebc1e8ef181d022bdcd25af8d152fa0fc8e408eb610d4075efa1e02f",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 07:40:08",
            "last_seen_utc": "2026-06-29 13:35:26",
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "BSC,ClearFake,ClickFix,EtherHiding,GoStealer",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839097": [
        {
            "ioc_value": "d246a63fcffa767c9407a4090489db5986233c63c79f79292ae6e0715673ddad",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 07:40:08",
            "last_seen_utc": "2026-06-29 13:35:30",
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "BSC,ClearFake,ClickFix,EtherHiding,GoStealer",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839098": [
        {
            "ioc_value": "039d75c7bfe0c3917aba98362c636198eafea3f93e4760796abbcd84c2c7e3d1",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 07:40:08",
            "last_seen_utc": "2026-06-29 13:35:31",
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "BSC,ClearFake,ClickFix,EtherHiding,GoStealer",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839099": [
        {
            "ioc_value": "e1287b14eaa142e26a4bb988d8e3431c80d0ffc4401810c07b0d954960738e0f",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 07:40:08",
            "last_seen_utc": "2026-06-29 13:35:33",
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "BSC,ClearFake,ClickFix,EtherHiding,GoStealer",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839100": [
        {
            "ioc_value": "3f18be9db505a0ee69a528269e8bbe2f85cf2116ca465d8f618946013f4bedee",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 07:40:08",
            "last_seen_utc": "2026-06-29 13:35:35",
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "BSC,ClearFake,ClickFix,EtherHiding,GoStealer",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839101": [
        {
            "ioc_value": "80d4451d914a701e293e643ed33ec53c47b0692793c4d7e1a00368170c5cd739",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 07:40:08",
            "last_seen_utc": "2026-06-29 13:35:38",
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "BSC,ClearFake,ClickFix,EtherHiding,GoStealer",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839102": [
        {
            "ioc_value": "c0ac7be40b90efa93340d26787074f5ba40f02762039bdc84d8778419fb8bf46",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 07:40:08",
            "last_seen_utc": "2026-06-29 13:35:39",
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "BSC,ClearFake,ClickFix,EtherHiding,GoStealer",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839088": [
        {
            "ioc_value": "a580e434ed06f2bd779c0e6674a0ff31b69a6aaa5f908d95564b17e23bcb714d",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 07:40:07",
            "last_seen_utc": "2026-06-29 13:35:11",
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "BSC,ClearFake,ClickFix,EtherHiding,GoStealer",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839089": [
        {
            "ioc_value": "058e9c0b3c714b83e131d4990ac5199ee5622ef92dc5d7503f6eaffadb3347a4",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 07:40:07",
            "last_seen_utc": "2026-06-29 13:35:13",
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "BSC,ClearFake,ClickFix,EtherHiding,GoStealer",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839090": [
        {
            "ioc_value": "19d2c2c8f842d70bdd8a9b91ed168e45fbb9a0e3587027e863b3df051f4d3a82",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 07:40:07",
            "last_seen_utc": "2026-06-29 13:35:15",
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "BSC,ClearFake,ClickFix,EtherHiding,GoStealer",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839091": [
        {
            "ioc_value": "6433b5122e362359e61c61ff2a35b885a229fc41d4d9a942be169f711f81173e",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 07:40:07",
            "last_seen_utc": "2026-06-29 13:35:17",
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "BSC,ClearFake,ClickFix,EtherHiding,GoStealer",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839092": [
        {
            "ioc_value": "25009746f1960f36bf2efdea616a087c1cbe8cc00e88d6e5a562e76bfc2e2ec5",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 07:40:07",
            "last_seen_utc": "2026-06-29 13:35:20",
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "BSC,ClearFake,ClickFix,EtherHiding,GoStealer",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839093": [
        {
            "ioc_value": "fd79ca089f7fef7acb21457cde1056c09d36c1fabea56b6333c61171363d320a",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 07:40:07",
            "last_seen_utc": "2026-06-29 13:35:21",
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "BSC,ClearFake,ClickFix,EtherHiding,GoStealer",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839094": [
        {
            "ioc_value": "f943eb5158841d992932c2502e0075eff351cbd368922e9ab256827c4b707c9f",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 07:40:07",
            "last_seen_utc": "2026-06-29 13:35:23",
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "BSC,ClearFake,ClickFix,EtherHiding,GoStealer",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839087": [
        {
            "ioc_value": "22439bc9a2b6716ae7eb5c1aaa9f3ff3ff91cefcbfe27b52763546861121adbc",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 07:40:06",
            "last_seen_utc": "2026-06-29 13:35:08",
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "BSC,ClearFake,ClickFix,EtherHiding,GoStealer",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839084": [
        {
            "ioc_value": "qiuy.org",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 07:40:04",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "BSC,ClearFake,ClickFix,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839085": [
        {
            "ioc_value": "abt90shart.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 07:40:04",
            "last_seen_utc": "2026-06-29 13:50:39",
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "BSC,ClearFake,ClickFix,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839086": [
        {
            "ioc_value": "yekshart.app",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 07:40:04",
            "last_seen_utc": "2026-06-29 13:49:36",
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "BSC,ClearFake,ClickFix,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839083": [
        {
            "ioc_value": "1xbet.sex",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 07:40:03",
            "last_seen_utc": "2026-06-29 13:35:10",
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "BSC,ClearFake,ClickFix,EtherHiding",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839081": [
        {
            "ioc_value": "https://rpc-cloud.beer/api/",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 07:24:11",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding,Polygon,Stealer",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1839080": [
        {
            "ioc_value": "38.190.224.61:8082",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-06-29 07:05:07",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "cobaltstrike",
            "anonymous": "1",
            "reporter": "_ik_"
        }
    ],
    "1839079": [
        {
            "ioc_value": "34.181.236.49:8808",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-06-29 07:05:06",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "asyncrat",
            "anonymous": "1",
            "reporter": "_ik_"
        }
    ],
    "1839078": [
        {
            "ioc_value": "154.94.233.166:60000",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-06-29 07:05:05",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "viper",
            "anonymous": "1",
            "reporter": "_ik_"
        }
    ],
    "1839070": [
        {
            "ioc_value": "http://103.26.86.217:52895/Mozi.a",
            "ioc_type": "url",
            "threat_type": "payload_delivery",
            "malware": "elf.mozi",
            "malware_alias": null,
            "malware_printable": "Mozi",
            "first_seen_utc": "2026-06-29 06:43:58",
            "last_seen_utc": null,
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://honeylabs.net/lookup/103.26.86.217",
            "tags": "elf,iot,Mozi",
            "anonymous": "0",
            "reporter": "HoneyLabs"
        }
    ],
    "1839071": [
        {
            "ioc_value": "http://103.213.112.214:49082/Mozi.m",
            "ioc_type": "url",
            "threat_type": "payload_delivery",
            "malware": "elf.mozi",
            "malware_alias": null,
            "malware_printable": "Mozi",
            "first_seen_utc": "2026-06-29 06:43:57",
            "last_seen_utc": null,
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://honeylabs.net/lookup/103.213.112.214",
            "tags": "elf,iot,Mozi",
            "anonymous": "0",
            "reporter": "HoneyLabs"
        }
    ],
    "1839072": [
        {
            "ioc_value": "settra5ldqwgtw5q7z5awbsvlksakyfojuc5slgrz5lvapune4fantqd.onion",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-06-29 06:43:57",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://github.com/TheRavenFile/Daily-Hunt/blob/main/Settra%20Ransomware",
            "tags": "ransomware,settra",
            "anonymous": "0",
            "reporter": "TheRavenFile"
        }
    ],
    "1839073": [
        {
            "ioc_value": "pbxvml6h3wz35qlr5muy2cg5jvjsd4qhjlsztmxj4lqkyohnfdrntqyd.onion",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-06-29 06:43:57",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://github.com/TheRavenFile/Daily-Hunt/blob/main/Settra%20Ransomware",
            "tags": "ransomware,settra",
            "anonymous": "0",
            "reporter": "TheRavenFile"
        }
    ],
    "1839074": [
        {
            "ioc_value": "26z3gms2rshr2zzedxhw5fbucilmgt2inhmxzmuhteyztpxohoqplgyd.onion",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-06-29 06:43:57",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://github.com/TheRavenFile/Daily-Hunt/blob/main/Settra%20Ransomware",
            "tags": "ransomware,settra",
            "anonymous": "0",
            "reporter": "TheRavenFile"
        }
    ],
    "1839075": [
        {
            "ioc_value": "ttfy4zmtiaywfkkmykpxiwtlxkcr5ofvrhqgxxyspgwzbxkc3uze7jid.onion",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-06-29 06:43:56",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://github.com/TheRavenFile/Daily-Hunt/blob/main/Settra%20Ransomware",
            "tags": "ransomware,settra",
            "anonymous": "0",
            "reporter": "TheRavenFile"
        }
    ],
    "1839076": [
        {
            "ioc_value": "c3u3g7dz2yxkefci3x34jfvfa4gka4iogi4zfjkyxx2c536oqdld4kid.onion",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-06-29 06:43:56",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://github.com/TheRavenFile/Daily-Hunt/blob/main/Settra%20Ransomware",
            "tags": "ransomware,settra",
            "anonymous": "0",
            "reporter": "TheRavenFile"
        }
    ],
    "1839077": [
        {
            "ioc_value": "https://aheadsupport.co.uk/",
            "ioc_type": "url",
            "threat_type": "payload_delivery",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-06-29 06:43:55",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": "https://clickfix.carsonww.com/domains/aheadsupport.co.uk",
            "tags": "ClickFix",
            "anonymous": "0",
            "reporter": "CarsonWilliams"
        }
    ],
    "1839069": [
        {
            "ioc_value": "130.12.182.90:2404",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-06-29 06:10:48",
            "last_seen_utc": null,
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://bazaar.abuse.ch/sample/47c3f86cd33b11cb9c57df1f9ab4363eab0306e230936cbf45321b17c11fb012/",
            "tags": "remcos",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1839068": [
        {
            "ioc_value": "151.239.25.40:9090",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-06-29 06:05:04",
            "last_seen_utc": "2026-06-30 09:53:51",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "cobaltstrike",
            "anonymous": "1",
            "reporter": "_ik_"
        }
    ],
    "1838807": [
        {
            "ioc_value": "103.214.9.20:6379",
            "ioc_type": "ip:port",
            "threat_type": "payload_delivery",
            "malware": "elf.xmrig",
            "malware_alias": null,
            "malware_printable": "XMRIG",
            "first_seen_utc": "2026-06-29 05:55:21",
            "last_seen_utc": "2026-06-29 09:39:58",
            "confidence_level": 80,
            "is_compromised": false,
            "reference": "https://twitter.com/NullBlue67",
            "tags": "rce,redis",
            "anonymous": "0",
            "reporter": "nullblue67"
        }
    ],
    "1838808": [
        {
            "ioc_value": "116.162.216.223:6379",
            "ioc_type": "ip:port",
            "threat_type": "payload_delivery",
            "malware": "elf.xmrig",
            "malware_alias": null,
            "malware_printable": "XMRIG",
            "first_seen_utc": "2026-06-29 05:55:21",
            "last_seen_utc": null,
            "confidence_level": 80,
            "is_compromised": false,
            "reference": "https://twitter.com/NullBlue67",
            "tags": "rce,redis",
            "anonymous": "0",
            "reporter": "nullblue67"
        }
    ],
    "1838809": [
        {
            "ioc_value": "123.57.92.77:6379",
            "ioc_type": "ip:port",
            "threat_type": "payload_delivery",
            "malware": "elf.xmrig",
            "malware_alias": null,
            "malware_printable": "XMRIG",
            "first_seen_utc": "2026-06-29 05:55:20",
            "last_seen_utc": null,
            "confidence_level": 80,
            "is_compromised": false,
            "reference": "https://twitter.com/NullBlue67",
            "tags": "rce,redis",
            "anonymous": "0",
            "reporter": "nullblue67"
        }
    ],
    "1838810": [
        {
            "ioc_value": "134.122.1.61:6379",
            "ioc_type": "ip:port",
            "threat_type": "payload_delivery",
            "malware": "elf.xmrig",
            "malware_alias": null,
            "malware_printable": "XMRIG",
            "first_seen_utc": "2026-06-29 05:55:20",
            "last_seen_utc": "2026-06-29 09:40:01",
            "confidence_level": 80,
            "is_compromised": false,
            "reference": "https://twitter.com/NullBlue67",
            "tags": "rce,redis",
            "anonymous": "0",
            "reporter": "nullblue67"
        }
    ],
    "1838811": [
        {
            "ioc_value": "159.203.64.55:6379",
            "ioc_type": "ip:port",
            "threat_type": "payload_delivery",
            "malware": "elf.xmrig",
            "malware_alias": null,
            "malware_printable": "XMRIG",
            "first_seen_utc": "2026-06-29 05:55:19",
            "last_seen_utc": null,
            "confidence_level": 80,
            "is_compromised": false,
            "reference": "https://twitter.com/NullBlue67",
            "tags": "rce,redis",
            "anonymous": "0",
            "reporter": "nullblue67"
        }
    ],
    "1838812": [
        {
            "ioc_value": "159.89.172.54:6379",
            "ioc_type": "ip:port",
            "threat_type": "payload_delivery",
            "malware": "elf.xmrig",
            "malware_alias": null,
            "malware_printable": "XMRIG",
            "first_seen_utc": "2026-06-29 05:55:19",
            "last_seen_utc": null,
            "confidence_level": 80,
            "is_compromised": false,
            "reference": "https://twitter.com/NullBlue67",
            "tags": "rce,redis",
            "anonymous": "0",
            "reporter": "nullblue67"
        }
    ],
    "1838813": [
        {
            "ioc_value": "165.22.8.2:6379",
            "ioc_type": "ip:port",
            "threat_type": "payload_delivery",
            "malware": "elf.xmrig",
            "malware_alias": null,
            "malware_printable": "XMRIG",
            "first_seen_utc": "2026-06-29 05:55:18",
            "last_seen_utc": "2026-06-29 09:40:05",
            "confidence_level": 80,
            "is_compromised": false,
            "reference": "https://twitter.com/NullBlue67",
            "tags": "rce,redis",
            "anonymous": "0",
            "reporter": "nullblue67"
        }
    ],
    "1838816": [
        {
            "ioc_value": "188.166.154.126:6379",
            "ioc_type": "ip:port",
            "threat_type": "payload_delivery",
            "malware": "elf.xmrig",
            "malware_alias": null,
            "malware_printable": "XMRIG",
            "first_seen_utc": "2026-06-29 05:55:18",
            "last_seen_utc": null,
            "confidence_level": 80,
            "is_compromised": false,
            "reference": "https://twitter.com/NullBlue67",
            "tags": "rce,redis",
            "anonymous": "0",
            "reporter": "nullblue67"
        }
    ],
    "1838814": [
        {
            "ioc_value": "172.104.63.215:6379",
            "ioc_type": "ip:port",
            "threat_type": "payload_delivery",
            "malware": "elf.xmrig",
            "malware_alias": null,
            "malware_printable": "XMRIG",
            "first_seen_utc": "2026-06-29 05:55:17",
            "last_seen_utc": "2026-06-29 09:40:08",
            "confidence_level": 80,
            "is_compromised": false,
            "reference": "https://twitter.com/NullBlue67",
            "tags": "rce,redis",
            "anonymous": "0",
            "reporter": "nullblue67"
        }
    ],
    "1838815": [
        {
            "ioc_value": "174.138.39.122:6379",
            "ioc_type": "ip:port",
            "threat_type": "payload_delivery",
            "malware": "elf.xmrig",
            "malware_alias": null,
            "malware_printable": "XMRIG",
            "first_seen_utc": "2026-06-29 05:55:16",
            "last_seen_utc": null,
            "confidence_level": 80,
            "is_compromised": false,
            "reference": "https://twitter.com/NullBlue67",
            "tags": "rce,redis",
            "anonymous": "0",
            "reporter": "nullblue67"
        }
    ],
    "1838817": [
        {
            "ioc_value": "194.163.181.15:6379",
            "ioc_type": "ip:port",
            "threat_type": "payload_delivery",
            "malware": "elf.xmrig",
            "malware_alias": null,
            "malware_printable": "XMRIG",
            "first_seen_utc": "2026-06-29 05:55:15",
            "last_seen_utc": null,
            "confidence_level": 80,
            "is_compromised": false,
            "reference": "https://twitter.com/NullBlue67",
            "tags": "rce,redis",
            "anonymous": "0",
            "reporter": "nullblue67"
        }
    ],
    "1838818": [
        {
            "ioc_value": "213.136.84.163:6379",
            "ioc_type": "ip:port",
            "threat_type": "payload_delivery",
            "malware": "elf.xmrig",
            "malware_alias": null,
            "malware_printable": "XMRIG",
            "first_seen_utc": "2026-06-29 05:55:15",
            "last_seen_utc": null,
            "confidence_level": 80,
            "is_compromised": false,
            "reference": "https://twitter.com/NullBlue67",
            "tags": "rce,redis",
            "anonymous": "0",
            "reporter": "nullblue67"
        }
    ],
    "1838819": [
        {
            "ioc_value": "217.216.66.74:5432",
            "ioc_type": "ip:port",
            "threat_type": "payload_delivery",
            "malware": "elf.xmrig",
            "malware_alias": null,
            "malware_printable": "XMRIG",
            "first_seen_utc": "2026-06-29 05:55:14",
            "last_seen_utc": "2026-06-29 09:40:22",
            "confidence_level": 80,
            "is_compromised": false,
            "reference": "https://twitter.com/NullBlue67",
            "tags": "postgres,takeover",
            "anonymous": "0",
            "reporter": "nullblue67"
        }
    ],
    "1838820": [
        {
            "ioc_value": "185.76.9.35:5432",
            "ioc_type": "ip:port",
            "threat_type": "payload_delivery",
            "malware": "elf.xmrig",
            "malware_alias": null,
            "malware_printable": "XMRIG",
            "first_seen_utc": "2026-06-29 05:55:14",
            "last_seen_utc": "2026-06-29 09:40:20",
            "confidence_level": 80,
            "is_compromised": false,
            "reference": "https://twitter.com/NullBlue67",
            "tags": "postgres,takeover",
            "anonymous": "0",
            "reporter": "nullblue67"
        }
    ],
    "1838821": [
        {
            "ioc_value": "23.234.72.111:5432",
            "ioc_type": "ip:port",
            "threat_type": "payload_delivery",
            "malware": "elf.xmrig",
            "malware_alias": null,
            "malware_printable": "XMRIG",
            "first_seen_utc": "2026-06-29 05:55:13",
            "last_seen_utc": null,
            "confidence_level": 80,
            "is_compromised": false,
            "reference": "https://twitter.com/NullBlue67",
            "tags": "postgres,takeover",
            "anonymous": "0",
            "reporter": "nullblue67"
        }
    ],
    "1838822": [
        {
            "ioc_value": "139.59.67.197:5432",
            "ioc_type": "ip:port",
            "threat_type": "payload_delivery",
            "malware": "elf.xmrig",
            "malware_alias": null,
            "malware_printable": "XMRIG",
            "first_seen_utc": "2026-06-29 05:55:13",
            "last_seen_utc": "2026-06-29 09:40:18",
            "confidence_level": 80,
            "is_compromised": false,
            "reference": "https://twitter.com/NullBlue67",
            "tags": "postgres,takeover",
            "anonymous": "0",
            "reporter": "nullblue67"
        }
    ],
    "1838823": [
        {
            "ioc_value": "138.199.15.161:5432",
            "ioc_type": "ip:port",
            "threat_type": "payload_delivery",
            "malware": "elf.xmrig",
            "malware_alias": null,
            "malware_printable": "XMRIG",
            "first_seen_utc": "2026-06-29 05:55:13",
            "last_seen_utc": null,
            "confidence_level": 80,
            "is_compromised": false,
            "reference": "https://twitter.com/NullBlue67",
            "tags": "postgres,takeover",
            "anonymous": "0",
            "reporter": "nullblue67"
        }
    ],
    "1838824": [
        {
            "ioc_value": "104.207.47.232:2375",
            "ioc_type": "ip:port",
            "threat_type": "payload_delivery",
            "malware": "elf.redtail",
            "malware_alias": null,
            "malware_printable": "RedTail",
            "first_seen_utc": "2026-06-29 05:55:12",
            "last_seen_utc": null,
            "confidence_level": 80,
            "is_compromised": false,
            "reference": "https://twitter.com/NullBlue67",
            "tags": "docker-api",
            "anonymous": "0",
            "reporter": "nullblue67"
        }
    ],
    "1838825": [
        {
            "ioc_value": "104.207.59.109:2375",
            "ioc_type": "ip:port",
            "threat_type": "payload_delivery",
            "malware": "elf.redtail",
            "malware_alias": null,
            "malware_printable": "RedTail",
            "first_seen_utc": "2026-06-29 05:55:12",
            "last_seen_utc": null,
            "confidence_level": 80,
            "is_compromised": false,
            "reference": "https://twitter.com/NullBlue67",
            "tags": "docker-api",
            "anonymous": "0",
            "reporter": "nullblue67"
        }
    ],
    "1838826": [
        {
            "ioc_value": "109.91.201.209:2375",
            "ioc_type": "ip:port",
            "threat_type": "payload_delivery",
            "malware": "elf.redtail",
            "malware_alias": null,
            "malware_printable": "RedTail",
            "first_seen_utc": "2026-06-29 05:55:11",
            "last_seen_utc": null,
            "confidence_level": 80,
            "is_compromised": false,
            "reference": "https://twitter.com/NullBlue67",
            "tags": "docker-api",
            "anonymous": "0",
            "reporter": "nullblue67"
        }
    ],
    "1838828": [
        {
            "ioc_value": "159.195.76.136:2375",
            "ioc_type": "ip:port",
            "threat_type": "payload_delivery",
            "malware": "elf.redtail",
            "malware_alias": null,
            "malware_printable": "RedTail",
            "first_seen_utc": "2026-06-29 05:55:11",
            "last_seen_utc": null,
            "confidence_level": 80,
            "is_compromised": false,
            "reference": "https://twitter.com/NullBlue67",
            "tags": "docker-api",
            "anonymous": "0",
            "reporter": "nullblue67"
        }
    ],
    "1838827": [
        {
            "ioc_value": "157.245.123.148:2375",
            "ioc_type": "ip:port",
            "threat_type": "payload_delivery",
            "malware": "elf.redtail",
            "malware_alias": null,
            "malware_printable": "RedTail",
            "first_seen_utc": "2026-06-29 05:55:10",
            "last_seen_utc": null,
            "confidence_level": 80,
            "is_compromised": false,
            "reference": "https://twitter.com/NullBlue67",
            "tags": "docker-api",
            "anonymous": "0",
            "reporter": "nullblue67"
        }
    ],
    "1838829": [
        {
            "ioc_value": "162.227.109.103:2375",
            "ioc_type": "ip:port",
            "threat_type": "payload_delivery",
            "malware": "elf.redtail",
            "malware_alias": null,
            "malware_printable": "RedTail",
            "first_seen_utc": "2026-06-29 05:55:08",
            "last_seen_utc": null,
            "confidence_level": 80,
            "is_compromised": false,
            "reference": "https://twitter.com/NullBlue67",
            "tags": "docker-api",
            "anonymous": "0",
            "reporter": "nullblue67"
        }
    ],
    "1838830": [
        {
            "ioc_value": "169.150.201.135:2375",
            "ioc_type": "ip:port",
            "threat_type": "payload_delivery",
            "malware": "elf.redtail",
            "malware_alias": null,
            "malware_printable": "RedTail",
            "first_seen_utc": "2026-06-29 05:55:08",
            "last_seen_utc": null,
            "confidence_level": 80,
            "is_compromised": false,
            "reference": "https://twitter.com/NullBlue67",
            "tags": "docker-api",
            "anonymous": "0",
            "reporter": "nullblue67"
        }
    ],
    "1838831": [
        {
            "ioc_value": "172.185.40.47:2375",
            "ioc_type": "ip:port",
            "threat_type": "payload_delivery",
            "malware": "elf.redtail",
            "malware_alias": null,
            "malware_printable": "RedTail",
            "first_seen_utc": "2026-06-29 05:55:07",
            "last_seen_utc": null,
            "confidence_level": 80,
            "is_compromised": false,
            "reference": "https://twitter.com/NullBlue67",
            "tags": "docker-api",
            "anonymous": "0",
            "reporter": "nullblue67"
        }
    ],
    "1838832": [
        {
            "ioc_value": "172.202.118.46:2375",
            "ioc_type": "ip:port",
            "threat_type": "payload_delivery",
            "malware": "elf.redtail",
            "malware_alias": null,
            "malware_printable": "RedTail",
            "first_seen_utc": "2026-06-29 05:55:07",
            "last_seen_utc": null,
            "confidence_level": 80,
            "is_compromised": false,
            "reference": "https://twitter.com/NullBlue67",
            "tags": "docker-api",
            "anonymous": "0",
            "reporter": "nullblue67"
        }
    ],
    "1838833": [
        {
            "ioc_value": "173.177.131.92:2375",
            "ioc_type": "ip:port",
            "threat_type": "payload_delivery",
            "malware": "elf.redtail",
            "malware_alias": null,
            "malware_printable": "RedTail",
            "first_seen_utc": "2026-06-29 05:55:06",
            "last_seen_utc": null,
            "confidence_level": 80,
            "is_compromised": false,
            "reference": "https://twitter.com/NullBlue67",
            "tags": "docker-api",
            "anonymous": "0",
            "reporter": "nullblue67"
        }
    ],
    "1838834": [
        {
            "ioc_value": "174.170.194.116:2375",
            "ioc_type": "ip:port",
            "threat_type": "payload_delivery",
            "malware": "elf.redtail",
            "malware_alias": null,
            "malware_printable": "RedTail",
            "first_seen_utc": "2026-06-29 05:55:06",
            "last_seen_utc": null,
            "confidence_level": 80,
            "is_compromised": false,
            "reference": "https://twitter.com/NullBlue67",
            "tags": "docker-api",
            "anonymous": "0",
            "reporter": "nullblue67"
        }
    ],
    "1838835": [
        {
            "ioc_value": "174.18.49.143:2375",
            "ioc_type": "ip:port",
            "threat_type": "payload_delivery",
            "malware": "elf.redtail",
            "malware_alias": null,
            "malware_printable": "RedTail",
            "first_seen_utc": "2026-06-29 05:55:05",
            "last_seen_utc": null,
            "confidence_level": 80,
            "is_compromised": false,
            "reference": "https://twitter.com/NullBlue67",
            "tags": "docker-api",
            "anonymous": "0",
            "reporter": "nullblue67"
        }
    ],
    "1838836": [
        {
            "ioc_value": "176.144.233.36:2375",
            "ioc_type": "ip:port",
            "threat_type": "payload_delivery",
            "malware": "elf.redtail",
            "malware_alias": null,
            "malware_printable": "RedTail",
            "first_seen_utc": "2026-06-29 05:55:04",
            "last_seen_utc": null,
            "confidence_level": 80,
            "is_compromised": false,
            "reference": "https://twitter.com/NullBlue67",
            "tags": "docker-api",
            "anonymous": "0",
            "reporter": "nullblue67"
        }
    ],
    "1838837": [
        {
            "ioc_value": "176.146.33.242:2375",
            "ioc_type": "ip:port",
            "threat_type": "payload_delivery",
            "malware": "elf.redtail",
            "malware_alias": null,
            "malware_printable": "RedTail",
            "first_seen_utc": "2026-06-29 05:54:39",
            "last_seen_utc": null,
            "confidence_level": 80,
            "is_compromised": false,
            "reference": "https://twitter.com/NullBlue67",
            "tags": "docker-api",
            "anonymous": "0",
            "reporter": "nullblue67"
        }
    ],
    "1838838": [
        {
            "ioc_value": "178.26.11.44:2375",
            "ioc_type": "ip:port",
            "threat_type": "payload_delivery",
            "malware": "elf.redtail",
            "malware_alias": null,
            "malware_printable": "RedTail",
            "first_seen_utc": "2026-06-29 05:54:38",
            "last_seen_utc": null,
            "confidence_level": 80,
            "is_compromised": false,
            "reference": "https://twitter.com/NullBlue67",
            "tags": "docker-api",
            "anonymous": "0",
            "reporter": "nullblue67"
        }
    ],
    "1838839": [
        {
            "ioc_value": "185.214.96.150:2375",
            "ioc_type": "ip:port",
            "threat_type": "payload_delivery",
            "malware": "elf.redtail",
            "malware_alias": null,
            "malware_printable": "RedTail",
            "first_seen_utc": "2026-06-29 05:54:38",
            "last_seen_utc": null,
            "confidence_level": 80,
            "is_compromised": false,
            "reference": "https://twitter.com/NullBlue67",
            "tags": "docker-api",
            "anonymous": "0",
            "reporter": "nullblue67"
        }
    ],
    "1838840": [
        {
            "ioc_value": "191.44.125.4:2375",
            "ioc_type": "ip:port",
            "threat_type": "payload_delivery",
            "malware": "elf.redtail",
            "malware_alias": null,
            "malware_printable": "RedTail",
            "first_seen_utc": "2026-06-29 05:54:37",
            "last_seen_utc": null,
            "confidence_level": 80,
            "is_compromised": false,
            "reference": "https://twitter.com/NullBlue67",
            "tags": "docker-api",
            "anonymous": "0",
            "reporter": "nullblue67"
        }
    ],
    "1838841": [
        {
            "ioc_value": "191.44.71.181:2375",
            "ioc_type": "ip:port",
            "threat_type": "payload_delivery",
            "malware": "elf.redtail",
            "malware_alias": null,
            "malware_printable": "RedTail",
            "first_seen_utc": "2026-06-29 05:54:37",
            "last_seen_utc": null,
            "confidence_level": 80,
            "is_compromised": false,
            "reference": "https://twitter.com/NullBlue67",
            "tags": "docker-api",
            "anonymous": "0",
            "reporter": "nullblue67"
        }
    ],
    "1838842": [
        {
            "ioc_value": "191.44.71.39:2375",
            "ioc_type": "ip:port",
            "threat_type": "payload_delivery",
            "malware": "elf.redtail",
            "malware_alias": null,
            "malware_printable": "RedTail",
            "first_seen_utc": "2026-06-29 05:54:36",
            "last_seen_utc": null,
            "confidence_level": 80,
            "is_compromised": false,
            "reference": "https://twitter.com/NullBlue67",
            "tags": "docker-api",
            "anonymous": "0",
            "reporter": "nullblue67"
        }
    ],
    "1838843": [
        {
            "ioc_value": "191.44.91.71:2375",
            "ioc_type": "ip:port",
            "threat_type": "payload_delivery",
            "malware": "elf.redtail",
            "malware_alias": null,
            "malware_printable": "RedTail",
            "first_seen_utc": "2026-06-29 05:54:36",
            "last_seen_utc": null,
            "confidence_level": 80,
            "is_compromised": false,
            "reference": "https://twitter.com/NullBlue67",
            "tags": "docker-api",
            "anonymous": "0",
            "reporter": "nullblue67"
        }
    ],
    "1838844": [
        {
            "ioc_value": "2.15.88.196:2375",
            "ioc_type": "ip:port",
            "threat_type": "payload_delivery",
            "malware": "elf.redtail",
            "malware_alias": null,
            "malware_printable": "RedTail",
            "first_seen_utc": "2026-06-29 05:54:36",
            "last_seen_utc": null,
            "confidence_level": 80,
            "is_compromised": false,
            "reference": "https://twitter.com/NullBlue67",
            "tags": "docker-api",
            "anonymous": "0",
            "reporter": "nullblue67"
        }
    ],
    "1838845": [
        {
            "ioc_value": "20.102.108.84:2375",
            "ioc_type": "ip:port",
            "threat_type": "payload_delivery",
            "malware": "elf.redtail",
            "malware_alias": null,
            "malware_printable": "RedTail",
            "first_seen_utc": "2026-06-29 05:54:34",
            "last_seen_utc": null,
            "confidence_level": 80,
            "is_compromised": false,
            "reference": "https://twitter.com/NullBlue67",
            "tags": "docker-api",
            "anonymous": "0",
            "reporter": "nullblue67"
        }
    ],
    "1838846": [
        {
            "ioc_value": "209.50.168.38:2375",
            "ioc_type": "ip:port",
            "threat_type": "payload_delivery",
            "malware": "elf.redtail",
            "malware_alias": null,
            "malware_printable": "RedTail",
            "first_seen_utc": "2026-06-29 05:54:33",
            "last_seen_utc": null,
            "confidence_level": 80,
            "is_compromised": false,
            "reference": "https://twitter.com/NullBlue67",
            "tags": "docker-api",
            "anonymous": "0",
            "reporter": "nullblue67"
        }
    ],
    "1838847": [
        {
            "ioc_value": "217.253.14.112:2375",
            "ioc_type": "ip:port",
            "threat_type": "payload_delivery",
            "malware": "elf.redtail",
            "malware_alias": null,
            "malware_printable": "RedTail",
            "first_seen_utc": "2026-06-29 05:54:33",
            "last_seen_utc": null,
            "confidence_level": 80,
            "is_compromised": false,
            "reference": "https://twitter.com/NullBlue67",
            "tags": "docker-api",
            "anonymous": "0",
            "reporter": "nullblue67"
        }
    ],
    "1838848": [
        {
            "ioc_value": "217.253.208.240:2375",
            "ioc_type": "ip:port",
            "threat_type": "payload_delivery",
            "malware": "elf.redtail",
            "malware_alias": null,
            "malware_printable": "RedTail",
            "first_seen_utc": "2026-06-29 05:54:32",
            "last_seen_utc": null,
            "confidence_level": 80,
            "is_compromised": false,
            "reference": "https://twitter.com/NullBlue67",
            "tags": "docker-api",
            "anonymous": "0",
            "reporter": "nullblue67"
        }
    ],
    "1838849": [
        {
            "ioc_value": "37.65.13.51:2375",
            "ioc_type": "ip:port",
            "threat_type": "payload_delivery",
            "malware": "elf.redtail",
            "malware_alias": null,
            "malware_printable": "RedTail",
            "first_seen_utc": "2026-06-29 05:54:32",
            "last_seen_utc": null,
            "confidence_level": 80,
            "is_compromised": false,
            "reference": "https://twitter.com/NullBlue67",
            "tags": "docker-api",
            "anonymous": "0",
            "reporter": "nullblue67"
        }
    ],
    "1838850": [
        {
            "ioc_value": "37.67.104.221:2375",
            "ioc_type": "ip:port",
            "threat_type": "payload_delivery",
            "malware": "elf.redtail",
            "malware_alias": null,
            "malware_printable": "RedTail",
            "first_seen_utc": "2026-06-29 05:54:32",
            "last_seen_utc": null,
            "confidence_level": 80,
            "is_compromised": false,
            "reference": "https://twitter.com/NullBlue67",
            "tags": "docker-api",
            "anonymous": "0",
            "reporter": "nullblue67"
        }
    ],
    "1838851": [
        {
            "ioc_value": "37.67.75.82:2375",
            "ioc_type": "ip:port",
            "threat_type": "payload_delivery",
            "malware": "elf.redtail",
            "malware_alias": null,
            "malware_printable": "RedTail",
            "first_seen_utc": "2026-06-29 05:54:31",
            "last_seen_utc": null,
            "confidence_level": 80,
            "is_compromised": false,
            "reference": "https://twitter.com/NullBlue67",
            "tags": "docker-api",
            "anonymous": "0",
            "reporter": "nullblue67"
        }
    ],
    "1838852": [
        {
            "ioc_value": "45.156.129.127:2375",
            "ioc_type": "ip:port",
            "threat_type": "payload_delivery",
            "malware": "elf.redtail",
            "malware_alias": null,
            "malware_printable": "RedTail",
            "first_seen_utc": "2026-06-29 05:54:31",
            "last_seen_utc": null,
            "confidence_level": 80,
            "is_compromised": false,
            "reference": "https://twitter.com/NullBlue67",
            "tags": "docker-api",
            "anonymous": "0",
            "reporter": "nullblue67"
        }
    ],
    "1838853": [
        {
            "ioc_value": "60.191.137.103:2375",
            "ioc_type": "ip:port",
            "threat_type": "payload_delivery",
            "malware": "elf.redtail",
            "malware_alias": null,
            "malware_printable": "RedTail",
            "first_seen_utc": "2026-06-29 05:54:30",
            "last_seen_utc": null,
            "confidence_level": 80,
            "is_compromised": false,
            "reference": "https://twitter.com/NullBlue67",
            "tags": "docker-api",
            "anonymous": "0",
            "reporter": "nullblue67"
        }
    ],
    "1838854": [
        {
            "ioc_value": "64.62.156.10:2375",
            "ioc_type": "ip:port",
            "threat_type": "payload_delivery",
            "malware": "elf.redtail",
            "malware_alias": null,
            "malware_printable": "RedTail",
            "first_seen_utc": "2026-06-29 05:54:30",
            "last_seen_utc": null,
            "confidence_level": 80,
            "is_compromised": false,
            "reference": "https://twitter.com/NullBlue67",
            "tags": "docker-api",
            "anonymous": "0",
            "reporter": "nullblue67"
        }
    ],
    "1838855": [
        {
            "ioc_value": "65.49.1.182:2375",
            "ioc_type": "ip:port",
            "threat_type": "payload_delivery",
            "malware": "elf.redtail",
            "malware_alias": null,
            "malware_printable": "RedTail",
            "first_seen_utc": "2026-06-29 05:54:29",
            "last_seen_utc": null,
            "confidence_level": 80,
            "is_compromised": false,
            "reference": "https://twitter.com/NullBlue67",
            "tags": "docker-api",
            "anonymous": "0",
            "reporter": "nullblue67"
        }
    ],
    "1838856": [
        {
            "ioc_value": "66.132.195.118:2375",
            "ioc_type": "ip:port",
            "threat_type": "payload_delivery",
            "malware": "elf.redtail",
            "malware_alias": null,
            "malware_printable": "RedTail",
            "first_seen_utc": "2026-06-29 05:54:29",
            "last_seen_utc": null,
            "confidence_level": 80,
            "is_compromised": false,
            "reference": "https://twitter.com/NullBlue67",
            "tags": "docker-api",
            "anonymous": "0",
            "reporter": "nullblue67"
        }
    ],
    "1838858": [
        {
            "ioc_value": "71.226.150.30:2375",
            "ioc_type": "ip:port",
            "threat_type": "payload_delivery",
            "malware": "elf.redtail",
            "malware_alias": null,
            "malware_printable": "RedTail",
            "first_seen_utc": "2026-06-29 05:54:28",
            "last_seen_utc": null,
            "confidence_level": 80,
            "is_compromised": false,
            "reference": "https://twitter.com/NullBlue67",
            "tags": "docker-api",
            "anonymous": "0",
            "reporter": "nullblue67"
        }
    ],
    "1838857": [
        {
            "ioc_value": "70.95.146.19:2375",
            "ioc_type": "ip:port",
            "threat_type": "payload_delivery",
            "malware": "elf.redtail",
            "malware_alias": null,
            "malware_printable": "RedTail",
            "first_seen_utc": "2026-06-29 05:54:27",
            "last_seen_utc": null,
            "confidence_level": 80,
            "is_compromised": false,
            "reference": "https://twitter.com/NullBlue67",
            "tags": "docker-api",
            "anonymous": "0",
            "reporter": "nullblue67"
        }
    ],
    "1838859": [
        {
            "ioc_value": "73.146.198.16:2375",
            "ioc_type": "ip:port",
            "threat_type": "payload_delivery",
            "malware": "elf.redtail",
            "malware_alias": null,
            "malware_printable": "RedTail",
            "first_seen_utc": "2026-06-29 05:54:25",
            "last_seen_utc": null,
            "confidence_level": 80,
            "is_compromised": false,
            "reference": "https://twitter.com/NullBlue67",
            "tags": "docker-api",
            "anonymous": "0",
            "reporter": "nullblue67"
        }
    ],
    "1838860": [
        {
            "ioc_value": "73.198.29.237:2375",
            "ioc_type": "ip:port",
            "threat_type": "payload_delivery",
            "malware": "elf.redtail",
            "malware_alias": null,
            "malware_printable": "RedTail",
            "first_seen_utc": "2026-06-29 05:54:25",
            "last_seen_utc": null,
            "confidence_level": 80,
            "is_compromised": false,
            "reference": "https://twitter.com/NullBlue67",
            "tags": "docker-api",
            "anonymous": "0",
            "reporter": "nullblue67"
        }
    ],
    "1838861": [
        {
            "ioc_value": "74.15.98.76:2375",
            "ioc_type": "ip:port",
            "threat_type": "payload_delivery",
            "malware": "elf.redtail",
            "malware_alias": null,
            "malware_printable": "RedTail",
            "first_seen_utc": "2026-06-29 05:54:25",
            "last_seen_utc": null,
            "confidence_level": 80,
            "is_compromised": false,
            "reference": "https://twitter.com/NullBlue67",
            "tags": "docker-api",
            "anonymous": "0",
            "reporter": "nullblue67"
        }
    ],
    "1838862": [
        {
            "ioc_value": "75.184.86.154:2375",
            "ioc_type": "ip:port",
            "threat_type": "payload_delivery",
            "malware": "elf.redtail",
            "malware_alias": null,
            "malware_printable": "RedTail",
            "first_seen_utc": "2026-06-29 05:54:24",
            "last_seen_utc": null,
            "confidence_level": 80,
            "is_compromised": false,
            "reference": "https://twitter.com/NullBlue67",
            "tags": "docker-api",
            "anonymous": "0",
            "reporter": "nullblue67"
        }
    ],
    "1838863": [
        {
            "ioc_value": "79.197.154.178:2375",
            "ioc_type": "ip:port",
            "threat_type": "payload_delivery",
            "malware": "elf.redtail",
            "malware_alias": null,
            "malware_printable": "RedTail",
            "first_seen_utc": "2026-06-29 05:54:24",
            "last_seen_utc": null,
            "confidence_level": 80,
            "is_compromised": false,
            "reference": "https://twitter.com/NullBlue67",
            "tags": "docker-api",
            "anonymous": "0",
            "reporter": "nullblue67"
        }
    ],
    "1839067": [
        {
            "ioc_value": "4cfyhd61.fagaheestedlali.xyz",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 05:54:24",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "clearfake",
            "anonymous": "1",
            "reporter": "ttakvam"
        }
    ],
    "1838864": [
        {
            "ioc_value": "80.134.27.93:2375",
            "ioc_type": "ip:port",
            "threat_type": "payload_delivery",
            "malware": "elf.redtail",
            "malware_alias": null,
            "malware_printable": "RedTail",
            "first_seen_utc": "2026-06-29 05:54:23",
            "last_seen_utc": null,
            "confidence_level": 80,
            "is_compromised": false,
            "reference": "https://twitter.com/NullBlue67",
            "tags": "docker-api",
            "anonymous": "0",
            "reporter": "nullblue67"
        }
    ],
    "1838865": [
        {
            "ioc_value": "82.226.177.82:2375",
            "ioc_type": "ip:port",
            "threat_type": "payload_delivery",
            "malware": "elf.redtail",
            "malware_alias": null,
            "malware_printable": "RedTail",
            "first_seen_utc": "2026-06-29 05:54:23",
            "last_seen_utc": null,
            "confidence_level": 80,
            "is_compromised": false,
            "reference": "https://twitter.com/NullBlue67",
            "tags": "docker-api",
            "anonymous": "0",
            "reporter": "nullblue67"
        }
    ],
    "1838866": [
        {
            "ioc_value": "85.217.140.1:2375",
            "ioc_type": "ip:port",
            "threat_type": "payload_delivery",
            "malware": "elf.redtail",
            "malware_alias": null,
            "malware_printable": "RedTail",
            "first_seen_utc": "2026-06-29 05:54:23",
            "last_seen_utc": null,
            "confidence_level": 80,
            "is_compromised": false,
            "reference": "https://twitter.com/NullBlue67",
            "tags": "docker-api",
            "anonymous": "0",
            "reporter": "nullblue67"
        }
    ],
    "1838867": [
        {
            "ioc_value": "85.217.140.9:2375",
            "ioc_type": "ip:port",
            "threat_type": "payload_delivery",
            "malware": "elf.redtail",
            "malware_alias": null,
            "malware_printable": "RedTail",
            "first_seen_utc": "2026-06-29 05:54:22",
            "last_seen_utc": null,
            "confidence_level": 80,
            "is_compromised": false,
            "reference": "https://twitter.com/NullBlue67",
            "tags": "docker-api",
            "anonymous": "0",
            "reporter": "nullblue67"
        }
    ],
    "1838868": [
        {
            "ioc_value": "87.160.124.215:2375",
            "ioc_type": "ip:port",
            "threat_type": "payload_delivery",
            "malware": "elf.redtail",
            "malware_alias": null,
            "malware_printable": "RedTail",
            "first_seen_utc": "2026-06-29 05:54:22",
            "last_seen_utc": null,
            "confidence_level": 80,
            "is_compromised": false,
            "reference": "https://twitter.com/NullBlue67",
            "tags": "docker-api",
            "anonymous": "0",
            "reporter": "nullblue67"
        }
    ],
    "1838869": [
        {
            "ioc_value": "88.151.33.203:2375",
            "ioc_type": "ip:port",
            "threat_type": "payload_delivery",
            "malware": "elf.redtail",
            "malware_alias": null,
            "malware_printable": "RedTail",
            "first_seen_utc": "2026-06-29 05:54:21",
            "last_seen_utc": null,
            "confidence_level": 80,
            "is_compromised": false,
            "reference": "https://twitter.com/NullBlue67",
            "tags": "docker-api",
            "anonymous": "0",
            "reporter": "nullblue67"
        }
    ],
    "1838870": [
        {
            "ioc_value": "88.162.196.213:2375",
            "ioc_type": "ip:port",
            "threat_type": "payload_delivery",
            "malware": "elf.redtail",
            "malware_alias": null,
            "malware_printable": "RedTail",
            "first_seen_utc": "2026-06-29 05:54:21",
            "last_seen_utc": null,
            "confidence_level": 80,
            "is_compromised": false,
            "reference": "https://twitter.com/NullBlue67",
            "tags": "docker-api",
            "anonymous": "0",
            "reporter": "nullblue67"
        }
    ],
    "1838871": [
        {
            "ioc_value": "88.168.217.152:2375",
            "ioc_type": "ip:port",
            "threat_type": "payload_delivery",
            "malware": "elf.redtail",
            "malware_alias": null,
            "malware_printable": "RedTail",
            "first_seen_utc": "2026-06-29 05:54:21",
            "last_seen_utc": null,
            "confidence_level": 80,
            "is_compromised": false,
            "reference": "https://twitter.com/NullBlue67",
            "tags": "docker-api",
            "anonymous": "0",
            "reporter": "nullblue67"
        }
    ],
    "1838872": [
        {
            "ioc_value": "88.170.161.23:2375",
            "ioc_type": "ip:port",
            "threat_type": "payload_delivery",
            "malware": "elf.redtail",
            "malware_alias": null,
            "malware_printable": "RedTail",
            "first_seen_utc": "2026-06-29 05:54:20",
            "last_seen_utc": null,
            "confidence_level": 80,
            "is_compromised": false,
            "reference": "https://twitter.com/NullBlue67",
            "tags": "docker-api",
            "anonymous": "0",
            "reporter": "nullblue67"
        }
    ],
    "1838873": [
        {
            "ioc_value": "89.92.248.142:2375",
            "ioc_type": "ip:port",
            "threat_type": "payload_delivery",
            "malware": "elf.redtail",
            "malware_alias": null,
            "malware_printable": "RedTail",
            "first_seen_utc": "2026-06-29 05:54:20",
            "last_seen_utc": null,
            "confidence_level": 80,
            "is_compromised": false,
            "reference": "https://twitter.com/NullBlue67",
            "tags": "docker-api",
            "anonymous": "0",
            "reporter": "nullblue67"
        }
    ],
    "1838874": [
        {
            "ioc_value": "90.114.76.109:2375",
            "ioc_type": "ip:port",
            "threat_type": "payload_delivery",
            "malware": "elf.redtail",
            "malware_alias": null,
            "malware_printable": "RedTail",
            "first_seen_utc": "2026-06-29 05:54:19",
            "last_seen_utc": null,
            "confidence_level": 80,
            "is_compromised": false,
            "reference": "https://twitter.com/NullBlue67",
            "tags": "docker-api",
            "anonymous": "0",
            "reporter": "nullblue67"
        }
    ],
    "1838875": [
        {
            "ioc_value": "90.21.61.108:2375",
            "ioc_type": "ip:port",
            "threat_type": "payload_delivery",
            "malware": "elf.redtail",
            "malware_alias": null,
            "malware_printable": "RedTail",
            "first_seen_utc": "2026-06-29 05:54:19",
            "last_seen_utc": null,
            "confidence_level": 80,
            "is_compromised": false,
            "reference": "https://twitter.com/NullBlue67",
            "tags": "docker-api",
            "anonymous": "0",
            "reporter": "nullblue67"
        }
    ],
    "1838876": [
        {
            "ioc_value": "90.62.187.41:2375",
            "ioc_type": "ip:port",
            "threat_type": "payload_delivery",
            "malware": "elf.redtail",
            "malware_alias": null,
            "malware_printable": "RedTail",
            "first_seen_utc": "2026-06-29 05:54:18",
            "last_seen_utc": null,
            "confidence_level": 80,
            "is_compromised": false,
            "reference": "https://twitter.com/NullBlue67",
            "tags": "docker-api",
            "anonymous": "0",
            "reporter": "nullblue67"
        }
    ],
    "1838877": [
        {
            "ioc_value": "90.9.80.38:2375",
            "ioc_type": "ip:port",
            "threat_type": "payload_delivery",
            "malware": "elf.redtail",
            "malware_alias": null,
            "malware_printable": "RedTail",
            "first_seen_utc": "2026-06-29 05:54:18",
            "last_seen_utc": null,
            "confidence_level": 80,
            "is_compromised": false,
            "reference": "https://twitter.com/NullBlue67",
            "tags": "docker-api",
            "anonymous": "0",
            "reporter": "nullblue67"
        }
    ],
    "1838878": [
        {
            "ioc_value": "91.166.6.193:2375",
            "ioc_type": "ip:port",
            "threat_type": "payload_delivery",
            "malware": "elf.redtail",
            "malware_alias": null,
            "malware_printable": "RedTail",
            "first_seen_utc": "2026-06-29 05:54:17",
            "last_seen_utc": null,
            "confidence_level": 80,
            "is_compromised": false,
            "reference": "https://twitter.com/NullBlue67",
            "tags": "docker-api",
            "anonymous": "0",
            "reporter": "nullblue67"
        }
    ],
    "1838879": [
        {
            "ioc_value": "91.55.174.82:2375",
            "ioc_type": "ip:port",
            "threat_type": "payload_delivery",
            "malware": "elf.redtail",
            "malware_alias": null,
            "malware_printable": "RedTail",
            "first_seen_utc": "2026-06-29 05:54:04",
            "last_seen_utc": null,
            "confidence_level": 80,
            "is_compromised": false,
            "reference": "https://twitter.com/NullBlue67",
            "tags": "docker-api",
            "anonymous": "0",
            "reporter": "nullblue67"
        }
    ],
    "1838880": [
        {
            "ioc_value": "91.96.255.15:2375",
            "ioc_type": "ip:port",
            "threat_type": "payload_delivery",
            "malware": "elf.redtail",
            "malware_alias": null,
            "malware_printable": "RedTail",
            "first_seen_utc": "2026-06-29 05:54:03",
            "last_seen_utc": null,
            "confidence_level": 80,
            "is_compromised": false,
            "reference": "https://twitter.com/NullBlue67",
            "tags": "docker-api",
            "anonymous": "0",
            "reporter": "nullblue67"
        }
    ],
    "1838882": [
        {
            "ioc_value": "92.209.188.108:2375",
            "ioc_type": "ip:port",
            "threat_type": "payload_delivery",
            "malware": "elf.redtail",
            "malware_alias": null,
            "malware_printable": "RedTail",
            "first_seen_utc": "2026-06-29 05:54:03",
            "last_seen_utc": null,
            "confidence_level": 80,
            "is_compromised": false,
            "reference": "https://twitter.com/NullBlue67",
            "tags": "docker-api",
            "anonymous": "0",
            "reporter": "nullblue67"
        }
    ],
    "1838881": [
        {
            "ioc_value": "92.208.25.142:2375",
            "ioc_type": "ip:port",
            "threat_type": "payload_delivery",
            "malware": "elf.redtail",
            "malware_alias": null,
            "malware_printable": "RedTail",
            "first_seen_utc": "2026-06-29 05:54:02",
            "last_seen_utc": null,
            "confidence_level": 80,
            "is_compromised": false,
            "reference": "https://twitter.com/NullBlue67",
            "tags": "docker-api",
            "anonymous": "0",
            "reporter": "nullblue67"
        }
    ],
    "1838883": [
        {
            "ioc_value": "93.128.162.24:2375",
            "ioc_type": "ip:port",
            "threat_type": "payload_delivery",
            "malware": "elf.redtail",
            "malware_alias": null,
            "malware_printable": "RedTail",
            "first_seen_utc": "2026-06-29 05:54:01",
            "last_seen_utc": null,
            "confidence_level": 80,
            "is_compromised": false,
            "reference": "https://twitter.com/NullBlue67",
            "tags": "docker-api",
            "anonymous": "0",
            "reporter": "nullblue67"
        }
    ],
    "1838884": [
        {
            "ioc_value": "95.182.96.193:2375",
            "ioc_type": "ip:port",
            "threat_type": "payload_delivery",
            "malware": "elf.redtail",
            "malware_alias": null,
            "malware_printable": "RedTail",
            "first_seen_utc": "2026-06-29 05:54:00",
            "last_seen_utc": null,
            "confidence_level": 80,
            "is_compromised": false,
            "reference": "https://twitter.com/NullBlue67",
            "tags": "docker-api",
            "anonymous": "0",
            "reporter": "nullblue67"
        }
    ],
    "1838885": [
        {
            "ioc_value": "162.248.100.101:2",
            "ioc_type": "ip:port",
            "threat_type": "payload_delivery",
            "malware": "elf.mirai",
            "malware_alias": "Katana",
            "malware_printable": "Mirai",
            "first_seen_utc": "2026-06-29 05:54:00",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "Mirai,nc",
            "anonymous": "0",
            "reporter": "botnetkiller"
        }
    ],
    "1838886": [
        {
            "ioc_value": "162.248.100.101:23",
            "ioc_type": "ip:port",
            "threat_type": "payload_delivery",
            "malware": "elf.mirai",
            "malware_alias": "Katana",
            "malware_printable": "Mirai",
            "first_seen_utc": "2026-06-29 05:53:59",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "Mirai,nc",
            "anonymous": "0",
            "reporter": "botnetkiller"
        }
    ],
    "1838887": [
        {
            "ioc_value": "162.248.100.101:4567",
            "ioc_type": "ip:port",
            "threat_type": "payload_delivery",
            "malware": "elf.mirai",
            "malware_alias": "Katana",
            "malware_printable": "Mirai",
            "first_seen_utc": "2026-06-29 05:53:59",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "Mirai,nc",
            "anonymous": "0",
            "reporter": "botnetkiller"
        }
    ],
    "1838888": [
        {
            "ioc_value": "162.248.100.101:8512",
            "ioc_type": "ip:port",
            "threat_type": "payload_delivery",
            "malware": "elf.mirai",
            "malware_alias": "Katana",
            "malware_printable": "Mirai",
            "first_seen_utc": "2026-06-29 05:53:59",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "Mirai,nc",
            "anonymous": "0",
            "reporter": "botnetkiller"
        }
    ],
    "1838890": [
        {
            "ioc_value": "43.241.19.155:9327",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.mirai",
            "malware_alias": "Katana",
            "malware_printable": "Mirai",
            "first_seen_utc": "2026-06-29 05:53:58",
            "last_seen_utc": null,
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "",
            "tags": "C2,Mirai",
            "anonymous": "0",
            "reporter": "botnetkiller"
        }
    ],
    "1838889": [
        {
            "ioc_value": "162.248.100.101:2049",
            "ioc_type": "ip:port",
            "threat_type": "payload_delivery",
            "malware": "elf.mirai",
            "malware_alias": "Katana",
            "malware_printable": "Mirai",
            "first_seen_utc": "2026-06-29 05:53:57",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "Mirai,NFS",
            "anonymous": "0",
            "reporter": "botnetkiller"
        }
    ],
    "1839064": [
        {
            "ioc_value": "https://3king.ai/",
            "ioc_type": "url",
            "threat_type": "payload_delivery",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-06-29 05:53:57",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": "https://clickfix.carsonww.com/domains/3king.ai",
            "tags": "ClickFix",
            "anonymous": "0",
            "reporter": "CarsonWilliams"
        }
    ],
    "1839065": [
        {
            "ioc_value": "https://3king.live/",
            "ioc_type": "url",
            "threat_type": "payload_delivery",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-06-29 05:53:56",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": "https://clickfix.carsonww.com/domains/3king.live",
            "tags": "ClickFix",
            "anonymous": "0",
            "reporter": "CarsonWilliams"
        }
    ],
    "1839066": [
        {
            "ioc_value": "https://3king.app/",
            "ioc_type": "url",
            "threat_type": "payload_delivery",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-06-29 05:53:56",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": "https://clickfix.carsonww.com/domains/3king.app",
            "tags": "ClickFix",
            "anonymous": "0",
            "reporter": "CarsonWilliams"
        }
    ],
    "1838781": [
        {
            "ioc_value": "https://vacante-ieftine.ro/",
            "ioc_type": "url",
            "threat_type": "payload_delivery",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-06-29 05:53:54",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": "https://clickfix.carsonww.com/domains/vacante-ieftine.ro",
            "tags": "ClickFix",
            "anonymous": "0",
            "reporter": "CarsonWilliams"
        }
    ],
    "1838782": [
        {
            "ioc_value": "https://genova.com.vn/",
            "ioc_type": "url",
            "threat_type": "payload_delivery",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-06-29 05:53:53",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": "https://clickfix.carsonww.com/domains/genova.com.vn",
            "tags": "ClickFix",
            "anonymous": "0",
            "reporter": "CarsonWilliams"
        }
    ],
    "1838787": [
        {
            "ioc_value": "http://103.176.16.92:42446/Mozi.a",
            "ioc_type": "url",
            "threat_type": "payload_delivery",
            "malware": "elf.mozi",
            "malware_alias": null,
            "malware_printable": "Mozi",
            "first_seen_utc": "2026-06-29 05:53:52",
            "last_seen_utc": null,
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://honeylabs.net/lookup/103.176.16.92",
            "tags": "elf,iot,Mozi",
            "anonymous": "0",
            "reporter": "HoneyLabs"
        }
    ],
    "1838791": [
        {
            "ioc_value": "147.182.217.141:8080",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.aisuru",
            "malware_alias": null,
            "malware_printable": "Aisuru",
            "first_seen_utc": "2026-06-29 05:53:52",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "Aisuru,c2",
            "anonymous": "0",
            "reporter": "Bitsight"
        }
    ],
    "1838792": [
        {
            "ioc_value": "143.20.185.89:18129",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.mirai",
            "malware_alias": "Katana",
            "malware_printable": "Mirai",
            "first_seen_utc": "2026-06-29 05:53:51",
            "last_seen_utc": "2026-06-29 07:40:23",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "Mirai",
            "anonymous": "0",
            "reporter": "elfdigest"
        }
    ],
    "1839062": [
        {
            "ioc_value": "107.173.84.132:8084",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.vshell",
            "malware_alias": null,
            "malware_printable": "VShell",
            "first_seen_utc": "2026-06-29 05:05:07",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "vshell",
            "anonymous": "1",
            "reporter": "_ik_"
        }
    ],
    "1839063": [
        {
            "ioc_value": "161.153.82.75:10000",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.vshell",
            "malware_alias": null,
            "malware_printable": "VShell",
            "first_seen_utc": "2026-06-29 05:05:07",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "vshell",
            "anonymous": "1",
            "reporter": "_ik_"
        }
    ],
    "1839061": [
        {
            "ioc_value": "199.30.90.240:8888",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-06-29 05:05:06",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "supershell",
            "anonymous": "1",
            "reporter": "_ik_"
        }
    ],
    "1839060": [
        {
            "ioc_value": "6xbjz1e7.1xfa.bio",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 04:52:42",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "clearfake",
            "anonymous": "1",
            "reporter": "ttakvam"
        }
    ],
    "1839059": [
        {
            "ioc_value": "42.194.195.248:8090",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.vshell",
            "malware_alias": null,
            "malware_printable": "VShell",
            "first_seen_utc": "2026-06-29 04:05:04",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "vshell",
            "anonymous": "1",
            "reporter": "_ik_"
        }
    ],
    "1839058": [
        {
            "ioc_value": "9lw19l8l.betbuf.live",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 01:52:52",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "clearfake",
            "anonymous": "1",
            "reporter": "ttakvam"
        }
    ],
    "1839057": [
        {
            "ioc_value": "xmsjdtn0.betbuf.live",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-29 01:52:12",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake",
            "anonymous": "0",
            "reporter": "threatcat_ch"
        }
    ],
    "1839054": [
        {
            "ioc_value": "139d50b674112ca42a6f9e2aea789d0a1f3bd64e7ed5584d54bbfa6c7a418f72",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "py.venus_stealer",
            "malware_alias": null,
            "malware_printable": "Venus Stealer",
            "first_seen_utc": "2026-06-29 01:23:47",
            "last_seen_utc": null,
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": "0",
            "reporter": "Grim"
        }
    ],
    "1839055": [
        {
            "ioc_value": "41f8ffacbe031d1db7828d62a8e3a868f8599342",
            "ioc_type": "sha1_hash",
            "threat_type": "payload",
            "malware": "py.venus_stealer",
            "malware_alias": null,
            "malware_printable": "Venus Stealer",
            "first_seen_utc": "2026-06-29 01:23:47",
            "last_seen_utc": null,
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": "0",
            "reporter": "Grim"
        }
    ],
    "1839056": [
        {
            "ioc_value": "787d7a0b27f676de5986ff2aeffa694d",
            "ioc_type": "md5_hash",
            "threat_type": "payload",
            "malware": "py.venus_stealer",
            "malware_alias": null,
            "malware_printable": "Venus Stealer",
            "first_seen_utc": "2026-06-29 01:23:47",
            "last_seen_utc": null,
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": "0",
            "reporter": "Grim"
        }
    ],
    "1839051": [
        {
            "ioc_value": "e19f312bb3c65120c5faefbded0ce63abb79ae5871fdff02cc1c399c58ff5236",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-06-29 01:23:46",
            "last_seen_utc": null,
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": "0",
            "reporter": "Grim"
        }
    ],
    "1839052": [
        {
            "ioc_value": "24aa148b9aa0a391ec5fb157ef1c467f2eb75763",
            "ioc_type": "sha1_hash",
            "threat_type": "payload",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-06-29 01:23:46",
            "last_seen_utc": null,
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": "0",
            "reporter": "Grim"
        }
    ],
    "1839053": [
        {
            "ioc_value": "796c75cc4d7986e8088deeac118b3ff8",
            "ioc_type": "md5_hash",
            "threat_type": "payload",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-06-29 01:23:46",
            "last_seen_utc": null,
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": "0",
            "reporter": "Grim"
        }
    ],
    "1839047": [
        {
            "ioc_value": "e2ea34aa55123dd1c1c4ca7027b12053",
            "ioc_type": "md5_hash",
            "threat_type": "payload",
            "malware": "py.venus_stealer",
            "malware_alias": null,
            "malware_printable": "Venus Stealer",
            "first_seen_utc": "2026-06-29 01:23:45",
            "last_seen_utc": null,
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": "0",
            "reporter": "Grim"
        }
    ],
    "1839048": [
        {
            "ioc_value": "046ead5e49940d24ad2249ff10375d6d1a9057c08d00d1874a2669d7a7b57058",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-06-29 01:23:45",
            "last_seen_utc": null,
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": "0",
            "reporter": "Grim"
        }
    ],
    "1839049": [
        {
            "ioc_value": "50619615547d3f65f46546f21c9935913bc5ec44",
            "ioc_type": "sha1_hash",
            "threat_type": "payload",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-06-29 01:23:45",
            "last_seen_utc": null,
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": "0",
            "reporter": "Grim"
        }
    ],
    "1839050": [
        {
            "ioc_value": "83286b40935dc23576b57950f1fe9e62",
            "ioc_type": "md5_hash",
            "threat_type": "payload",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-06-29 01:23:45",
            "last_seen_utc": null,
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": "0",
            "reporter": "Grim"
        }
    ],
    "1839044": [
        {
            "ioc_value": "ccdd5b209678728be86711582b64f86c",
            "ioc_type": "md5_hash",
            "threat_type": "payload",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-06-29 01:23:44",
            "last_seen_utc": null,
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": "0",
            "reporter": "Grim"
        }
    ],
    "1839045": [
        {
            "ioc_value": "99fa87f8885cd8d4f0afb63b6c43c0f00d3cdd3edf535c1730641c8f919449b6",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "py.venus_stealer",
            "malware_alias": null,
            "malware_printable": "Venus Stealer",
            "first_seen_utc": "2026-06-29 01:23:44",
            "last_seen_utc": null,
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": "0",
            "reporter": "Grim"
        }
    ],
    "1839046": [
        {
            "ioc_value": "e12a2429c946114b6beb8921b7326b284250ebc8",
            "ioc_type": "sha1_hash",
            "threat_type": "payload",
            "malware": "py.venus_stealer",
            "malware_alias": null,
            "malware_printable": "Venus Stealer",
            "first_seen_utc": "2026-06-29 01:23:44",
            "last_seen_utc": null,
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": "0",
            "reporter": "Grim"
        }
    ],
    "1839041": [
        {
            "ioc_value": "496caac1fa6369e93cb48970f72e26da",
            "ioc_type": "md5_hash",
            "threat_type": "payload",
            "malware": "jar.crossrat",
            "malware_alias": "Trupto",
            "malware_printable": "CrossRAT",
            "first_seen_utc": "2026-06-29 01:23:43",
            "last_seen_utc": null,
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": "0",
            "reporter": "Grim"
        }
    ],
    "1839042": [
        {
            "ioc_value": "9a9e73edcf3b0732bb82ebcd530d4d9591cd057cbf080fb5f00eecc6366190b8",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-06-29 01:23:43",
            "last_seen_utc": null,
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": "0",
            "reporter": "Grim"
        }
    ],
    "1839043": [
        {
            "ioc_value": "e861ed732b772e44994486dbfd62e0d49fb1fcb8",
            "ioc_type": "sha1_hash",
            "threat_type": "payload",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-06-29 01:23:43",
            "last_seen_utc": null,
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": "0",
            "reporter": "Grim"
        }
    ],
    "1839038": [
        {
            "ioc_value": "9f18eac675b554fd802aa4641f61da47",
            "ioc_type": "md5_hash",
            "threat_type": "payload",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-06-29 01:23:42",
            "last_seen_utc": null,
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": "0",
            "reporter": "Grim"
        }
    ],
    "1839039": [
        {
            "ioc_value": "40079f05ba7cdccac1f62f8e7e1b644bc0a806b58465f5c005725bc54ee73ef1",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "jar.crossrat",
            "malware_alias": "Trupto",
            "malware_printable": "CrossRAT",
            "first_seen_utc": "2026-06-29 01:23:42",
            "last_seen_utc": null,
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": "0",
            "reporter": "Grim"
        }
    ],
    "1839040": [
        {
            "ioc_value": "bd2a22a6bab8f5d5c146f6162ad28244ab22985b",
            "ioc_type": "sha1_hash",
            "threat_type": "payload",
            "malware": "jar.crossrat",
            "malware_alias": "Trupto",
            "malware_printable": "CrossRAT",
            "first_seen_utc": "2026-06-29 01:23:42",
            "last_seen_utc": null,
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": "0",
            "reporter": "Grim"
        }
    ],
    "1839035": [
        {
            "ioc_value": "80b9ce821562da8e4178c2e08e761aca",
            "ioc_type": "md5_hash",
            "threat_type": "payload",
            "malware": "win.netwire",
            "malware_alias": "NetWeird,NetWire,Recam",
            "malware_printable": "NetWire RC",
            "first_seen_utc": "2026-06-29 01:23:41",
            "last_seen_utc": null,
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": "0",
            "reporter": "Grim"
        }
    ],
    "1839036": [
        {
            "ioc_value": "946754adecdf78d5d3fc21edcf01023405faf7bf698f3a5bf5b98df2060bbc3d",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-06-29 01:23:41",
            "last_seen_utc": null,
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": "0",
            "reporter": "Grim"
        }
    ],
    "1839037": [
        {
            "ioc_value": "773b2f09868d6a0ff62927d59f09f9e4d34dc726",
            "ioc_type": "sha1_hash",
            "threat_type": "payload",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-06-29 01:23:41",
            "last_seen_utc": null,
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": "0",
            "reporter": "Grim"
        }
    ],
    "1839032": [
        {
            "ioc_value": "a439f3ed1a23f8fad8a1b5b0e22bbea0",
            "ioc_type": "md5_hash",
            "threat_type": "payload",
            "malware": "win.netwire",
            "malware_alias": "NetWeird,NetWire,Recam",
            "malware_printable": "NetWire RC",
            "first_seen_utc": "2026-06-29 01:23:40",
            "last_seen_utc": null,
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": "0",
            "reporter": "Grim"
        }
    ],
    "1839033": [
        {
            "ioc_value": "8ee29f72021306cf5ed6e3a5e7ec19a8e4de837ec77c6dc307ce5dcc96d833b3",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "win.netwire",
            "malware_alias": "NetWeird,NetWire,Recam",
            "malware_printable": "NetWire RC",
            "first_seen_utc": "2026-06-29 01:23:40",
            "last_seen_utc": null,
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": "0",
            "reporter": "Grim"
        }
    ],
    "1839034": [
        {
            "ioc_value": "e7ddbec4cc309a35f40ed6127fa108363a56ffd0",
            "ioc_type": "sha1_hash",
            "threat_type": "payload",
            "malware": "win.netwire",
            "malware_alias": "NetWeird,NetWire,Recam",
            "malware_printable": "NetWire RC",
            "first_seen_utc": "2026-06-29 01:23:40",
            "last_seen_utc": null,
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": "0",
            "reporter": "Grim"
        }
    ],
    "1839029": [
        {
            "ioc_value": "2695e24e6d062fe97e0e3ae4238ecc11",
            "ioc_type": "md5_hash",
            "threat_type": "payload",
            "malware": "win.netwire",
            "malware_alias": "NetWeird,NetWire,Recam",
            "malware_printable": "NetWire RC",
            "first_seen_utc": "2026-06-29 01:23:39",
            "last_seen_utc": null,
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": "0",
            "reporter": "Grim"
        }
    ],
    "1839030": [
        {
            "ioc_value": "643812d9c9cc62a10d46401fcca897897d2fbe843014d175206131ad4aeaa576",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "win.netwire",
            "malware_alias": "NetWeird,NetWire,Recam",
            "malware_printable": "NetWire RC",
            "first_seen_utc": "2026-06-29 01:23:39",
            "last_seen_utc": null,
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": "0",
            "reporter": "Grim"
        }
    ],
    "1839031": [
        {
            "ioc_value": "9edc9d2206b28c939176a2fc4970ee7c4ca3a65b",
            "ioc_type": "sha1_hash",
            "threat_type": "payload",
            "malware": "win.netwire",
            "malware_alias": "NetWeird,NetWire,Recam",
            "malware_printable": "NetWire RC",
            "first_seen_utc": "2026-06-29 01:23:39",
            "last_seen_utc": null,
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": "0",
            "reporter": "Grim"
        }
    ],
    "1839025": [
        {
            "ioc_value": "f53a40ad6fae35057880eaf1dbd0624e2ac7c7f1",
            "ioc_type": "sha1_hash",
            "threat_type": "payload",
            "malware": "win.netwire",
            "malware_alias": "NetWeird,NetWire,Recam",
            "malware_printable": "NetWire RC",
            "first_seen_utc": "2026-06-29 01:23:38",
            "last_seen_utc": null,
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": "0",
            "reporter": "Grim"
        }
    ],
    "1839026": [
        {
            "ioc_value": "3993e71fea3db426410909d3752d4932",
            "ioc_type": "md5_hash",
            "threat_type": "payload",
            "malware": "win.netwire",
            "malware_alias": "NetWeird,NetWire,Recam",
            "malware_printable": "NetWire RC",
            "first_seen_utc": "2026-06-29 01:23:38",
            "last_seen_utc": null,
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": "0",
            "reporter": "Grim"
        }
    ],
    "1839027": [
        {
            "ioc_value": "2f33698f3e24d9f7633782c67097b67973630bbf16b51dbb493d59acaf36f5b7",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "win.netwire",
            "malware_alias": "NetWeird,NetWire,Recam",
            "malware_printable": "NetWire RC",
            "first_seen_utc": "2026-06-29 01:23:38",
            "last_seen_utc": null,
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": "0",
            "reporter": "Grim"
        }
    ],
    "1839028": [
        {
            "ioc_value": "4a22a0aeef82e9e9094f100e714ad71919ae8a84",
            "ioc_type": "sha1_hash",
            "threat_type": "payload",
            "malware": "win.netwire",
            "malware_alias": "NetWeird,NetWire,Recam",
            "malware_printable": "NetWire RC",
            "first_seen_utc": "2026-06-29 01:23:38",
            "last_seen_utc": null,
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": "0",
            "reporter": "Grim"
        }
    ],
    "1839022": [
        {
            "ioc_value": "5d465ee2e2567bd59a1110597045c87d14a7a611",
            "ioc_type": "sha1_hash",
            "threat_type": "payload",
            "malware": "win.netwire",
            "malware_alias": "NetWeird,NetWire,Recam",
            "malware_printable": "NetWire RC",
            "first_seen_utc": "2026-06-29 01:23:37",
            "last_seen_utc": null,
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": "0",
            "reporter": "Grim"
        }
    ],
    "1839023": [
        {
            "ioc_value": "fda577720a8c60c46a37650398fc0144",
            "ioc_type": "md5_hash",
            "threat_type": "payload",
            "malware": "win.netwire",
            "malware_alias": "NetWeird,NetWire,Recam",
            "malware_printable": "NetWire RC",
            "first_seen_utc": "2026-06-29 01:23:37",
            "last_seen_utc": null,
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": "0",
            "reporter": "Grim"
        }
    ],
    "1839024": [
        {
            "ioc_value": "be245c2e6674ae197b407cd08b7d995909f79f4b2ea128f2a049ce7227ac5b93",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "win.netwire",
            "malware_alias": "NetWeird,NetWire,Recam",
            "malware_printable": "NetWire RC",
            "first_seen_utc": "2026-06-29 01:23:37",
            "last_seen_utc": null,
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": "0",
            "reporter": "Grim"
        }
    ],
    "1839019": [
        {
            "ioc_value": "449b411859b06e87e62ea42985d02ba8c5134716",
            "ioc_type": "sha1_hash",
            "threat_type": "payload",
            "malware": "win.netwire",
            "malware_alias": "NetWeird,NetWire,Recam",
            "malware_printable": "NetWire RC",
            "first_seen_utc": "2026-06-29 01:23:36",
            "last_seen_utc": null,
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": "0",
            "reporter": "Grim"
        }
    ],
    "1839020": [
        {
            "ioc_value": "d5e9cd5cd5ba38ae51a114cbc2189efa",
            "ioc_type": "md5_hash",
            "threat_type": "payload",
            "malware": "win.netwire",
            "malware_alias": "NetWeird,NetWire,Recam",
            "malware_printable": "NetWire RC",
            "first_seen_utc": "2026-06-29 01:23:36",
            "last_seen_utc": null,
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": "0",
            "reporter": "Grim"
        }
    ],
    "1839021": [
        {
            "ioc_value": "bc5a6386c6ecdc49d1714ebf156059d392c8d40def48eca333aee821da492e0a",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "win.netwire",
            "malware_alias": "NetWeird,NetWire,Recam",
            "malware_printable": "NetWire RC",
            "first_seen_utc": "2026-06-29 01:23:36",
            "last_seen_utc": null,
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": "0",
            "reporter": "Grim"
        }
    ],
    "1839016": [
        {
            "ioc_value": "ea8402d8d42601b6c8efb38dd19c60e52bb60f09",
            "ioc_type": "sha1_hash",
            "threat_type": "payload",
            "malware": "win.netwire",
            "malware_alias": "NetWeird,NetWire,Recam",
            "malware_printable": "NetWire RC",
            "first_seen_utc": "2026-06-29 01:23:35",
            "last_seen_utc": null,
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": "0",
            "reporter": "Grim"
        }
    ],
    "1839017": [
        {
            "ioc_value": "d6d0aff94ec9c1d794fa31daf5fad87a",
            "ioc_type": "md5_hash",
            "threat_type": "payload",
            "malware": "win.netwire",
            "malware_alias": "NetWeird,NetWire,Recam",
            "malware_printable": "NetWire RC",
            "first_seen_utc": "2026-06-29 01:23:35",
            "last_seen_utc": null,
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": "0",
            "reporter": "Grim"
        }
    ],
    "1839018": [
        {
            "ioc_value": "4a087a74df20ffa9f4acc2427cea2158f76f32ae85389fe396282c8c44fa794a",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "win.netwire",
            "malware_alias": "NetWeird,NetWire,Recam",
            "malware_printable": "NetWire RC",
            "first_seen_utc": "2026-06-29 01:23:35",
            "last_seen_utc": null,
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": "0",
            "reporter": "Grim"
        }
    ],
    "1839013": [
        {
            "ioc_value": "2c707ca426222f790dc10216f9784127b386bf75",
            "ioc_type": "sha1_hash",
            "threat_type": "payload",
            "malware": "win.ghost_rat",
            "malware_alias": "Farfli,Gh0st RAT,PCRat",
            "malware_printable": "Ghost RAT",
            "first_seen_utc": "2026-06-29 01:23:34",
            "last_seen_utc": null,
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": "0",
            "reporter": "Grim"
        }
    ],
    "1839014": [
        {
            "ioc_value": "c21c6962c9902ddbf4d08537ea7d96a4",
            "ioc_type": "md5_hash",
            "threat_type": "payload",
            "malware": "win.ghost_rat",
            "malware_alias": "Farfli,Gh0st RAT,PCRat",
            "malware_printable": "Ghost RAT",
            "first_seen_utc": "2026-06-29 01:23:34",
            "last_seen_utc": null,
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": "0",
            "reporter": "Grim"
        }
    ],
    "1839015": [
        {
            "ioc_value": "823aa0257a4c971b780e5569f4f93a017db7337f9ae6eb16692c37f68920b6bf",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "win.netwire",
            "malware_alias": "NetWeird,NetWire,Recam",
            "malware_printable": "NetWire RC",
            "first_seen_utc": "2026-06-29 01:23:34",
            "last_seen_utc": null,
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": "0",
            "reporter": "Grim"
        }
    ],
    "1839010": [
        {
            "ioc_value": "fab8258cfc30c4a88de0ca122513ea8ddd306f9d",
            "ioc_type": "sha1_hash",
            "threat_type": "payload",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-06-29 01:23:33",
            "last_seen_utc": null,
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": "0",
            "reporter": "Grim"
        }
    ],
    "1839011": [
        {
            "ioc_value": "7e359d8fdd0d72a0971d639c20197d40",
            "ioc_type": "md5_hash",
            "threat_type": "payload",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-06-29 01:23:33",
            "last_seen_utc": null,
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": "0",
            "reporter": "Grim"
        }
    ],
    "1839012": [
        {
            "ioc_value": "7317d297686d154b4d78217e100df5f57949f05efe095f1a017b5988cddef98b",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "win.ghost_rat",
            "malware_alias": "Farfli,Gh0st RAT,PCRat",
            "malware_printable": "Ghost RAT",
            "first_seen_utc": "2026-06-29 01:23:33",
            "last_seen_utc": null,
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": "0",
            "reporter": "Grim"
        }
    ],
    "1839006": [
        {
            "ioc_value": "fe566ca92d40914438c7ce3157a6a0936ac7be94e71e6c37b95ac84177511874",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "jar.strrat",
            "malware_alias": null,
            "malware_printable": "STRRAT",
            "first_seen_utc": "2026-06-29 01:23:32",
            "last_seen_utc": null,
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": "0",
            "reporter": "Grim"
        }
    ],
    "1839007": [
        {
            "ioc_value": "38fe8d2da94de97b0a6c0e7648dba85e00eeecca",
            "ioc_type": "sha1_hash",
            "threat_type": "payload",
            "malware": "jar.strrat",
            "malware_alias": null,
            "malware_printable": "STRRAT",
            "first_seen_utc": "2026-06-29 01:23:32",
            "last_seen_utc": null,
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": "0",
            "reporter": "Grim"
        }
    ],
    "1839008": [
        {
            "ioc_value": "41251868de0e68da924595a9e4b6b899",
            "ioc_type": "md5_hash",
            "threat_type": "payload",
            "malware": "jar.strrat",
            "malware_alias": null,
            "malware_printable": "STRRAT",
            "first_seen_utc": "2026-06-29 01:23:32",
            "last_seen_utc": null,
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": "0",
            "reporter": "Grim"
        }
    ],
    "1839009": [
        {
            "ioc_value": "f89d864f7d2382e8e2e34c35ef0b435eb6fd3f1e43cc4c2a9e3d2e96faf452f7",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-06-29 01:23:32",
            "last_seen_utc": null,
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": "0",
            "reporter": "Grim"
        }
    ],
    "1839005": [
        {
            "ioc_value": "3e7ca33a0746e65cc08a92035af226c0",
            "ioc_type": "md5_hash",
            "threat_type": "payload",
            "malware": "win.valley_rat",
            "malware_alias": "Winos",
            "malware_printable": "ValleyRAT",
            "first_seen_utc": "2026-06-29 01:23:28",
            "last_seen_utc": null,
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": "0",
            "reporter": "Grim"
        }
    ],
    "1839003": [
        {
            "ioc_value": "b8b16633d9cc1eda12aa9415d2fa2e91f39ffe8b7a94e38812e5c49ac88fe9ca",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "win.valley_rat",
            "malware_alias": "Winos",
            "malware_printable": "ValleyRAT",
            "first_seen_utc": "2026-06-29 01:23:27",
            "last_seen_utc": null,
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": "0",
            "reporter": "Grim"
        }
    ],
    "1839004": [
        {
            "ioc_value": "ec6c1aa469dea25359080e6e2f22a7dfecb8a14e",
            "ioc_type": "sha1_hash",
            "threat_type": "payload",
            "malware": "win.valley_rat",
            "malware_alias": "Winos",
            "malware_printable": "ValleyRAT",
            "first_seen_utc": "2026-06-29 01:23:27",
            "last_seen_utc": null,
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": "0",
            "reporter": "Grim"
        }
    ],
    "1839002": [
        {
            "ioc_value": "dced1923790be572edf4191106a6dc10",
            "ioc_type": "md5_hash",
            "threat_type": "payload",
            "malware": "win.dostealer",
            "malware_alias": null,
            "malware_printable": "DOSTEALER",
            "first_seen_utc": "2026-06-29 01:23:26",
            "last_seen_utc": null,
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": "0",
            "reporter": "Grim"
        }
    ],
    "1838999": [
        {
            "ioc_value": "d070cecbc810cebe7c1cf373ea69b5fd",
            "ioc_type": "md5_hash",
            "threat_type": "payload",
            "malware": "win.acr_stealer",
            "malware_alias": null,
            "malware_printable": "ACR Stealer",
            "first_seen_utc": "2026-06-29 01:23:25",
            "last_seen_utc": null,
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": "0",
            "reporter": "Grim"
        }
    ],
    "1839000": [
        {
            "ioc_value": "d6d38c1850e229809385420e9473ebd68fc9ade8d3d2b25052c476741db52bda",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "win.dostealer",
            "malware_alias": null,
            "malware_printable": "DOSTEALER",
            "first_seen_utc": "2026-06-29 01:23:25",
            "last_seen_utc": null,
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": "0",
            "reporter": "Grim"
        }
    ],
    "1839001": [
        {
            "ioc_value": "2b671eb88103b9af4fb79f494eab79f80f0d7899",
            "ioc_type": "sha1_hash",
            "threat_type": "payload",
            "malware": "win.dostealer",
            "malware_alias": null,
            "malware_printable": "DOSTEALER",
            "first_seen_utc": "2026-06-29 01:23:25",
            "last_seen_utc": null,
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": "0",
            "reporter": "Grim"
        }
    ],
    "1838996": [
        {
            "ioc_value": "4322706ec257b3612d493aec83709abd",
            "ioc_type": "md5_hash",
            "threat_type": "payload",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-06-29 01:23:24",
            "last_seen_utc": null,
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": "0",
            "reporter": "Grim"
        }
    ],
    "1838997": [
        {
            "ioc_value": "afed5328d5778877ed29130d62987f9492177080a067d249ee303502ef9530d1",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "win.acr_stealer",
            "malware_alias": null,
            "malware_printable": "ACR Stealer",
            "first_seen_utc": "2026-06-29 01:23:24",
            "last_seen_utc": null,
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": "0",
            "reporter": "Grim"
        }
    ],
    "1838998": [
        {
            "ioc_value": "87452ff24f31736f014cc9852c6e879d3f3c3b8f",
            "ioc_type": "sha1_hash",
            "threat_type": "payload",
            "malware": "win.acr_stealer",
            "malware_alias": null,
            "malware_printable": "ACR Stealer",
            "first_seen_utc": "2026-06-29 01:23:24",
            "last_seen_utc": null,
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": "0",
            "reporter": "Grim"
        }
    ],
    "1838993": [
        {
            "ioc_value": "28a483eac56dcdc47c904ce010f34d65",
            "ioc_type": "md5_hash",
            "threat_type": "payload",
            "malware": "win.acr_stealer",
            "malware_alias": null,
            "malware_printable": "ACR Stealer",
            "first_seen_utc": "2026-06-29 01:23:23",
            "last_seen_utc": null,
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": "0",
            "reporter": "Grim"
        }
    ],
    "1838994": [
        {
            "ioc_value": "123450a779753bd0045cb82de9179cd7a3aad2d560b16a8201ca4eaa7da52ba3",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-06-29 01:23:23",
            "last_seen_utc": null,
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": "0",
            "reporter": "Grim"
        }
    ],
    "1838995": [
        {
            "ioc_value": "45bbb23402b9d86278b9953820c9252d33ee85a1",
            "ioc_type": "sha1_hash",
            "threat_type": "payload",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-06-29 01:23:23",
            "last_seen_utc": null,
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": "0",
            "reporter": "Grim"
        }
    ],
    "1838990": [
        {
            "ioc_value": "029714671183c6988e3067a1d2fdec6e",
            "ioc_type": "md5_hash",
            "threat_type": "payload",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-06-29 01:23:22",
            "last_seen_utc": null,
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": "0",
            "reporter": "Grim"
        }
    ],
    "1838991": [
        {
            "ioc_value": "b30a55c62ea914a9dd179a56583cffffdccdf03b38210b87af7f4064a2a941b5",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "win.acr_stealer",
            "malware_alias": null,
            "malware_printable": "ACR Stealer",
            "first_seen_utc": "2026-06-29 01:23:22",
            "last_seen_utc": null,
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": "0",
            "reporter": "Grim"
        }
    ],
    "1838992": [
        {
            "ioc_value": "af51eb484b38c2084bdfca42d5178821238ec5a3",
            "ioc_type": "sha1_hash",
            "threat_type": "payload",
            "malware": "win.acr_stealer",
            "malware_alias": null,
            "malware_printable": "ACR Stealer",
            "first_seen_utc": "2026-06-29 01:23:22",
            "last_seen_utc": null,
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": "0",
            "reporter": "Grim"
        }
    ],
    "1838986": [
        {
            "ioc_value": "30f5f001631cb48f37b684fcbb7791976dbdadb2",
            "ioc_type": "sha1_hash",
            "threat_type": "payload",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-06-29 01:23:21",
            "last_seen_utc": null,
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": "0",
            "reporter": "Grim"
        }
    ],
    "1838987": [
        {
            "ioc_value": "77ac1472bfb41dcc80e160bc87691abc",
            "ioc_type": "md5_hash",
            "threat_type": "payload",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-06-29 01:23:21",
            "last_seen_utc": null,
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": "0",
            "reporter": "Grim"
        }
    ],
    "1838988": [
        {
            "ioc_value": "acb2f08fd49a1958c809389b01141248f19bde31dc70b44b9f466ebd8c6dcbd0",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-06-29 01:23:21",
            "last_seen_utc": null,
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": "0",
            "reporter": "Grim"
        }
    ],
    "1838989": [
        {
            "ioc_value": "79bb656381c24aacdd3bdae1e6c3ad8448eaf34a",
            "ioc_type": "sha1_hash",
            "threat_type": "payload",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-06-29 01:23:21",
            "last_seen_utc": null,
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": "0",
            "reporter": "Grim"
        }
    ],
    "1838983": [
        {
            "ioc_value": "cbaebbe158ff69d922a67b61eb93b19e3a92306a",
            "ioc_type": "sha1_hash",
            "threat_type": "payload",
            "malware": "win.acr_stealer",
            "malware_alias": null,
            "malware_printable": "ACR Stealer",
            "first_seen_utc": "2026-06-29 01:23:20",
            "last_seen_utc": null,
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": "0",
            "reporter": "Grim"
        }
    ],
    "1838984": [
        {
            "ioc_value": "948b712d99e0c5cad05416e7f13841bb",
            "ioc_type": "md5_hash",
            "threat_type": "payload",
            "malware": "win.acr_stealer",
            "malware_alias": null,
            "malware_printable": "ACR Stealer",
            "first_seen_utc": "2026-06-29 01:23:20",
            "last_seen_utc": null,
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": "0",
            "reporter": "Grim"
        }
    ],
    "1838985": [
        {
            "ioc_value": "4ed6520516e5f756f1d020510d5e508c03811b3cb5062eed4bede73df641b779",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-06-29 01:23:20",
            "last_seen_utc": null,
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": "0",
            "reporter": "Grim"
        }
    ],
    "1838979": [
        {
            "ioc_value": "4a465658121a15449fadbeed82d37c461e601ae45c08a3d6c992285d31ebf804",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "win.acr_stealer",
            "malware_alias": null,
            "malware_printable": "ACR Stealer",
            "first_seen_utc": "2026-06-29 01:23:19",
            "last_seen_utc": null,
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": "0",
            "reporter": "Grim"
        }
    ],
    "1838980": [
        {
            "ioc_value": "f8feca6cc45f6b934201c28a8c0d86409fce8836",
            "ioc_type": "sha1_hash",
            "threat_type": "payload",
            "malware": "win.acr_stealer",
            "malware_alias": null,
            "malware_printable": "ACR Stealer",
            "first_seen_utc": "2026-06-29 01:23:19",
            "last_seen_utc": null,
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": "0",
            "reporter": "Grim"
        }
    ],
    "1838981": [
        {
            "ioc_value": "a040670ccbe6b4c9841d8706c433997c",
            "ioc_type": "md5_hash",
            "threat_type": "payload",
            "malware": "win.acr_stealer",
            "malware_alias": null,
            "malware_printable": "ACR Stealer",
            "first_seen_utc": "2026-06-29 01:23:19",
            "last_seen_utc": null,
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": "0",
            "reporter": "Grim"
        }
    ],
    "1838982": [
        {
            "ioc_value": "e21f70aebb96b545be30ba9b92fb7a77321d78da5641ce9f4d7b3ab8f6d09e70",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "win.acr_stealer",
            "malware_alias": null,
            "malware_printable": "ACR Stealer",
            "first_seen_utc": "2026-06-29 01:23:19",
            "last_seen_utc": null,
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": "0",
            "reporter": "Grim"
        }
    ],
    "1838978": [
        {
            "ioc_value": "9fc877b010e2c630c4db9efd1e0c5ffe",
            "ioc_type": "md5_hash",
            "threat_type": "payload",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-06-29 01:23:18",
            "last_seen_utc": null,
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": "0",
            "reporter": "Grim"
        }
    ],
    "1838976": [
        {
            "ioc_value": "a3fed15f05903e3bb645f059a65f5e56ffeab45ab02f535d6df263d4363a6628",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-06-29 01:23:17",
            "last_seen_utc": null,
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": "0",
            "reporter": "Grim"
        }
    ],
    "1838977": [
        {
            "ioc_value": "64dda3b0dc00c304bb3b65db472548d7d4c7204c",
            "ioc_type": "sha1_hash",
            "threat_type": "payload",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-06-29 01:23:17",
            "last_seen_utc": null,
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": "0",
            "reporter": "Grim"
        }
    ],
    "1838975": [
        {
            "ioc_value": "390929763242f8f854188b405ac7f5ba",
            "ioc_type": "md5_hash",
            "threat_type": "payload",
            "malware": "win.njrat",
            "malware_alias": "Bladabindi,Lime-Worm",
            "malware_printable": "NjRAT",
            "first_seen_utc": "2026-06-29 01:23:16",
            "last_seen_utc": null,
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": "0",
            "reporter": "Grim"
        }
    ],
    "1838971": [
        {
            "ioc_value": "b7d45389d4acc560c93215f1096befb28cda75f8",
            "ioc_type": "sha1_hash",
            "threat_type": "payload",
            "malware": "py.blankgrabber",
            "malware_alias": null,
            "malware_printable": "BlankGrabber",
            "first_seen_utc": "2026-06-29 01:23:15",
            "last_seen_utc": null,
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": "0",
            "reporter": "Grim"
        }
    ],
    "1838972": [
        {
            "ioc_value": "e2f13f6d216b70e66ce859e3e0cadcb7",
            "ioc_type": "md5_hash",
            "threat_type": "payload",
            "malware": "py.blankgrabber",
            "malware_alias": null,
            "malware_printable": "BlankGrabber",
            "first_seen_utc": "2026-06-29 01:23:15",
            "last_seen_utc": null,
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": "0",
            "reporter": "Grim"
        }
    ],
    "1838973": [
        {
            "ioc_value": "39cbd2d2299ebbc1eba6bb1ffab7d87f0016715fb237d0a1a253262b4b9cea13",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "win.njrat",
            "malware_alias": "Bladabindi,Lime-Worm",
            "malware_printable": "NjRAT",
            "first_seen_utc": "2026-06-29 01:23:15",
            "last_seen_utc": null,
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": "0",
            "reporter": "Grim"
        }
    ],
    "1838974": [
        {
            "ioc_value": "6d20314cdc9d3ba60bb44a2ff17666054394dfcb",
            "ioc_type": "sha1_hash",
            "threat_type": "payload",
            "malware": "win.njrat",
            "malware_alias": "Bladabindi,Lime-Worm",
            "malware_printable": "NjRAT",
            "first_seen_utc": "2026-06-29 01:23:15",
            "last_seen_utc": null,
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": "0",
            "reporter": "Grim"
        }
    ],
    "1838968": [
        {
            "ioc_value": "7542b7b567d58fde29869a84038ce49f20a8ffe4",
            "ioc_type": "sha1_hash",
            "threat_type": "payload",
            "malware": "py.blankgrabber",
            "malware_alias": null,
            "malware_printable": "BlankGrabber",
            "first_seen_utc": "2026-06-29 01:23:14",
            "last_seen_utc": null,
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": "0",
            "reporter": "Grim"
        }
    ],
    "1838969": [
        {
            "ioc_value": "4f32445270d6f1a4b3a1692aebce68b0",
            "ioc_type": "md5_hash",
            "threat_type": "payload",
            "malware": "py.blankgrabber",
            "malware_alias": null,
            "malware_printable": "BlankGrabber",
            "first_seen_utc": "2026-06-29 01:23:14",
            "last_seen_utc": null,
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": "0",
            "reporter": "Grim"
        }
    ],
    "1838970": [
        {
            "ioc_value": "8928d35f3e18435f6c17940a5a9a2515186b5a7a4faa6f681b7d244249daaf0b",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "py.blankgrabber",
            "malware_alias": null,
            "malware_printable": "BlankGrabber",
            "first_seen_utc": "2026-06-29 01:23:14",
            "last_seen_utc": null,
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": "0",
            "reporter": "Grim"
        }
    ],
    "1838964": [
        {
            "ioc_value": "94dc6a521549029a2bcd479bf04327518ea0cf0a3a4675d98cb421f256340122",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "py.blankgrabber",
            "malware_alias": null,
            "malware_printable": "BlankGrabber",
            "first_seen_utc": "2026-06-29 01:23:13",
            "last_seen_utc": null,
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": "0",
            "reporter": "Grim"
        }
    ],
    "1838965": [
        {
            "ioc_value": "5c7fc0c75b357a21fb920bdb78eaa3a236c7b634",
            "ioc_type": "sha1_hash",
            "threat_type": "payload",
            "malware": "py.blankgrabber",
            "malware_alias": null,
            "malware_printable": "BlankGrabber",
            "first_seen_utc": "2026-06-29 01:23:13",
            "last_seen_utc": null,
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": "0",
            "reporter": "Grim"
        }
    ],
    "1838966": [
        {
            "ioc_value": "e0227ae2a175af87b2e31d1a47cb3276",
            "ioc_type": "md5_hash",
            "threat_type": "payload",
            "malware": "py.blankgrabber",
            "malware_alias": null,
            "malware_printable": "BlankGrabber",
            "first_seen_utc": "2026-06-29 01:23:13",
            "last_seen_utc": null,
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": "0",
            "reporter": "Grim"
        }
    ],
    "1838967": [
        {
            "ioc_value": "542ab12e9aa46a0a19d380e7390a84c4628c7316cb7a4bd01a85a8b3a45ca421",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "py.blankgrabber",
            "malware_alias": null,
            "malware_printable": "BlankGrabber",
            "first_seen_utc": "2026-06-29 01:23:13",
            "last_seen_utc": null,
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": "0",
            "reporter": "Grim"
        }
    ],
    "1838962": [
        {
            "ioc_value": "a39c3459c3a86a8e1ab58323e878320c85b43b51",
            "ioc_type": "sha1_hash",
            "threat_type": "payload",
            "malware": "py.blankgrabber",
            "malware_alias": null,
            "malware_printable": "BlankGrabber",
            "first_seen_utc": "2026-06-29 01:23:12",
            "last_seen_utc": null,
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": "0",
            "reporter": "Grim"
        }
    ],
    "1838963": [
        {
            "ioc_value": "7e87c40331ad08fecfeb53c22fccd9d1",
            "ioc_type": "md5_hash",
            "threat_type": "payload",
            "malware": "py.blankgrabber",
            "malware_alias": null,
            "malware_printable": "BlankGrabber",
            "first_seen_utc": "2026-06-29 01:23:12",
            "last_seen_utc": null,
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": "0",
            "reporter": "Grim"
        }
    ],
    "1838960": [
        {
            "ioc_value": "011c4ffba12eb2a298ff83159177ca7a",
            "ioc_type": "md5_hash",
            "threat_type": "payload",
            "malware": "win.stealc",
            "malware_alias": null,
            "malware_printable": "Stealc",
            "first_seen_utc": "2026-06-29 01:23:11",
            "last_seen_utc": null,
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": "0",
            "reporter": "Grim"
        }
    ],
    "1838961": [
        {
            "ioc_value": "e207ce6f845f84bd247294390e12fd94df499436b8170ec143266405735d36fe",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "py.blankgrabber",
            "malware_alias": null,
            "malware_printable": "BlankGrabber",
            "first_seen_utc": "2026-06-29 01:23:11",
            "last_seen_utc": null,
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": "0",
            "reporter": "Grim"
        }
    ],
    "1838957": [
        {
            "ioc_value": "c1cda5f5016b812993dd4858fa6fb949",
            "ioc_type": "md5_hash",
            "threat_type": "payload",
            "malware": "win.amadey",
            "malware_alias": null,
            "malware_printable": "Amadey",
            "first_seen_utc": "2026-06-29 01:23:10",
            "last_seen_utc": null,
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": "0",
            "reporter": "Grim"
        }
    ],
    "1838958": [
        {
            "ioc_value": "b2687e641c114589ef0f3e96abb7bdf5758009b72a0ef74f2e7f30fafe7bebe7",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "win.stealc",
            "malware_alias": null,
            "malware_printable": "Stealc",
            "first_seen_utc": "2026-06-29 01:23:10",
            "last_seen_utc": null,
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": "0",
            "reporter": "Grim"
        }
    ],
    "1838959": [
        {
            "ioc_value": "71f8c01b5819fe2d77519326317a1922cbd92a40",
            "ioc_type": "sha1_hash",
            "threat_type": "payload",
            "malware": "win.stealc",
            "malware_alias": null,
            "malware_printable": "Stealc",
            "first_seen_utc": "2026-06-29 01:23:10",
            "last_seen_utc": null,
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": "0",
            "reporter": "Grim"
        }
    ],
    "1838954": [
        {
            "ioc_value": "6f9edbfed883db4efc7ede0460ecb3ff",
            "ioc_type": "md5_hash",
            "threat_type": "payload",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-06-29 01:23:09",
            "last_seen_utc": null,
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": "0",
            "reporter": "Grim"
        }
    ],
    "1838955": [
        {
            "ioc_value": "c942ecd62cc2de17119903a9adb79dc9a382136288a2a5e9385e856a668a3d7a",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "win.amadey",
            "malware_alias": null,
            "malware_printable": "Amadey",
            "first_seen_utc": "2026-06-29 01:23:09",
            "last_seen_utc": null,
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": "0",
            "reporter": "Grim"
        }
    ],
    "1838956": [
        {
            "ioc_value": "75b70ffacf08e1d1cc7d77fbf3dc719c8711f150",
            "ioc_type": "sha1_hash",
            "threat_type": "payload",
            "malware": "win.amadey",
            "malware_alias": null,
            "malware_printable": "Amadey",
            "first_seen_utc": "2026-06-29 01:23:09",
            "last_seen_utc": null,
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": "0",
            "reporter": "Grim"
        }
    ],
    "1838951": [
        {
            "ioc_value": "38d02de220bc3849fbc8632696f8dd6c",
            "ioc_type": "md5_hash",
            "threat_type": "payload",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-06-29 01:23:08",
            "last_seen_utc": null,
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": "0",
            "reporter": "Grim"
        }
    ],
    "1838952": [
        {
            "ioc_value": "ed7a9ad7284781a6961eb2b9715e813c430f732f7535813c0c6285a34e29b67b",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-06-29 01:23:08",
            "last_seen_utc": null,
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": "0",
            "reporter": "Grim"
        }
    ],
    "1838953": [
        {
            "ioc_value": "78ecd6ea99e2b709bd1fda2554069451edebd56d",
            "ioc_type": "sha1_hash",
            "threat_type": "payload",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-06-29 01:23:08",
            "last_seen_utc": null,
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": "0",
            "reporter": "Grim"
        }
    ],
    "1838947": [
        {
            "ioc_value": "803dd34dfa729441444bc19a74db9cf5b7fd73a7",
            "ioc_type": "sha1_hash",
            "threat_type": "payload",
            "malware": "win.wannacryptor",
            "malware_alias": "Wana Decrypt0r,WannaCry,WannaCrypt,Wcry",
            "malware_printable": "WannaCryptor",
            "first_seen_utc": "2026-06-29 01:23:07",
            "last_seen_utc": null,
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": "0",
            "reporter": "Grim"
        }
    ],
    "1838948": [
        {
            "ioc_value": "2e4931fc4f7fcfcea1192df30ffcb858",
            "ioc_type": "md5_hash",
            "threat_type": "payload",
            "malware": "win.wannacryptor",
            "malware_alias": "Wana Decrypt0r,WannaCry,WannaCrypt,Wcry",
            "malware_printable": "WannaCryptor",
            "first_seen_utc": "2026-06-29 01:23:07",
            "last_seen_utc": null,
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": "0",
            "reporter": "Grim"
        }
    ],
    "1838949": [
        {
            "ioc_value": "147c4f3da4b13ba13048e762128aeaf1270a9c9a47c7caf481feb947e4428794",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-06-29 01:23:07",
            "last_seen_utc": null,
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": "0",
            "reporter": "Grim"
        }
    ],
    "1838950": [
        {
            "ioc_value": "4b02778c2e6387e73baa0b8404cf7346cd625695",
            "ioc_type": "sha1_hash",
            "threat_type": "payload",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-06-29 01:23:07",
            "last_seen_utc": null,
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": "0",
            "reporter": "Grim"
        }
    ],
    "1838944": [
        {
            "ioc_value": "56210b7439f90f92eba1093292e3b23e6127f693",
            "ioc_type": "sha1_hash",
            "threat_type": "payload",
            "malware": "win.ghost_rat",
            "malware_alias": "Farfli,Gh0st RAT,PCRat",
            "malware_printable": "Ghost RAT",
            "first_seen_utc": "2026-06-29 01:23:06",
            "last_seen_utc": null,
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": "0",
            "reporter": "Grim"
        }
    ],
    "1838945": [
        {
            "ioc_value": "b2930338fad806be737dd392270160dc",
            "ioc_type": "md5_hash",
            "threat_type": "payload",
            "malware": "win.ghost_rat",
            "malware_alias": "Farfli,Gh0st RAT,PCRat",
            "malware_printable": "Ghost RAT",
            "first_seen_utc": "2026-06-29 01:23:06",
            "last_seen_utc": null,
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": "0",
            "reporter": "Grim"
        }
    ],
    "1838946": [
        {
            "ioc_value": "555cb9ec0842dce18895c26b81fc108cadc4958970235631fd703d31d7e6ba65",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "win.wannacryptor",
            "malware_alias": "Wana Decrypt0r,WannaCry,WannaCrypt,Wcry",
            "malware_printable": "WannaCryptor",
            "first_seen_utc": "2026-06-29 01:23:06",
            "last_seen_utc": null,
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": "0",
            "reporter": "Grim"
        }
    ],
    "1838941": [
        {
            "ioc_value": "c817079b896094d9aaf6be570b7ee03f87323cea",
            "ioc_type": "sha1_hash",
            "threat_type": "payload",
            "malware": "win.gcleaner",
            "malware_alias": null,
            "malware_printable": "GCleaner",
            "first_seen_utc": "2026-06-29 01:23:05",
            "last_seen_utc": null,
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": "0",
            "reporter": "Grim"
        }
    ],
    "1838942": [
        {
            "ioc_value": "1413fa8b1bc8437830fe7dcfc19ebd90",
            "ioc_type": "md5_hash",
            "threat_type": "payload",
            "malware": "win.gcleaner",
            "malware_alias": null,
            "malware_printable": "GCleaner",
            "first_seen_utc": "2026-06-29 01:23:05",
            "last_seen_utc": null,
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": "0",
            "reporter": "Grim"
        }
    ],
    "1838943": [
        {
            "ioc_value": "fcd0a4054eba07a6e2c6697c7e6f116afe494e43cce7ceb99cea6d1ba6faf0b4",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "win.ghost_rat",
            "malware_alias": "Farfli,Gh0st RAT,PCRat",
            "malware_printable": "Ghost RAT",
            "first_seen_utc": "2026-06-29 01:23:05",
            "last_seen_utc": null,
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": "0",
            "reporter": "Grim"
        }
    ],
    "1838938": [
        {
            "ioc_value": "79b63082f73ed3cab60901b9256a81b78de4192b",
            "ioc_type": "sha1_hash",
            "threat_type": "payload",
            "malware": "win.valley_rat",
            "malware_alias": "Winos",
            "malware_printable": "ValleyRAT",
            "first_seen_utc": "2026-06-29 01:23:04",
            "last_seen_utc": null,
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": "0",
            "reporter": "Grim"
        }
    ],
    "1838939": [
        {
            "ioc_value": "29e09a2fdea6179f9ac0bbfffecfba99",
            "ioc_type": "md5_hash",
            "threat_type": "payload",
            "malware": "win.valley_rat",
            "malware_alias": "Winos",
            "malware_printable": "ValleyRAT",
            "first_seen_utc": "2026-06-29 01:23:04",
            "last_seen_utc": null,
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": "0",
            "reporter": "Grim"
        }
    ],
    "1838940": [
        {
            "ioc_value": "0befde76298e1cd14983e1ed0c5858c29a46381f45592acfc9143deca6fc6ecb",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "win.gcleaner",
            "malware_alias": null,
            "malware_printable": "GCleaner",
            "first_seen_utc": "2026-06-29 01:23:04",
            "last_seen_utc": null,
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": "0",
            "reporter": "Grim"
        }
    ],
    "1838935": [
        {
            "ioc_value": "e9e83354951260d9485f21cdaacf954034f1fe05",
            "ioc_type": "sha1_hash",
            "threat_type": "payload",
            "malware": "py.venus_stealer",
            "malware_alias": null,
            "malware_printable": "Venus Stealer",
            "first_seen_utc": "2026-06-29 01:23:03",
            "last_seen_utc": null,
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": "0",
            "reporter": "Grim"
        }
    ],
    "1838936": [
        {
            "ioc_value": "ce93846b8a4d42531f4e5950a817bcc1",
            "ioc_type": "md5_hash",
            "threat_type": "payload",
            "malware": "py.venus_stealer",
            "malware_alias": null,
            "malware_printable": "Venus Stealer",
            "first_seen_utc": "2026-06-29 01:23:03",
            "last_seen_utc": null,
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": "0",
            "reporter": "Grim"
        }
    ],
    "1838937": [
        {
            "ioc_value": "670482ef4243ca62c495b94b86af529e5b44fa449e524613cee373dd0aa549af",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "win.valley_rat",
            "malware_alias": "Winos",
            "malware_printable": "ValleyRAT",
            "first_seen_utc": "2026-06-29 01:23:03",
            "last_seen_utc": null,
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": "0",
            "reporter": "Grim"
        }
    ],
    "1838932": [
        {
            "ioc_value": "896235eebadf15fb2fe4333e109b9c7d3e2b7432",
            "ioc_type": "sha1_hash",
            "threat_type": "payload",
            "malware": "win.nanocore",
            "malware_alias": "Nancrat,NanoCore",
            "malware_printable": "Nanocore RAT",
            "first_seen_utc": "2026-06-29 01:23:02",
            "last_seen_utc": null,
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": "0",
            "reporter": "Grim"
        }
    ],
    "1838933": [
        {
            "ioc_value": "3dcd3e2a1919055bd32c83dab86da59e",
            "ioc_type": "md5_hash",
            "threat_type": "payload",
            "malware": "win.nanocore",
            "malware_alias": "Nancrat,NanoCore",
            "malware_printable": "Nanocore RAT",
            "first_seen_utc": "2026-06-29 01:23:02",
            "last_seen_utc": null,
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": "0",
            "reporter": "Grim"
        }
    ],
    "1838934": [
        {
            "ioc_value": "bb9433e362bc054482b4dda309b67271b0de66bd4facb5370d2c48c3a2f69b17",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "py.venus_stealer",
            "malware_alias": null,
            "malware_printable": "Venus Stealer",
            "first_seen_utc": "2026-06-29 01:23:02",
            "last_seen_utc": null,
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": "0",
            "reporter": "Grim"
        }
    ],
    "1838929": [
        {
            "ioc_value": "1db264fab7a33a9962423109aa9fdcf1688eee74",
            "ioc_type": "sha1_hash",
            "threat_type": "payload",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-06-29 01:23:01",
            "last_seen_utc": null,
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": "0",
            "reporter": "Grim"
        }
    ],
    "1838930": [
        {
            "ioc_value": "8871665f04a761afb82cd425a9419130",
            "ioc_type": "md5_hash",
            "threat_type": "payload",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-06-29 01:23:01",
            "last_seen_utc": null,
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": "0",
            "reporter": "Grim"
        }
    ],
    "1838931": [
        {
            "ioc_value": "8258d0072d4ce97403d82e6560f46d9e135ff8783ed04409870ad7df03035953",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "win.nanocore",
            "malware_alias": "Nancrat,NanoCore",
            "malware_printable": "Nanocore RAT",
            "first_seen_utc": "2026-06-29 01:23:01",
            "last_seen_utc": null,
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": "0",
            "reporter": "Grim"
        }
    ],
    "1838927": [
        {
            "ioc_value": "de295da07916a1e68e05fb9f6eb4fee5",
            "ioc_type": "md5_hash",
            "threat_type": "payload",
            "malware": "win.netwire",
            "malware_alias": "NetWeird,NetWire,Recam",
            "malware_printable": "NetWire RC",
            "first_seen_utc": "2026-06-29 01:23:00",
            "last_seen_utc": null,
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": "0",
            "reporter": "Grim"
        }
    ],
    "1838928": [
        {
            "ioc_value": "536a20ad2c2de578288f060adba7ce718ca8b4ad3e9111e6e461dd482bd34cc8",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-06-29 01:23:00",
            "last_seen_utc": null,
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": "0",
            "reporter": "Grim"
        }
    ],
    "1838923": [
        {
            "ioc_value": "007293c1ec4879705375c9f89dfaa78a8b45db6a",
            "ioc_type": "sha1_hash",
            "threat_type": "payload",
            "malware": "win.netwire",
            "malware_alias": "NetWeird,NetWire,Recam",
            "malware_printable": "NetWire RC",
            "first_seen_utc": "2026-06-29 01:22:59",
            "last_seen_utc": null,
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": "0",
            "reporter": "Grim"
        }
    ],
    "1838924": [
        {
            "ioc_value": "9ac45cd7937cadf8ee6e9b45484aaec5",
            "ioc_type": "md5_hash",
            "threat_type": "payload",
            "malware": "win.netwire",
            "malware_alias": "NetWeird,NetWire,Recam",
            "malware_printable": "NetWire RC",
            "first_seen_utc": "2026-06-29 01:22:59",
            "last_seen_utc": null,
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": "0",
            "reporter": "Grim"
        }
    ],
    "1838925": [
        {
            "ioc_value": "d70a183081591e5760f750c5ecf24cac4bd9d9db61b3269ab4933401649cacfa",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "win.netwire",
            "malware_alias": "NetWeird,NetWire,Recam",
            "malware_printable": "NetWire RC",
            "first_seen_utc": "2026-06-29 01:22:59",
            "last_seen_utc": null,
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": "0",
            "reporter": "Grim"
        }
    ],
    "1838926": [
        {
            "ioc_value": "f66b4f00e56a4f100c6f179b30e06285ae4230fa",
            "ioc_type": "sha1_hash",
            "threat_type": "payload",
            "malware": "win.netwire",
            "malware_alias": "NetWeird,NetWire,Recam",
            "malware_printable": "NetWire RC",
            "first_seen_utc": "2026-06-29 01:22:59",
            "last_seen_utc": null,
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": "0",
            "reporter": "Grim"
        }
    ],
    "1838920": [
        {
            "ioc_value": "a8cbb1b5420146a7d3f57bf4115caa96d8930b42",
            "ioc_type": "sha1_hash",
            "threat_type": "payload",
            "malware": "elf.zhtrap",
            "malware_alias": null,
            "malware_printable": "ZHtrap",
            "first_seen_utc": "2026-06-29 01:22:58",
            "last_seen_utc": null,
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": "0",
            "reporter": "Grim"
        }
    ],
    "1838921": [
        {
            "ioc_value": "cdce6c8c32f041f574161f7e2edfd398",
            "ioc_type": "md5_hash",
            "threat_type": "payload",
            "malware": "elf.zhtrap",
            "malware_alias": null,
            "malware_printable": "ZHtrap",
            "first_seen_utc": "2026-06-29 01:22:58",
            "last_seen_utc": null,
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": "0",
            "reporter": "Grim"
        }
    ],
    "1838922": [
        {
            "ioc_value": "09f9d5761ddd83f5830852c9958b35c2f379dbdb1f2ad8a35a8a442911726c28",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "win.netwire",
            "malware_alias": "NetWeird,NetWire,Recam",
            "malware_printable": "NetWire RC",
            "first_seen_utc": "2026-06-29 01:22:58",
            "last_seen_utc": null,
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": "0",
            "reporter": "Grim"
        }
    ],
    "1838917": [
        {
            "ioc_value": "a136cb341ae29b97ce6cb1d980bc8c793d85d8bd",
            "ioc_type": "sha1_hash",
            "threat_type": "payload",
            "malware": "win.netwire",
            "malware_alias": "NetWeird,NetWire,Recam",
            "malware_printable": "NetWire RC",
            "first_seen_utc": "2026-06-29 01:22:57",
            "last_seen_utc": null,
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": "0",
            "reporter": "Grim"
        }
    ],
    "1838918": [
        {
            "ioc_value": "ca4f85f75f459c4963f7e3eb4e295394",
            "ioc_type": "md5_hash",
            "threat_type": "payload",
            "malware": "win.netwire",
            "malware_alias": "NetWeird,NetWire,Recam",
            "malware_printable": "NetWire RC",
            "first_seen_utc": "2026-06-29 01:22:57",
            "last_seen_utc": null,
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": "0",
            "reporter": "Grim"
        }
    ],
    "1838919": [
        {
            "ioc_value": "9c9fd1ab06198b6d0aa3222006a7f97e2cb29c5ea3ab1d5f408784c008a32515",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "elf.zhtrap",
            "malware_alias": null,
            "malware_printable": "ZHtrap",
            "first_seen_utc": "2026-06-29 01:22:57",
            "last_seen_utc": null,
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": "0",
            "reporter": "Grim"
        }
    ],
    "1838914": [
        {
            "ioc_value": "e2885a36319e84ef9c8decc8d261192b13590754",
            "ioc_type": "sha1_hash",
            "threat_type": "payload",
            "malware": "win.gcleaner",
            "malware_alias": null,
            "malware_printable": "GCleaner",
            "first_seen_utc": "2026-06-29 01:22:56",
            "last_seen_utc": null,
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": "0",
            "reporter": "Grim"
        }
    ],
    "1838915": [
        {
            "ioc_value": "b953f81730955b8883bc2e8baa9091e6",
            "ioc_type": "md5_hash",
            "threat_type": "payload",
            "malware": "win.gcleaner",
            "malware_alias": null,
            "malware_printable": "GCleaner",
            "first_seen_utc": "2026-06-29 01:22:56",
            "last_seen_utc": null,
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": "0",
            "reporter": "Grim"
        }
    ],
    "1838916": [
        {
            "ioc_value": "20160e27904a71a77b26aeb6edb37aedc6ed18aaffb5f7eb3fbbab035ab3c458",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "win.netwire",
            "malware_alias": "NetWeird,NetWire,Recam",
            "malware_printable": "NetWire RC",
            "first_seen_utc": "2026-06-29 01:22:56",
            "last_seen_utc": null,
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": "0",
            "reporter": "Grim"
        }
    ],
    "1838910": [
        {
            "ioc_value": "b435de3e50714d774f42cfdefd710519915e7f987f69da8d5fc1963961519844",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "win.luca_stealer",
            "malware_alias": null,
            "malware_printable": "Luca Stealer",
            "first_seen_utc": "2026-06-29 01:22:55",
            "last_seen_utc": null,
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": "0",
            "reporter": "Grim"
        }
    ],
    "1838911": [
        {
            "ioc_value": "0a5b8f09e60b8c9598e16e1ffb37d877da4d069d",
            "ioc_type": "sha1_hash",
            "threat_type": "payload",
            "malware": "win.luca_stealer",
            "malware_alias": null,
            "malware_printable": "Luca Stealer",
            "first_seen_utc": "2026-06-29 01:22:55",
            "last_seen_utc": null,
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": "0",
            "reporter": "Grim"
        }
    ],
    "1838912": [
        {
            "ioc_value": "0184f5f0b05f0bfb33f2657836f00dd5",
            "ioc_type": "md5_hash",
            "threat_type": "payload",
            "malware": "win.luca_stealer",
            "malware_alias": null,
            "malware_printable": "Luca Stealer",
            "first_seen_utc": "2026-06-29 01:22:55",
            "last_seen_utc": null,
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": "0",
            "reporter": "Grim"
        }
    ],
    "1838913": [
        {
            "ioc_value": "11f50bd71ee026c644b2322d84b4a3e03b48455e34ebf478bd6afc32e0fdfbef",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "win.gcleaner",
            "malware_alias": null,
            "malware_printable": "GCleaner",
            "first_seen_utc": "2026-06-29 01:22:55",
            "last_seen_utc": null,
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": "0",
            "reporter": "Grim"
        }
    ],
    "1838908": [
        {
            "ioc_value": "1d0bf06fdc2505d6947d4b2825e888ab5148b68b",
            "ioc_type": "sha1_hash",
            "threat_type": "payload",
            "malware": "win.gcleaner",
            "malware_alias": null,
            "malware_printable": "GCleaner",
            "first_seen_utc": "2026-06-29 01:22:54",
            "last_seen_utc": null,
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": "0",
            "reporter": "Grim"
        }
    ],
    "1838909": [
        {
            "ioc_value": "3cc6072eca86948127764f87d84baa85",
            "ioc_type": "md5_hash",
            "threat_type": "payload",
            "malware": "win.gcleaner",
            "malware_alias": null,
            "malware_printable": "GCleaner",
            "first_seen_utc": "2026-06-29 01:22:54",
            "last_seen_utc": null,
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": "0",
            "reporter": "Grim"
        }
    ],
    "1838905": [
        {
            "ioc_value": "688f4b4ecfd26d2529d2c1b21a9d8be2f3245cc8",
            "ioc_type": "sha1_hash",
            "threat_type": "payload",
            "malware": "win.njrat",
            "malware_alias": "Bladabindi,Lime-Worm",
            "malware_printable": "NjRAT",
            "first_seen_utc": "2026-06-29 01:22:53",
            "last_seen_utc": null,
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": "0",
            "reporter": "Grim"
        }
    ],
    "1838906": [
        {
            "ioc_value": "193177af43f8f24851b76d2866a11e1f",
            "ioc_type": "md5_hash",
            "threat_type": "payload",
            "malware": "win.njrat",
            "malware_alias": "Bladabindi,Lime-Worm",
            "malware_printable": "NjRAT",
            "first_seen_utc": "2026-06-29 01:22:53",
            "last_seen_utc": null,
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": "0",
            "reporter": "Grim"
        }
    ],
    "1838907": [
        {
            "ioc_value": "e9c6dda67b1da1be30f8b0d4c7ff329c6b9831ae2c413742bbe59cc66690a630",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "win.gcleaner",
            "malware_alias": null,
            "malware_printable": "GCleaner",
            "first_seen_utc": "2026-06-29 01:22:53",
            "last_seen_utc": null,
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": "0",
            "reporter": "Grim"
        }
    ],
    "1838902": [
        {
            "ioc_value": "ed5bdffd8e51239effd147106709a026995deaee",
            "ioc_type": "sha1_hash",
            "threat_type": "payload",
            "malware": "win.wannacryptor",
            "malware_alias": "Wana Decrypt0r,WannaCry,WannaCrypt,Wcry",
            "malware_printable": "WannaCryptor",
            "first_seen_utc": "2026-06-29 01:22:52",
            "last_seen_utc": null,
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": "0",
            "reporter": "Grim"
        }
    ],
    "1838903": [
        {
            "ioc_value": "388ed6c8e9e5ba54c49209337f0a71a6",
            "ioc_type": "md5_hash",
            "threat_type": "payload",
            "malware": "win.wannacryptor",
            "malware_alias": "Wana Decrypt0r,WannaCry,WannaCrypt,Wcry",
            "malware_printable": "WannaCryptor",
            "first_seen_utc": "2026-06-29 01:22:52",
            "last_seen_utc": null,
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": "0",
            "reporter": "Grim"
        }
    ],
    "1838904": [
        {
            "ioc_value": "cd1ab1369c5b2090a046e27574158e038fabdabc695623b3e85810246990e351",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "win.njrat",
            "malware_alias": "Bladabindi,Lime-Worm",
            "malware_printable": "NjRAT",
            "first_seen_utc": "2026-06-29 01:22:52",
            "last_seen_utc": null,
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": "0",
            "reporter": "Grim"
        }
    ],
    "1838901": [
        {
            "ioc_value": "ffb966fce55f67726e7f8084a1dc21b80650e5c05373529b35d93eafcfcc7e26",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "win.wannacryptor",
            "malware_alias": "Wana Decrypt0r,WannaCry,WannaCrypt,Wcry",
            "malware_printable": "WannaCryptor",
            "first_seen_utc": "2026-06-29 01:22:51",
            "last_seen_utc": null,
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": "0",
            "reporter": "Grim"
        }
    ],
    "1838900": [
        {
            "ioc_value": "38.54.117.107:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-06-29 01:05:06",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "cobaltstrike",
            "anonymous": "1",
            "reporter": "_ik_"
        }
    ],
    "1838899": [
        {
            "ioc_value": "88.216.208.91:65523",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.vshell",
            "malware_alias": null,
            "malware_printable": "VShell",
            "first_seen_utc": "2026-06-29 01:05:04",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "vshell",
            "anonymous": "1",
            "reporter": "_ik_"
        }
    ],
    "1838898": [
        {
            "ioc_value": "38.54.117.107:6666",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-06-28 23:45:51",
            "last_seen_utc": "2026-06-30 10:46:59",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1838897": [
        {
            "ioc_value": "117.72.159.96:8777",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-06-28 23:45:35",
            "last_seen_utc": "2026-06-30 10:46:38",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1838896": [
        {
            "ioc_value": "103.73.161.60:9005",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-06-28 23:45:30",
            "last_seen_utc": "2026-06-30 10:46:32",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1838895": [
        {
            "ioc_value": "82.157.191.79:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-06-28 23:05:05",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "cobaltstrike",
            "anonymous": "1",
            "reporter": "_ik_"
        }
    ],
    "1838894": [
        {
            "ioc_value": "104.248.201.191:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-06-28 22:05:05",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "cobaltstrike",
            "anonymous": "1",
            "reporter": "_ik_"
        }
    ],
    "1838893": [
        {
            "ioc_value": "8zdusrwn.xbetone.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-28 21:51:44",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "clearfake",
            "anonymous": "1",
            "reporter": "ttakvam"
        }
    ],
    "1838892": [
        {
            "ioc_value": "dows.sabad724.bio",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-28 21:47:56",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake",
            "anonymous": "1",
            "reporter": "ttakvam"
        }
    ],
    "1838891": [
        {
            "ioc_value": "htfll3q5.1x303.casino",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-28 21:42:56",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "clearfake",
            "anonymous": "1",
            "reporter": "ttakvam"
        }
    ],
    "1838806": [
        {
            "ioc_value": "https://vihangamyoga.org/",
            "ioc_type": "url",
            "threat_type": "payload_delivery",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-06-28 21:15:03",
            "last_seen_utc": "2026-06-28 23:31:03",
            "confidence_level": 75,
            "is_compromised": true,
            "reference": null,
            "tags": "ClickFix,compromised,EtherHiding,Polygon,Vidar,WordPress",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1838805": [
        {
            "ioc_value": "82.157.191.79:8001",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-06-28 20:05:05",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "cobaltstrike",
            "anonymous": "1",
            "reporter": "_ik_"
        }
    ],
    "1838803": [
        {
            "ioc_value": "54.180.147.42:7707",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-06-28 19:45:13",
            "last_seen_utc": "2026-06-30 10:45:55",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1838804": [
        {
            "ioc_value": "54.180.147.42:8808",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-06-28 19:45:13",
            "last_seen_utc": "2026-06-30 10:45:55",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1838801": [
        {
            "ioc_value": "5.8.19.157:14645",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-06-28 19:45:11",
            "last_seen_utc": "2026-06-30 10:45:53",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1838802": [
        {
            "ioc_value": "5.8.19.157:14646",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-06-28 19:45:11",
            "last_seen_utc": "2026-06-30 10:45:53",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1838800": [
        {
            "ioc_value": "45.94.23.42:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-06-28 19:45:00",
            "last_seen_utc": "2026-06-30 10:45:43",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1838799": [
        {
            "ioc_value": "45.150.38.95:4321",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-06-28 19:44:54",
            "last_seen_utc": "2026-06-30 10:45:36",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1838798": [
        {
            "ioc_value": "199.247.14.228:8080",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.chaos",
            "malware_alias": "FakeRyuk,RyukJoke,Yashma",
            "malware_printable": "Chaos",
            "first_seen_utc": "2026-06-28 19:44:04",
            "last_seen_utc": "2026-06-30 10:44:24",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CHAOS,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1838797": [
        {
            "ioc_value": "185.115.164.59:2892",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-06-28 19:43:47",
            "last_seen_utc": "2026-06-30 10:44:00",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1838796": [
        {
            "ioc_value": "109.227.35.147:4433",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.danabot",
            "malware_alias": "DanaTools",
            "malware_printable": "DanaBot",
            "first_seen_utc": "2026-06-28 19:43:12",
            "last_seen_utc": "2026-06-30 10:43:16",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DanBot,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1838793": [
        {
            "ioc_value": "103.11.41.10:8237",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-06-28 19:43:05",
            "last_seen_utc": "2026-06-30 10:43:06",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1838794": [
        {
            "ioc_value": "103.11.41.19:16666",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-06-28 19:43:05",
            "last_seen_utc": "2026-06-30 10:43:07",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1838795": [
        {
            "ioc_value": "103.11.41.20:1000",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-06-28 19:43:05",
            "last_seen_utc": "2026-06-30 10:43:07",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1838790": [
        {
            "ioc_value": "106.52.59.233:39001",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.vshell",
            "malware_alias": null,
            "malware_printable": "VShell",
            "first_seen_utc": "2026-06-28 19:05:06",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "vshell",
            "anonymous": "1",
            "reporter": "_ik_"
        }
    ],
    "1838789": [
        {
            "ioc_value": "104.248.201.191:8080",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-06-28 19:05:05",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "cobaltstrike",
            "anonymous": "1",
            "reporter": "_ik_"
        }
    ],
    "1838788": [
        {
            "ioc_value": "fjy9zygx.1xsignupbet.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-28 18:51:27",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "clearfake",
            "anonymous": "1",
            "reporter": "ttakvam"
        }
    ],
    "1838786": [
        {
            "ioc_value": "huz6wkqi.mokatebatedari.xyz",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-28 17:50:52",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "clearfake",
            "anonymous": "1",
            "reporter": "ttakvam"
        }
    ],
    "1838785": [
        {
            "ioc_value": "mokatebatedari.xyz",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-28 17:50:03",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake",
            "anonymous": "0",
            "reporter": "threatcat_ch"
        }
    ],
    "1838784": [
        {
            "ioc_value": "82.157.78.201:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-06-28 16:05:05",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "cobaltstrike",
            "anonymous": "1",
            "reporter": "_ik_"
        }
    ],
    "1838783": [
        {
            "ioc_value": "jarayemaleyhamval.xyz",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-28 15:49:26",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake",
            "anonymous": "0",
            "reporter": "threatcat_ch"
        }
    ],
    "1838780": [
        {
            "ioc_value": "http://103.146.231.107:80/DFne",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-06-28 15:15:53",
            "last_seen_utc": null,
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://bazaar.abuse.ch/sample/536a20ad2c2de578288f060adba7ce718ca8b4ad3e9111e6e461dd482bd34cc8/",
            "tags": "cobaltstrike",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1838772": [
        {
            "ioc_value": "https://geurtuin.com/?doing_wp_cron=1782651363.9469881057739257812500",
            "ioc_type": "url",
            "threat_type": "payload_delivery",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-06-28 14:38:00",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": "https://clickfix.carsonww.com/domains/geurtuin.com",
            "tags": "ClickFix",
            "anonymous": "0",
            "reporter": "CarsonWilliams"
        }
    ],
    "1838775": [
        {
            "ioc_value": "vacante-ieftine.ro",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.iclickfix",
            "malware_alias": null,
            "malware_printable": "IClickFix",
            "first_seen_utc": "2026-06-28 14:38:00",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": "",
            "tags": "ClickFix,FakeCF",
            "anonymous": "0",
            "reporter": "varysz"
        }
    ],
    "1838776": [
        {
            "ioc_value": "genova.com.vn",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.iclickfix",
            "malware_alias": null,
            "malware_printable": "IClickFix",
            "first_seen_utc": "2026-06-28 14:37:59",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": "",
            "tags": "ClickFix,FakeCF",
            "anonymous": "0",
            "reporter": "varysz"
        }
    ],
    "1838777": [
        {
            "ioc_value": "geurtuin.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.iclickfix",
            "malware_alias": null,
            "malware_printable": "IClickFix",
            "first_seen_utc": "2026-06-28 14:37:59",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": "",
            "tags": "ClickFix,FakeCF",
            "anonymous": "0",
            "reporter": "varysz"
        }
    ],
    "1838778": [
        {
            "ioc_value": "engr-salahuddin.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.iclickfix",
            "malware_alias": null,
            "malware_printable": "IClickFix",
            "first_seen_utc": "2026-06-28 14:37:58",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": "",
            "tags": "ClickFix,FakeCF",
            "anonymous": "0",
            "reporter": "varysz"
        }
    ],
    "1838779": [
        {
            "ioc_value": "https://citrusocarpetscleaning.com/",
            "ioc_type": "url",
            "threat_type": "payload_delivery",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-06-28 14:37:58",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": "https://clickfix.carsonww.com/domains/citrusocarpetscleaning.com",
            "tags": "ClickFix",
            "anonymous": "0",
            "reporter": "CarsonWilliams"
        }
    ],
    "1838774": [
        {
            "ioc_value": "nqxr9m1i.iranfitness.top",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-28 13:50:10",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "clearfake",
            "anonymous": "1",
            "reporter": "ttakvam"
        }
    ],
    "1838773": [
        {
            "ioc_value": "iranfitness.top",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-28 13:48:55",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake",
            "anonymous": "0",
            "reporter": "threatcat_ch"
        }
    ],
    "1838771": [
        {
            "ioc_value": "http://lawofi.xyz:7538",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.remus",
            "malware_alias": null,
            "malware_printable": "Remus",
            "first_seen_utc": "2026-06-28 13:10:43",
            "last_seen_utc": null,
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://bazaar.abuse.ch/sample/bb9433e362bc054482b4dda309b67271b0de66bd4facb5370d2c48c3a2f69b17/",
            "tags": "remus",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1838744": [
        {
            "ioc_value": "lawofi.xyz",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.remus",
            "malware_alias": null,
            "malware_printable": "Remus",
            "first_seen_utc": "2026-06-28 13:07:11",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://bazaar.abuse.ch/sample/c86b1625d01dbd8c7dd9e5cc17a438c1c39bb333bd71e2062a89e241d1875263/",
            "tags": "c2,RemusStealer",
            "anonymous": "0",
            "reporter": "burger"
        }
    ],
    "1838746": [
        {
            "ioc_value": "https://bibliorock.lol/",
            "ioc_type": "url",
            "threat_type": "payload_delivery",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-06-28 13:07:10",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": "https://clickfix.carsonww.com/domains/bibliorock.lol",
            "tags": "ClickFix",
            "anonymous": "0",
            "reporter": "CarsonWilliams"
        }
    ],
    "1838747": [
        {
            "ioc_value": "https://memshowblob.forum/",
            "ioc_type": "url",
            "threat_type": "payload_delivery",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-06-28 13:07:10",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": "https://clickfix.carsonww.com/domains/memshowblob.forum",
            "tags": "ClickFix",
            "anonymous": "0",
            "reporter": "CarsonWilliams"
        }
    ],
    "1838748": [
        {
            "ioc_value": "https://mistertwister.sale/",
            "ioc_type": "url",
            "threat_type": "payload_delivery",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-06-28 13:07:09",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": "https://clickfix.carsonww.com/domains/mistertwister.sale",
            "tags": "ClickFix",
            "anonymous": "0",
            "reporter": "CarsonWilliams"
        }
    ],
    "1838766": [
        {
            "ioc_value": "http://153.117.41.29:45738/Mozi.m",
            "ioc_type": "url",
            "threat_type": "payload_delivery",
            "malware": "elf.mozi",
            "malware_alias": null,
            "malware_printable": "Mozi",
            "first_seen_utc": "2026-06-28 13:07:08",
            "last_seen_utc": null,
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://honeylabs.net/lookup/153.117.41.29",
            "tags": "elf,iot,Mozi",
            "anonymous": "0",
            "reporter": "HoneyLabs"
        }
    ],
    "1838767": [
        {
            "ioc_value": "http://175.107.208.203:48676/Mozi.m",
            "ioc_type": "url",
            "threat_type": "payload_delivery",
            "malware": "elf.mozi",
            "malware_alias": null,
            "malware_printable": "Mozi",
            "first_seen_utc": "2026-06-28 13:07:08",
            "last_seen_utc": null,
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://honeylabs.net/lookup/175.107.208.203",
            "tags": "elf,iot,Mozi",
            "anonymous": "0",
            "reporter": "HoneyLabs"
        }
    ],
    "1838769": [
        {
            "ioc_value": "27.124.43.241:12159",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.dcrat",
            "malware_alias": "DarkCrystal RAT",
            "malware_printable": "DCRat",
            "first_seen_utc": "2026-06-28 13:05:06",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "dcrat",
            "anonymous": "1",
            "reporter": "_ik_"
        }
    ],
    "1838770": [
        {
            "ioc_value": "185.126.115.48:4443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.quasar_rat",
            "malware_alias": "CinaRAT,QuasarRAT,Yggdrasil",
            "malware_printable": "Quasar RAT",
            "first_seen_utc": "2026-06-28 13:05:06",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "quasarrat",
            "anonymous": "1",
            "reporter": "_ik_"
        }
    ],
    "1838768": [
        {
            "ioc_value": "82.157.78.201:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-06-28 13:05:05",
            "last_seen_utc": "2026-06-30 09:53:50",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "cobaltstrike",
            "anonymous": "1",
            "reporter": "_ik_"
        }
    ],
    "1838765": [
        {
            "ioc_value": "fagaheestedlali.xyz",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-28 11:46:53",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake",
            "anonymous": "0",
            "reporter": "threatcat_ch"
        }
    ],
    "1838764": [
        {
            "ioc_value": "1bmaiu5y.1xbetpartnersiran.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-28 11:42:26",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "clearfake",
            "anonymous": "1",
            "reporter": "ttakvam"
        }
    ],
    "1838758": [
        {
            "ioc_value": "bcxmyrgq.betbuf.live",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-28 09:46:02",
            "last_seen_utc": "2026-06-29 18:00:13",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake",
            "anonymous": "0",
            "reporter": "threatcat_ch"
        }
    ],
    "1838757": [
        {
            "ioc_value": "45.74.7.173:9521",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-06-28 09:45:16",
            "last_seen_utc": "2026-06-30 10:45:41",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1838756": [
        {
            "ioc_value": "192.162.199.149:7707",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-06-28 09:44:03",
            "last_seen_utc": "2026-06-30 10:44:14",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1838755": [
        {
            "ioc_value": "185.212.128.231:9000",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.evilginx",
            "malware_alias": null,
            "malware_printable": "Evilginx",
            "first_seen_utc": "2026-06-28 09:43:55",
            "last_seen_utc": "2026-06-30 10:44:06",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Evilginx,EvilGoPhish",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1838754": [
        {
            "ioc_value": "177.22.119.145:9001",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.danabot",
            "malware_alias": "DanaTools",
            "malware_printable": "DanaBot",
            "first_seen_utc": "2026-06-28 09:43:45",
            "last_seen_utc": "2026-06-30 10:43:52",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DanBot,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1838753": [
        {
            "ioc_value": "167.94.81.175:62722",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-06-28 09:43:38",
            "last_seen_utc": "2026-06-30 10:43:45",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1838752": [
        {
            "ioc_value": "159.195.193.179:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-06-28 09:43:34",
            "last_seen_utc": "2026-06-30 10:43:39",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1838751": [
        {
            "ioc_value": "141.98.10.150:14648",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-06-28 09:43:21",
            "last_seen_utc": "2026-06-30 10:43:25",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1838750": [
        {
            "ioc_value": "103.83.87.87:25900",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-06-28 09:43:09",
            "last_seen_utc": "2026-06-30 10:43:11",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1838749": [
        {
            "ioc_value": "103.11.41.20:201",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-06-28 09:43:06",
            "last_seen_utc": "2026-06-30 10:43:07",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1838635": [
        {
            "ioc_value": "147.182.140.2:12345",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.aisuru",
            "malware_alias": null,
            "malware_printable": "Aisuru",
            "first_seen_utc": "2026-06-28 07:46:08",
            "last_seen_utc": "2026-06-30 00:34:55",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "Aisuru,c2",
            "anonymous": "0",
            "reporter": "Bitsight"
        }
    ],
    "1838703": [
        {
            "ioc_value": "bibliorock.lol",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-06-28 07:45:56",
            "last_seen_utc": "2026-06-29 13:26:16",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "",
            "tags": "c2,ClickFix,Polygon",
            "anonymous": "0",
            "reporter": "varysz"
        }
    ],
    "1838704": [
        {
            "ioc_value": "mistertwister.sale",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-06-28 07:45:55",
            "last_seen_utc": "2026-06-30 06:26:27",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "c2,ClickFix,Polygon",
            "anonymous": "0",
            "reporter": "varysz"
        }
    ],
    "1838705": [
        {
            "ioc_value": "memshowblob.forum",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-06-28 07:45:53",
            "last_seen_utc": "2026-06-29 13:26:17",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "c2,ClickFix,Polygon",
            "anonymous": "0",
            "reporter": "varysz"
        }
    ],
    "1838736": [
        {
            "ioc_value": "149.50.96.57:8000",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-06-28 07:05:07",
            "last_seen_utc": "2026-06-30 10:43:31",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "asyncrat",
            "anonymous": "1",
            "reporter": "_ik_"
        }
    ],
    "1838730": [
        {
            "ioc_value": "47.236.116.9:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.amadey",
            "malware_alias": null,
            "malware_printable": "Amadey",
            "first_seen_utc": "2026-06-28 06:36:01",
            "last_seen_utc": "2026-06-30 11:24:02",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": "https://tracker.viriback.com/index.php?q=47.236.116.9",
            "tags": "Amadey,ViriBack",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1838724": [
        {
            "ioc_value": "http://47.236.116.9/y8jdGc5jS/index.php",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.amadey",
            "malware_alias": null,
            "malware_printable": "Amadey",
            "first_seen_utc": "2026-06-28 04:45:05",
            "last_seen_utc": "2026-06-29 08:41:24",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "Amadey",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1838710": [
        {
            "ioc_value": "45.227.253.121:52445",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-06-27 23:46:10",
            "last_seen_utc": "2026-06-30 10:47:07",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1838708": [
        {
            "ioc_value": "134.122.135.120:18443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-06-27 23:45:52",
            "last_seen_utc": "2026-06-30 10:46:44",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1838709": [
        {
            "ioc_value": "134.122.135.53:18443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-06-27 23:45:52",
            "last_seen_utc": "2026-06-30 10:46:44",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1838698": [
        {
            "ioc_value": "8cd1408dbe57b890cb7aac49c60567e659156f376075ef617d5d7afb588daa09",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "win.darkme",
            "malware_alias": null,
            "malware_printable": "DarkMe",
            "first_seen_utc": "2026-06-27 21:28:14",
            "last_seen_utc": "2026-06-29 01:23:31",
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": "0",
            "reporter": "Grim"
        }
    ],
    "1838699": [
        {
            "ioc_value": "6de94861e213b9b876edac4bdc716e141df735b7",
            "ioc_type": "sha1_hash",
            "threat_type": "payload",
            "malware": "win.darkme",
            "malware_alias": null,
            "malware_printable": "DarkMe",
            "first_seen_utc": "2026-06-27 21:28:14",
            "last_seen_utc": "2026-06-29 01:23:31",
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": "0",
            "reporter": "Grim"
        }
    ],
    "1838700": [
        {
            "ioc_value": "891776acc33d8c22e4667d51c8370d49",
            "ioc_type": "md5_hash",
            "threat_type": "payload",
            "malware": "win.darkme",
            "malware_alias": null,
            "malware_printable": "DarkMe",
            "first_seen_utc": "2026-06-27 21:28:14",
            "last_seen_utc": "2026-06-29 01:23:31",
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": "0",
            "reporter": "Grim"
        }
    ],
    "1838696": [
        {
            "ioc_value": "2b4e83cfdab5b79ae1aa1b4df8dd4503a9c99deb",
            "ioc_type": "sha1_hash",
            "threat_type": "payload",
            "malware": "jar.crossrat",
            "malware_alias": "Trupto",
            "malware_printable": "CrossRAT",
            "first_seen_utc": "2026-06-27 21:28:13",
            "last_seen_utc": "2026-06-29 01:23:30",
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": "0",
            "reporter": "Grim"
        }
    ],
    "1838697": [
        {
            "ioc_value": "038112c489a65525aaa6c2ede6c33c2a",
            "ioc_type": "md5_hash",
            "threat_type": "payload",
            "malware": "jar.crossrat",
            "malware_alias": "Trupto",
            "malware_printable": "CrossRAT",
            "first_seen_utc": "2026-06-27 21:28:13",
            "last_seen_utc": "2026-06-29 01:23:30",
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": "0",
            "reporter": "Grim"
        }
    ],
    "1838693": [
        {
            "ioc_value": "8c00b490332ca6af591294e1b2ffd01e708c612f",
            "ioc_type": "sha1_hash",
            "threat_type": "payload",
            "malware": "win.quasar_rat",
            "malware_alias": "CinaRAT,QuasarRAT,Yggdrasil",
            "malware_printable": "Quasar RAT",
            "first_seen_utc": "2026-06-27 21:28:12",
            "last_seen_utc": "2026-06-29 01:23:29",
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": "0",
            "reporter": "Grim"
        }
    ],
    "1838694": [
        {
            "ioc_value": "2549dc1f259917a6179f726de0ed45e7",
            "ioc_type": "md5_hash",
            "threat_type": "payload",
            "malware": "win.quasar_rat",
            "malware_alias": "CinaRAT,QuasarRAT,Yggdrasil",
            "malware_printable": "Quasar RAT",
            "first_seen_utc": "2026-06-27 21:28:12",
            "last_seen_utc": "2026-06-29 01:23:29",
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": "0",
            "reporter": "Grim"
        }
    ],
    "1838695": [
        {
            "ioc_value": "737646392a7c882064e22ecb9fc0b2732399e44ced2f56d873e656d0035af288",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "jar.crossrat",
            "malware_alias": "Trupto",
            "malware_printable": "CrossRAT",
            "first_seen_utc": "2026-06-27 21:28:12",
            "last_seen_utc": "2026-06-29 01:23:30",
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": "0",
            "reporter": "Grim"
        }
    ],
    "1838690": [
        {
            "ioc_value": "3eae959cc134d89dcfab4f8388569626e166be0e",
            "ioc_type": "sha1_hash",
            "threat_type": "payload",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-06-27 21:28:11",
            "last_seen_utc": "2026-06-29 01:23:28",
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": "0",
            "reporter": "Grim"
        }
    ],
    "1838691": [
        {
            "ioc_value": "885e4c62d17993ccffbfd44a1c128ddf",
            "ioc_type": "md5_hash",
            "threat_type": "payload",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-06-27 21:28:11",
            "last_seen_utc": "2026-06-29 01:23:29",
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": "0",
            "reporter": "Grim"
        }
    ],
    "1838692": [
        {
            "ioc_value": "feea6bd8a190f0820c19df24b870a205d5799a9c75ace8044542496650a91ef0",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "win.quasar_rat",
            "malware_alias": "CinaRAT,QuasarRAT,Yggdrasil",
            "malware_printable": "Quasar RAT",
            "first_seen_utc": "2026-06-27 21:28:11",
            "last_seen_utc": "2026-06-29 01:23:29",
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": "0",
            "reporter": "Grim"
        }
    ],
    "1838689": [
        {
            "ioc_value": "bac12c7b2bc08d4d552e4692bc1566d7d54efc67c3a1131628c491c23626d773",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-06-27 21:28:10",
            "last_seen_utc": "2026-06-29 01:23:28",
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": "0",
            "reporter": "Grim"
        }
    ],
    "1838686": [
        {
            "ioc_value": "f2cd38b6c081535971bc76d9aa3560ce3bf33e02986a430464a75e3261c4a8f1",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "win.wannacryptor",
            "malware_alias": "Wana Decrypt0r,WannaCry,WannaCrypt,Wcry",
            "malware_printable": "WannaCryptor",
            "first_seen_utc": "2026-06-27 21:28:09",
            "last_seen_utc": "2026-06-29 01:23:26",
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": "0",
            "reporter": "Grim"
        }
    ],
    "1838687": [
        {
            "ioc_value": "cc0ae92edb66b42397a1f91894c0e14d12c83454",
            "ioc_type": "sha1_hash",
            "threat_type": "payload",
            "malware": "win.wannacryptor",
            "malware_alias": "Wana Decrypt0r,WannaCry,WannaCrypt,Wcry",
            "malware_printable": "WannaCryptor",
            "first_seen_utc": "2026-06-27 21:28:09",
            "last_seen_utc": "2026-06-29 01:23:27",
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": "0",
            "reporter": "Grim"
        }
    ],
    "1838688": [
        {
            "ioc_value": "c0b5ba4fbb2d486362d4be79caecc2b9",
            "ioc_type": "md5_hash",
            "threat_type": "payload",
            "malware": "win.wannacryptor",
            "malware_alias": "Wana Decrypt0r,WannaCry,WannaCrypt,Wcry",
            "malware_printable": "WannaCryptor",
            "first_seen_utc": "2026-06-27 21:28:09",
            "last_seen_utc": "2026-06-29 01:23:27",
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": "0",
            "reporter": "Grim"
        }
    ],
    "1838684": [
        {
            "ioc_value": "b10573574be99566629f6ca88ba82d0e7e2122a7",
            "ioc_type": "sha1_hash",
            "threat_type": "payload",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-06-27 21:28:08",
            "last_seen_utc": "2026-06-29 01:23:18",
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": "0",
            "reporter": "Grim"
        }
    ],
    "1838685": [
        {
            "ioc_value": "f269378bb7d1c7817fa6200a1198b9df",
            "ioc_type": "md5_hash",
            "threat_type": "payload",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-06-27 21:28:08",
            "last_seen_utc": "2026-06-29 01:23:18",
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": "0",
            "reporter": "Grim"
        }
    ],
    "1838681": [
        {
            "ioc_value": "89eec27c0af96d4932891f02c0a7988b05526012",
            "ioc_type": "sha1_hash",
            "threat_type": "payload",
            "malware": "win.socks5_systemz",
            "malware_alias": "ProxyBox",
            "malware_printable": "Socks5Systemz",
            "first_seen_utc": "2026-06-27 21:28:07",
            "last_seen_utc": "2026-06-29 01:23:16",
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": "0",
            "reporter": "Grim"
        }
    ],
    "1838682": [
        {
            "ioc_value": "52c76d9b7366f34a1fad3b5b0527e24f",
            "ioc_type": "md5_hash",
            "threat_type": "payload",
            "malware": "win.socks5_systemz",
            "malware_alias": "ProxyBox",
            "malware_printable": "Socks5Systemz",
            "first_seen_utc": "2026-06-27 21:28:07",
            "last_seen_utc": "2026-06-29 01:23:17",
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": "0",
            "reporter": "Grim"
        }
    ],
    "1838683": [
        {
            "ioc_value": "abb0ddc5d6972b69a938f88cbc354dffbd14adcd13b8049e6654f51dd3f5836d",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-06-27 21:28:07",
            "last_seen_utc": "2026-06-29 01:23:18",
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": "0",
            "reporter": "Grim"
        }
    ],
    "1838680": [
        {
            "ioc_value": "716612c11982500cca51970f822ddffb5a4b3aa84fda3cb30ffab6daa94f5248",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "win.socks5_systemz",
            "malware_alias": "ProxyBox",
            "malware_printable": "Socks5Systemz",
            "first_seen_utc": "2026-06-27 21:28:06",
            "last_seen_utc": "2026-06-29 01:23:16",
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": "0",
            "reporter": "Grim"
        }
    ],
    "1838676": [
        {
            "ioc_value": "103.146.231.107:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-06-27 19:46:07",
            "last_seen_utc": "2026-06-30 10:46:31",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1838675": [
        {
            "ioc_value": "85.137.249.185:8977",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-06-27 19:45:47",
            "last_seen_utc": "2026-06-30 10:46:11",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1838674": [
        {
            "ioc_value": "80.211.129.141:1234",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-06-27 19:45:43",
            "last_seen_utc": "2026-06-30 10:46:07",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1838672": [
        {
            "ioc_value": "68.64.178.130:48951",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-06-27 19:45:40",
            "last_seen_utc": "2026-06-30 10:46:01",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1838673": [
        {
            "ioc_value": "69.48.228.170:65531",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-06-27 19:45:40",
            "last_seen_utc": "2026-06-30 10:46:04",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1838670": [
        {
            "ioc_value": "5.8.18.155:992",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.bianlian",
            "malware_alias": null,
            "malware_printable": "BianLian",
            "first_seen_utc": "2026-06-27 19:45:33",
            "last_seen_utc": "2026-06-30 10:45:53",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "Bianlian,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1838671": [
        {
            "ioc_value": "5.8.19.157:14644",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-06-27 19:45:33",
            "last_seen_utc": "2026-06-30 10:45:53",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1838669": [
        {
            "ioc_value": "5.206.224.226:2404",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-06-27 19:45:32",
            "last_seen_utc": "2026-06-30 10:45:52",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1838668": [
        {
            "ioc_value": "45.74.7.170:3305",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-06-27 19:45:22",
            "last_seen_utc": "2026-06-30 10:45:41",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1838666": [
        {
            "ioc_value": "45.74.7.165:8455",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-06-27 19:45:21",
            "last_seen_utc": "2026-06-30 10:45:41",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1838667": [
        {
            "ioc_value": "45.74.7.169:7312",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-06-27 19:45:21",
            "last_seen_utc": "2026-06-30 10:45:41",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1838665": [
        {
            "ioc_value": "45.141.234.47:4321",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-06-27 19:45:17",
            "last_seen_utc": "2026-06-30 10:45:36",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1838664": [
        {
            "ioc_value": "37.220.31.90:61135",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-06-27 19:45:09",
            "last_seen_utc": "2026-06-30 10:45:28",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1838663": [
        {
            "ioc_value": "185.212.128.139:9000",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.evilginx",
            "malware_alias": null,
            "malware_printable": "Evilginx",
            "first_seen_utc": "2026-06-27 19:43:58",
            "last_seen_utc": "2026-06-30 10:44:05",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Evilginx,EvilGoPhish",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1838662": [
        {
            "ioc_value": "178.83.121.60:48203",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-06-27 19:43:49",
            "last_seen_utc": "2026-06-30 10:43:54",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1838661": [
        {
            "ioc_value": "173.231.188.244:14646",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-06-27 19:43:46",
            "last_seen_utc": "2026-06-30 10:43:51",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1838660": [
        {
            "ioc_value": "155.94.163.75:8797",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-06-27 19:43:32",
            "last_seen_utc": "2026-06-30 10:43:36",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1838659": [
        {
            "ioc_value": "138.124.84.7:4321",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-06-27 19:43:20",
            "last_seen_utc": "2026-06-30 10:43:23",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1838657": [
        {
            "ioc_value": "107.174.142.104:6578",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-06-27 19:43:13",
            "last_seen_utc": "2026-06-30 10:43:14",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1838658": [
        {
            "ioc_value": "107.174.142.104:7790",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-06-27 19:43:13",
            "last_seen_utc": "2026-06-30 10:43:14",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1838656": [
        {
            "ioc_value": "107.173.160.177:2850",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.evilginx",
            "malware_alias": null,
            "malware_printable": "Evilginx",
            "first_seen_utc": "2026-06-27 19:43:12",
            "last_seen_utc": "2026-06-30 10:43:14",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Evilginx,EvilGoPhish",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1838655": [
        {
            "ioc_value": "104.37.173.203:14643",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-06-27 19:43:10",
            "last_seen_utc": "2026-06-30 10:43:12",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1838654": [
        {
            "ioc_value": "103.11.41.20:2753",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-06-27 19:43:06",
            "last_seen_utc": "2026-06-30 10:43:07",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1838653": [
        {
            "ioc_value": "103.11.41.10:49584",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-06-27 19:43:05",
            "last_seen_utc": "2026-06-30 10:43:06",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1838652": [
        {
            "ioc_value": "101.245.74.162:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.havoc",
            "malware_alias": "Havokiz",
            "malware_printable": "Havoc",
            "first_seen_utc": "2026-06-27 19:43:02",
            "last_seen_utc": "2026-06-30 10:43:03",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Havoc",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1838629": [
        {
            "ioc_value": "47.86.184.71:53",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-06-27 15:46:40",
            "last_seen_utc": "2026-06-30 10:47:12",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1838628": [
        {
            "ioc_value": "test.officeplustool.top",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-06-27 15:46:01",
            "last_seen_utc": "2026-06-30 10:46:27",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1838620": [
        {
            "ioc_value": "https://rssssociety.org.in/",
            "ioc_type": "url",
            "threat_type": "payload_delivery",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-06-27 14:15:03",
            "last_seen_utc": "2026-06-28 15:31:02",
            "confidence_level": 75,
            "is_compromised": true,
            "reference": null,
            "tags": "ClickFix,compromised,EtherHiding,Polygon,Vidar,WordPress",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1838598": [
        {
            "ioc_value": "103.11.41.20:9087",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-06-27 09:43:07",
            "last_seen_utc": "2026-06-30 10:43:08",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1838554": [
        {
            "ioc_value": "128.90.141.159:4444",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-06-27 08:05:05",
            "last_seen_utc": "2026-06-30 10:43:19",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "asyncrat",
            "anonymous": "1",
            "reporter": "_ik_"
        }
    ],
    "1838555": [
        {
            "ioc_value": "188.212.158.4:8808",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-06-27 08:05:05",
            "last_seen_utc": "2026-06-30 10:44:11",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "asyncrat",
            "anonymous": "1",
            "reporter": "_ik_"
        }
    ],
    "1838532": [
        {
            "ioc_value": "8.152.212.104:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-06-27 07:05:05",
            "last_seen_utc": "2026-06-30 10:47:16",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "cobaltstrike",
            "anonymous": "1",
            "reporter": "_ik_"
        }
    ],
    "1838464": [
        {
            "ioc_value": "129.212.233.8:8080",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.aisuru",
            "malware_alias": null,
            "malware_printable": "Aisuru",
            "first_seen_utc": "2026-06-27 06:24:38",
            "last_seen_utc": "2026-06-30 02:15:12",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "Aisuru,c2",
            "anonymous": "0",
            "reporter": "Bitsight"
        }
    ],
    "1838474": [
        {
            "ioc_value": "147.182.140.2:9035",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.aisuru",
            "malware_alias": null,
            "malware_printable": "Aisuru",
            "first_seen_utc": "2026-06-27 06:24:33",
            "last_seen_utc": "2026-06-30 09:12:03",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "Aisuru,c2",
            "anonymous": "0",
            "reporter": "Bitsight"
        }
    ],
    "1838478": [
        {
            "ioc_value": "47.108.60.27:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-06-27 06:24:31",
            "last_seen_utc": "2026-06-30 10:47:08",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": null,
            "tags": "37963,c2,censys,cobalt strike",
            "anonymous": "0",
            "reporter": "sojubear"
        }
    ],
    "1838489": [
        {
            "ioc_value": "147.182.140.2:34567",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.aisuru",
            "malware_alias": null,
            "malware_printable": "Aisuru",
            "first_seen_utc": "2026-06-27 06:24:30",
            "last_seen_utc": "2026-06-30 05:59:32",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "Aisuru,c2",
            "anonymous": "0",
            "reporter": "Bitsight"
        }
    ],
    "1838176": [
        {
            "ioc_value": "147.182.140.2:9034",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.aisuru",
            "malware_alias": null,
            "malware_printable": "Aisuru",
            "first_seen_utc": "2026-06-27 06:24:12",
            "last_seen_utc": "2026-06-30 09:03:51",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "Aisuru,c2",
            "anonymous": "0",
            "reporter": "Bitsight"
        }
    ],
    "1838519": [
        {
            "ioc_value": "62.0.120.51:82",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-06-27 06:05:06",
            "last_seen_utc": "2026-06-30 09:54:10",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "cobaltstrike",
            "anonymous": "1",
            "reporter": "_ik_"
        }
    ],
    "1838520": [
        {
            "ioc_value": "114.132.199.129:4443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-06-27 06:05:06",
            "last_seen_utc": "2026-06-30 10:46:35",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "cobaltstrike",
            "anonymous": "1",
            "reporter": "_ik_"
        }
    ],
    "1838498": [
        {
            "ioc_value": "27.124.43.249:8848",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.dcrat",
            "malware_alias": "DarkCrystal RAT",
            "malware_printable": "DCRat",
            "first_seen_utc": "2026-06-27 04:05:05",
            "last_seen_utc": "2026-06-30 10:45:22",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "dcrat",
            "anonymous": "1",
            "reporter": "_ik_"
        }
    ],
    "1838183": [
        {
            "ioc_value": "82.165.79.60:1336",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.sliver",
            "malware_alias": null,
            "malware_printable": "Sliver",
            "first_seen_utc": "2026-06-26 19:45:25",
            "last_seen_utc": "2026-06-30 10:46:09",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Sliver",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1838182": [
        {
            "ioc_value": "5.200.255.45:8848",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.dcrat",
            "malware_alias": "DarkCrystal RAT",
            "malware_printable": "DCRat",
            "first_seen_utc": "2026-06-26 19:45:15",
            "last_seen_utc": "2026-06-30 10:45:52",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DCRat,drb-ra,RAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1838181": [
        {
            "ioc_value": "45.254.246.208:4444",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-06-26 19:45:00",
            "last_seen_utc": "2026-06-30 10:45:38",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1838180": [
        {
            "ioc_value": "209.54.103.150:7707",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-06-26 19:44:13",
            "last_seen_utc": "2026-06-30 10:44:32",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1838179": [
        {
            "ioc_value": "193.169.194.63:4321",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-06-26 19:44:00",
            "last_seen_utc": "2026-06-30 10:44:17",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1838178": [
        {
            "ioc_value": "141.98.189.248:4321",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-06-26 19:43:19",
            "last_seen_utc": "2026-06-30 10:43:25",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1838177": [
        {
            "ioc_value": "103.11.41.19:52814",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-06-26 19:43:05",
            "last_seen_utc": "2026-06-30 10:43:07",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1838151": [
        {
            "ioc_value": "147.182.140.2:8443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.aisuru",
            "malware_alias": null,
            "malware_printable": "Aisuru",
            "first_seen_utc": "2026-06-26 16:12:29",
            "last_seen_utc": "2026-06-30 11:24:41",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "Aisuru,c2",
            "anonymous": "0",
            "reporter": "Bitsight"
        }
    ],
    "1838156": [
        {
            "ioc_value": "147.182.140.2:8080",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.aisuru",
            "malware_alias": null,
            "malware_printable": "Aisuru",
            "first_seen_utc": "2026-06-26 16:12:27",
            "last_seen_utc": "2026-06-30 10:50:20",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "Aisuru,c2",
            "anonymous": "0",
            "reporter": "Bitsight"
        }
    ],
    "1838146": [
        {
            "ioc_value": "147.182.140.2:8001",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.aisuru",
            "malware_alias": null,
            "malware_printable": "Aisuru",
            "first_seen_utc": "2026-06-26 14:37:32",
            "last_seen_utc": "2026-06-30 10:45:06",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "Aisuru,c2",
            "anonymous": "0",
            "reporter": "Bitsight"
        }
    ],
    "1838143": [
        {
            "ioc_value": "64.83.33.240:5173",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.overlord",
            "malware_alias": null,
            "malware_printable": "Overlord RAT",
            "first_seen_utc": "2026-06-26 14:00:06",
            "last_seen_utc": "2026-06-30 11:24:03",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": "https://tracker.viriback.com/index.php?q=64.83.33.240",
            "tags": "Overlord,ViriBack",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1838140": [
        {
            "ioc_value": "192.3.16.35:5173",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.overlord",
            "malware_alias": null,
            "malware_printable": "Overlord RAT",
            "first_seen_utc": "2026-06-26 14:00:05",
            "last_seen_utc": "2026-06-30 11:24:03",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": "https://tracker.viriback.com/index.php?q=192.3.16.35",
            "tags": "Overlord,ViriBack",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1838141": [
        {
            "ioc_value": "192.3.16.34:5173",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.overlord",
            "malware_alias": null,
            "malware_printable": "Overlord RAT",
            "first_seen_utc": "2026-06-26 14:00:05",
            "last_seen_utc": "2026-06-30 11:24:03",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": "https://tracker.viriback.com/index.php?q=192.3.16.34",
            "tags": "Overlord,ViriBack",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1838142": [
        {
            "ioc_value": "185.103.166.53:5173",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.overlord",
            "malware_alias": null,
            "malware_printable": "Overlord RAT",
            "first_seen_utc": "2026-06-26 14:00:05",
            "last_seen_utc": "2026-06-30 11:24:03",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": "https://tracker.viriback.com/index.php?q=185.103.166.53",
            "tags": "Overlord,ViriBack",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1838139": [
        {
            "ioc_value": "192.109.200.233:5173",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.overlord",
            "malware_alias": null,
            "malware_printable": "Overlord RAT",
            "first_seen_utc": "2026-06-26 14:00:04",
            "last_seen_utc": "2026-06-30 11:24:03",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": "https://tracker.viriback.com/index.php?q=192.109.200.233",
            "tags": "Overlord,ViriBack",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1838138": [
        {
            "ioc_value": "107.175.115.123:8443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.overlord",
            "malware_alias": null,
            "malware_printable": "Overlord RAT",
            "first_seen_utc": "2026-06-26 14:00:03",
            "last_seen_utc": "2026-06-30 11:24:03",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": "https://tracker.viriback.com/index.php?q=107.175.115.123",
            "tags": "Overlord,ViriBack",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1838137": [
        {
            "ioc_value": "87.120.84.133:5173",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.overlord",
            "malware_alias": null,
            "malware_printable": "Overlord RAT",
            "first_seen_utc": "2026-06-26 13:48:02",
            "last_seen_utc": "2026-06-30 11:24:03",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": "https://tracker.viriback.com/index.php?q=87.120.84.133",
            "tags": "Overlord,ViriBack",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1838125": [
        {
            "ioc_value": "https://k1h.fileboro.com/",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-06-26 12:25:27",
            "last_seen_utc": "2026-06-30 10:25:27",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "k5yss1,Vidar",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1838126": [
        {
            "ioc_value": "k1h.fileboro.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-06-26 12:25:27",
            "last_seen_utc": "2026-06-30 10:25:27",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "k5yss1,Vidar",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1838123": [
        {
            "ioc_value": "https://k1h.hopesm188.top/",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-06-26 12:25:15",
            "last_seen_utc": "2026-06-30 10:25:17",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "k5yss1,Vidar",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1838124": [
        {
            "ioc_value": "k1h.hopesm188.top",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-06-26 12:25:15",
            "last_seen_utc": "2026-06-30 10:25:17",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "k5yss1,Vidar",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1837938": [
        {
            "ioc_value": "107.173.9.99:14641",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-06-26 09:43:14",
            "last_seen_utc": "2026-06-30 10:43:14",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1837922": [
        {
            "ioc_value": "139.59.67.197:6379",
            "ioc_type": "ip:port",
            "threat_type": "payload_delivery",
            "malware": "elf.xmrig",
            "malware_alias": null,
            "malware_printable": "XMRIG",
            "first_seen_utc": "2026-06-26 09:02:28",
            "last_seen_utc": "2026-06-28 21:15:36",
            "confidence_level": 80,
            "is_compromised": false,
            "reference": "https://twitter.com/NullBlue67",
            "tags": "rce,redis",
            "anonymous": "0",
            "reporter": "nullblue67"
        }
    ],
    "1837925": [
        {
            "ioc_value": "64.227.164.38:6379",
            "ioc_type": "ip:port",
            "threat_type": "payload_delivery",
            "malware": "elf.xmrig",
            "malware_alias": null,
            "malware_printable": "XMRIG",
            "first_seen_utc": "2026-06-26 09:02:27",
            "last_seen_utc": "2026-06-29 09:40:14",
            "confidence_level": 80,
            "is_compromised": false,
            "reference": "https://twitter.com/NullBlue67",
            "tags": "rce,redis",
            "anonymous": "0",
            "reporter": "nullblue67"
        }
    ],
    "1837926": [
        {
            "ioc_value": "211.234.111.116:5432",
            "ioc_type": "ip:port",
            "threat_type": "payload_delivery",
            "malware": "elf.xmrig",
            "malware_alias": null,
            "malware_printable": "XMRIG",
            "first_seen_utc": "2026-06-26 09:02:26",
            "last_seen_utc": "2026-06-29 09:40:23",
            "confidence_level": 80,
            "is_compromised": false,
            "reference": "https://twitter.com/NullBlue67",
            "tags": "postgres,takeover",
            "anonymous": "0",
            "reporter": "nullblue67"
        }
    ],
    "1837927": [
        {
            "ioc_value": "77.90.185.248:5432",
            "ioc_type": "ip:port",
            "threat_type": "payload_delivery",
            "malware": "elf.xmrig",
            "malware_alias": null,
            "malware_printable": "XMRIG",
            "first_seen_utc": "2026-06-26 09:02:26",
            "last_seen_utc": "2026-06-29 09:40:25",
            "confidence_level": 80,
            "is_compromised": false,
            "reference": "https://twitter.com/NullBlue67",
            "tags": "postgres,takeover",
            "anonymous": "0",
            "reporter": "nullblue67"
        }
    ],
    "1837928": [
        {
            "ioc_value": "176.65.139.43:2375",
            "ioc_type": "ip:port",
            "threat_type": "payload_delivery",
            "malware": "elf.redtail",
            "malware_alias": null,
            "malware_printable": "RedTail",
            "first_seen_utc": "2026-06-26 09:02:26",
            "last_seen_utc": "2026-06-28 21:16:21",
            "confidence_level": 80,
            "is_compromised": false,
            "reference": "https://twitter.com/NullBlue67",
            "tags": "docker-api",
            "anonymous": "0",
            "reporter": "nullblue67"
        }
    ],
    "1837903": [
        {
            "ioc_value": "xb.bet1bonus.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-26 07:39:31",
            "last_seen_utc": "2026-06-29 02:08:40",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake",
            "anonymous": "1",
            "reporter": "ttakvam"
        }
    ],
    "1837844": [
        {
            "ioc_value": "superstarlog.click",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "unknown_stealer",
            "malware_alias": null,
            "malware_printable": "Unknown Stealer",
            "first_seen_utc": "2026-06-26 07:18:44",
            "last_seen_utc": "2026-06-29 13:26:19",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "C2,ClickFix,Polygon",
            "anonymous": "0",
            "reporter": "varysz"
        }
    ],
    "1837869": [
        {
            "ioc_value": "68.183.8.109:25001",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "apk.kimwolf",
            "malware_alias": null,
            "malware_printable": "Kimwolf",
            "first_seen_utc": "2026-06-26 07:18:42",
            "last_seen_utc": "2026-06-29 16:36:32",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "c2,Kimwolf",
            "anonymous": "0",
            "reporter": "Bitsight"
        }
    ],
    "1837870": [
        {
            "ioc_value": "167.99.36.25:25001",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "apk.kimwolf",
            "malware_alias": null,
            "malware_printable": "Kimwolf",
            "first_seen_utc": "2026-06-26 07:18:41",
            "last_seen_utc": "2026-06-29 16:36:44",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "c2,Kimwolf",
            "anonymous": "0",
            "reporter": "Bitsight"
        }
    ],
    "1837880": [
        {
            "ioc_value": "122.51.221.207:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-06-26 07:18:38",
            "last_seen_utc": "2026-06-30 10:46:42",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": null,
            "tags": "45090,c2,censys,cobalt strike",
            "anonymous": "0",
            "reporter": "sojubear"
        }
    ],
    "1837848": [
        {
            "ioc_value": "49.232.4.71:8888",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-06-25 21:05:09",
            "last_seen_utc": "2026-06-30 10:47:12",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "cobaltstrike",
            "anonymous": "1",
            "reporter": "_ik_"
        }
    ],
    "1837843": [
        {
            "ioc_value": "172.245.196.240:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-06-25 20:05:06",
            "last_seen_utc": "2026-06-30 10:46:51",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "cobaltstrike",
            "anonymous": "1",
            "reporter": "_ik_"
        }
    ],
    "1837840": [
        {
            "ioc_value": "217.60.97.3:8899",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-06-25 19:45:00",
            "last_seen_utc": "2026-06-30 10:45:18",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1837839": [
        {
            "ioc_value": "217.60.195.194:14645",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-06-25 19:44:59",
            "last_seen_utc": "2026-06-30 10:45:17",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1837838": [
        {
            "ioc_value": "209.54.103.150:8080",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-06-25 19:44:24",
            "last_seen_utc": "2026-06-30 10:44:33",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1837837": [
        {
            "ioc_value": "185.192.125.141:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-06-25 19:43:58",
            "last_seen_utc": "2026-06-30 10:44:05",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1837836": [
        {
            "ioc_value": "157.245.171.59:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.evilginx",
            "malware_alias": null,
            "malware_printable": "Evilginx",
            "first_seen_utc": "2026-06-25 19:43:34",
            "last_seen_utc": "2026-06-30 10:43:38",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Evilginx,EvilGoPhish",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1837833": [
        {
            "ioc_value": "147.124.223.75:14641",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-06-25 19:43:25",
            "last_seen_utc": "2026-06-30 10:43:28",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1837834": [
        {
            "ioc_value": "147.124.223.75:14643",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-06-25 19:43:25",
            "last_seen_utc": "2026-06-30 10:43:28",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1837835": [
        {
            "ioc_value": "147.124.223.75:2404",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-06-25 19:43:25",
            "last_seen_utc": "2026-06-30 10:43:29",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1837543": [
        {
            "ioc_value": "http://176.65.144.120/bc850000649f490e9617.php",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.stealc",
            "malware_alias": null,
            "malware_printable": "Stealc",
            "first_seen_utc": "2026-06-25 18:52:39",
            "last_seen_utc": "2026-06-29 11:25:48",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "c2,eu1,loader,StealC,stealer",
            "anonymous": "0",
            "reporter": "Bitsight"
        }
    ],
    "1837517": [
        {
            "ioc_value": "boldtop.click",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-06-25 15:45:59",
            "last_seen_utc": "2026-06-30 10:46:22",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1837358": [
        {
            "ioc_value": "verificationscodes.beer",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-06-25 13:55:26",
            "last_seen_utc": "2026-06-29 13:30:24",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "c2,ClickFix,Polygon",
            "anonymous": "0",
            "reporter": "varysz"
        }
    ],
    "1837335": [
        {
            "ioc_value": "172.245.57.227:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-06-25 11:46:44",
            "last_seen_utc": "2026-06-30 10:46:52",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1837334": [
        {
            "ioc_value": "124.222.218.12:4848",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-06-25 11:46:36",
            "last_seen_utc": "2026-06-30 10:46:43",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1837333": [
        {
            "ioc_value": "1.94.187.246:8080",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-06-25 11:46:22",
            "last_seen_utc": "2026-06-30 10:46:30",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1837319": [
        {
            "ioc_value": "http://64.89.161.67/3b250ef3f9e542adadfb.php",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.stealc",
            "malware_alias": null,
            "malware_printable": "Stealc",
            "first_seen_utc": "2026-06-25 11:10:48",
            "last_seen_utc": "2026-06-29 22:48:42",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://bazaar.abuse.ch/sample/07cc22c1db2b39a7fc3058b02ec15225b2945e4866a9a0e84b8f73672ae9bcd7/",
            "tags": "stealc",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1837297": [
        {
            "ioc_value": "8.130.74.111:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-06-25 09:47:23",
            "last_seen_utc": "2026-06-30 10:47:15",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1837296": [
        {
            "ioc_value": "159.75.176.139:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-06-25 09:46:55",
            "last_seen_utc": "2026-06-30 10:46:50",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1837295": [
        {
            "ioc_value": "88.198.11.120:8080",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.chaos",
            "malware_alias": "FakeRyuk,RyukJoke,Yashma",
            "malware_printable": "Chaos",
            "first_seen_utc": "2026-06-25 09:46:16",
            "last_seen_utc": "2026-06-30 10:46:13",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CHAOS,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1837294": [
        {
            "ioc_value": "5.101.84.82:9521",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-06-25 09:45:52",
            "last_seen_utc": "2026-06-30 10:45:49",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1837293": [
        {
            "ioc_value": "45.74.7.166:1377",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-06-25 09:45:43",
            "last_seen_utc": "2026-06-30 10:45:41",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1837292": [
        {
            "ioc_value": "27.124.43.249:12159",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.dcrat",
            "malware_alias": "DarkCrystal RAT",
            "malware_printable": "DCRat",
            "first_seen_utc": "2026-06-25 09:45:24",
            "last_seen_utc": "2026-06-30 10:45:22",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DCRat,drb-ra,RAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1837290": [
        {
            "ioc_value": "209.54.103.150:6606",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-06-25 09:44:34",
            "last_seen_utc": "2026-06-30 10:44:32",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1837291": [
        {
            "ioc_value": "209.54.103.150:8808",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-06-25 09:44:34",
            "last_seen_utc": "2026-06-30 10:44:33",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1837289": [
        {
            "ioc_value": "185.115.164.59:3731",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-06-25 09:44:03",
            "last_seen_utc": "2026-06-30 10:44:01",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1837287": [
        {
            "ioc_value": "154.219.98.36:8443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.sliver",
            "malware_alias": null,
            "malware_printable": "Sliver",
            "first_seen_utc": "2026-06-25 09:43:32",
            "last_seen_utc": "2026-06-30 10:43:33",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Sliver",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1837286": [
        {
            "ioc_value": "104.250.167.40:9093",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.dcrat",
            "malware_alias": "DarkCrystal RAT",
            "malware_printable": "DCRat",
            "first_seen_utc": "2026-06-25 09:43:11",
            "last_seen_utc": "2026-06-30 10:43:12",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DCRat,drb-ra,RAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1837285": [
        {
            "ioc_value": "103.11.41.10:55483",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-06-25 09:43:05",
            "last_seen_utc": "2026-06-30 10:43:06",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1837272": [
        {
            "ioc_value": "141.94.164.126:6379",
            "ioc_type": "ip:port",
            "threat_type": "payload_delivery",
            "malware": "elf.xmrig",
            "malware_alias": null,
            "malware_printable": "XMRIG",
            "first_seen_utc": "2026-06-25 08:49:58",
            "last_seen_utc": "2026-06-29 09:40:02",
            "confidence_level": 80,
            "is_compromised": false,
            "reference": "https://twitter.com/NullBlue67",
            "tags": "rce,redis",
            "anonymous": "0",
            "reporter": "nullblue67"
        }
    ],
    "1837273": [
        {
            "ioc_value": "143.244.165.24:6379",
            "ioc_type": "ip:port",
            "threat_type": "payload_delivery",
            "malware": "elf.xmrig",
            "malware_alias": null,
            "malware_printable": "XMRIG",
            "first_seen_utc": "2026-06-25 08:49:57",
            "last_seen_utc": "2026-06-29 09:40:04",
            "confidence_level": 80,
            "is_compromised": false,
            "reference": "https://twitter.com/NullBlue67",
            "tags": "rce,redis",
            "anonymous": "0",
            "reporter": "nullblue67"
        }
    ],
    "1837242": [
        {
            "ioc_value": "101.43.24.136:8899",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-06-25 08:08:03",
            "last_seen_utc": "2026-06-29 07:55:07",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-666666666",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1837243": [
        {
            "ioc_value": "169.239.128.43:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-06-25 08:08:03",
            "last_seen_utc": "2026-06-30 10:46:51",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-987654321",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1837237": [
        {
            "ioc_value": "172.245.196.240:8899",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-06-25 08:07:56",
            "last_seen_utc": "2026-06-30 09:54:11",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-666666666",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1837239": [
        {
            "ioc_value": "8.134.255.60:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-06-25 08:07:56",
            "last_seen_utc": "2026-06-30 10:47:15",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-987654321",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1837115": [
        {
            "ioc_value": "207.180.232.121:6379",
            "ioc_type": "ip:port",
            "threat_type": "payload_delivery",
            "malware": "elf.xmrig",
            "malware_alias": null,
            "malware_printable": "XMRIG",
            "first_seen_utc": "2026-06-25 03:14:06",
            "last_seen_utc": "2026-06-29 09:40:09",
            "confidence_level": 80,
            "is_compromised": false,
            "reference": "https://twitter.com/NullBlue67",
            "tags": "rce,redis",
            "anonymous": "0",
            "reporter": "nullblue67"
        }
    ],
    "1837153": [
        {
            "ioc_value": "178.83.206.213:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.mirai",
            "malware_alias": "Katana",
            "malware_printable": "Mirai",
            "first_seen_utc": "2026-06-25 03:13:48",
            "last_seen_utc": "2026-06-28 17:10:47",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "C2,Mirai",
            "anonymous": "0",
            "reporter": "botnetkiller"
        }
    ],
    "1837154": [
        {
            "ioc_value": "178.83.206.213:123",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.mirai",
            "malware_alias": "Katana",
            "malware_printable": "Mirai",
            "first_seen_utc": "2026-06-25 03:13:46",
            "last_seen_utc": "2026-06-28 17:10:47",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "C2,Mirai",
            "anonymous": "0",
            "reporter": "botnetkiller"
        }
    ],
    "1837155": [
        {
            "ioc_value": "178.83.206.213:25565",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.mirai",
            "malware_alias": "Katana",
            "malware_printable": "Mirai",
            "first_seen_utc": "2026-06-25 03:13:45",
            "last_seen_utc": "2026-06-28 17:10:47",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "C2,Mirai",
            "anonymous": "0",
            "reporter": "botnetkiller"
        }
    ],
    "1837166": [
        {
            "ioc_value": "147.182.217.141:8443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.aisuru",
            "malware_alias": null,
            "malware_printable": "Aisuru",
            "first_seen_utc": "2026-06-25 03:13:15",
            "last_seen_utc": "2026-06-30 06:36:05",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "Aisuru,c2",
            "anonymous": "0",
            "reporter": "Bitsight"
        }
    ],
    "1837180": [
        {
            "ioc_value": "g3byemsx.xbetone.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-25 02:56:45",
            "last_seen_utc": "2026-06-28 21:50:56",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "clearfake",
            "anonymous": "1",
            "reporter": "ttakvam"
        }
    ],
    "1837171": [
        {
            "ioc_value": "45.227.253.121:25338",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-06-24 23:48:40",
            "last_seen_utc": "2026-06-30 10:47:07",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1837170": [
        {
            "ioc_value": "130.94.59.160:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-06-24 23:48:22",
            "last_seen_utc": "2026-06-30 10:46:44",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1837169": [
        {
            "ioc_value": "121.4.76.54:8091",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-06-24 23:48:20",
            "last_seen_utc": "2026-06-30 10:46:41",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1837093": [
        {
            "ioc_value": "89.124.93.139:49999",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-06-24 19:45:44",
            "last_seen_utc": "2026-06-30 10:46:14",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1837092": [
        {
            "ioc_value": "83.136.210.74:7077",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-06-24 19:45:41",
            "last_seen_utc": "2026-06-30 10:46:09",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1837091": [
        {
            "ioc_value": "62.85.21.181:6606",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-06-24 19:45:33",
            "last_seen_utc": "2026-06-30 10:45:58",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1837090": [
        {
            "ioc_value": "46.246.4.2:8848",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.dcrat",
            "malware_alias": "DarkCrystal RAT",
            "malware_printable": "DCRat",
            "first_seen_utc": "2026-06-24 19:45:21",
            "last_seen_utc": "2026-06-30 10:45:45",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DCRat,drb-ra,RAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1837088": [
        {
            "ioc_value": "45.74.7.163:6448",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-06-24 19:45:18",
            "last_seen_utc": "2026-06-30 10:45:40",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1837089": [
        {
            "ioc_value": "45.74.7.164:6913",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-06-24 19:45:18",
            "last_seen_utc": "2026-06-30 10:45:41",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1837087": [
        {
            "ioc_value": "45.74.7.155:1202",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-06-24 19:45:17",
            "last_seen_utc": "2026-06-30 10:45:40",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1837086": [
        {
            "ioc_value": "27.124.43.241:8848",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.dcrat",
            "malware_alias": "DarkCrystal RAT",
            "malware_printable": "DCRat",
            "first_seen_utc": "2026-06-24 19:44:57",
            "last_seen_utc": "2026-06-30 10:45:22",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DCRat,drb-ra,RAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1837085": [
        {
            "ioc_value": "198.23.185.82:6666",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-06-24 19:44:11",
            "last_seen_utc": "2026-06-30 10:44:23",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1837084": [
        {
            "ioc_value": "192.227.219.81:14645",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-06-24 19:44:04",
            "last_seen_utc": "2026-06-30 10:44:14",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1837082": [
        {
            "ioc_value": "185.115.164.59:65372",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-06-24 19:43:53",
            "last_seen_utc": "2026-06-30 10:44:01",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1837083": [
        {
            "ioc_value": "185.115.164.60:10251",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-06-24 19:43:53",
            "last_seen_utc": "2026-06-30 10:44:02",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1837081": [
        {
            "ioc_value": "178.16.55.214:55380",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.dcrat",
            "malware_alias": "DarkCrystal RAT",
            "malware_printable": "DCRat",
            "first_seen_utc": "2026-06-24 19:43:46",
            "last_seen_utc": "2026-06-30 10:43:53",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DCRat,drb-ra,RAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1837080": [
        {
            "ioc_value": "146.190.80.105:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.havoc",
            "malware_alias": "Havokiz",
            "malware_printable": "Havoc",
            "first_seen_utc": "2026-06-24 19:43:22",
            "last_seen_utc": "2026-06-30 10:43:27",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Havoc",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1837079": [
        {
            "ioc_value": "141.98.10.150:14649",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-06-24 19:43:21",
            "last_seen_utc": "2026-06-30 10:43:25",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1837078": [
        {
            "ioc_value": "109.199.97.174:6010",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.evilginx",
            "malware_alias": null,
            "malware_printable": "Evilginx",
            "first_seen_utc": "2026-06-24 19:43:12",
            "last_seen_utc": "2026-06-30 10:43:16",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Evilginx,EvilGoPhish",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1837077": [
        {
            "ioc_value": "107.173.9.99:14642",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-06-24 19:43:11",
            "last_seen_utc": "2026-06-30 10:43:14",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1836946": [
        {
            "ioc_value": "157.230.237.88:8443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.aisuru",
            "malware_alias": null,
            "malware_printable": "Aisuru",
            "first_seen_utc": "2026-06-24 15:49:05",
            "last_seen_utc": "2026-06-30 01:04:18",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "Aisuru,c2",
            "anonymous": "0",
            "reporter": "Bitsight"
        }
    ],
    "1836925": [
        {
            "ioc_value": "60.217.58.49:2121",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-06-24 11:48:48",
            "last_seen_utc": "2026-06-30 10:47:13",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1836924": [
        {
            "ioc_value": "43.131.240.236:8015",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-06-24 11:48:29",
            "last_seen_utc": "2026-06-30 10:47:01",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1836784": [
        {
            "ioc_value": "95.81.79.153:8443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-06-24 09:45:56",
            "last_seen_utc": "2026-06-30 10:46:18",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1836783": [
        {
            "ioc_value": "45.74.7.160:9405",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-06-24 09:45:24",
            "last_seen_utc": "2026-06-30 10:45:40",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1836782": [
        {
            "ioc_value": "45.138.16.56:6666",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-06-24 09:45:19",
            "last_seen_utc": "2026-06-30 10:45:35",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1836781": [
        {
            "ioc_value": "38.207.177.71:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-06-24 09:45:14",
            "last_seen_utc": "2026-06-30 10:45:30",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1836780": [
        {
            "ioc_value": "217.60.195.194:14642",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-06-24 09:45:00",
            "last_seen_utc": "2026-06-30 10:45:17",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1836779": [
        {
            "ioc_value": "192.227.219.81:14644",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-06-24 09:44:09",
            "last_seen_utc": "2026-06-30 10:44:14",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1836777": [
        {
            "ioc_value": "185.115.161.32:6943",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.havoc",
            "malware_alias": "Havokiz",
            "malware_printable": "Havoc",
            "first_seen_utc": "2026-06-24 09:43:58",
            "last_seen_utc": "2026-06-30 10:44:00",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Havoc",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1836778": [
        {
            "ioc_value": "185.115.164.59:30023",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-06-24 09:43:58",
            "last_seen_utc": "2026-06-30 10:44:01",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1836775": [
        {
            "ioc_value": "154.219.98.36:31337",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.sliver",
            "malware_alias": null,
            "malware_printable": "Sliver",
            "first_seen_utc": "2026-06-24 09:43:30",
            "last_seen_utc": "2026-06-30 10:43:33",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Sliver",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1836776": [
        {
            "ioc_value": "154.219.98.36:8080",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.sliver",
            "malware_alias": null,
            "malware_printable": "Sliver",
            "first_seen_utc": "2026-06-24 09:43:30",
            "last_seen_utc": "2026-06-30 10:43:33",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Sliver",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1836774": [
        {
            "ioc_value": "141.98.10.150:14647",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-06-24 09:43:23",
            "last_seen_utc": "2026-06-30 10:43:25",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1836773": [
        {
            "ioc_value": "128.90.115.181:7011",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.dcrat",
            "malware_alias": "DarkCrystal RAT",
            "malware_printable": "DCRat",
            "first_seen_utc": "2026-06-24 09:43:17",
            "last_seen_utc": "2026-06-30 10:43:19",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DCRat,drb-ra,RAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1836771": [
        {
            "ioc_value": "107.172.140.187:32333",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-06-24 09:43:12",
            "last_seen_utc": "2026-06-30 10:43:13",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1836772": [
        {
            "ioc_value": "107.173.9.99:14644",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-06-24 09:43:12",
            "last_seen_utc": "2026-06-30 10:43:14",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1836770": [
        {
            "ioc_value": "107.172.133.195:56001",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-06-24 09:43:11",
            "last_seen_utc": "2026-06-30 10:43:13",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1836767": [
        {
            "ioc_value": "102.220.160.222:6606",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-06-24 09:43:04",
            "last_seen_utc": "2026-06-30 10:43:04",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1836768": [
        {
            "ioc_value": "102.220.160.250:6606",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-06-24 09:43:04",
            "last_seen_utc": "2026-06-30 10:43:05",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1836769": [
        {
            "ioc_value": "102.220.160.250:7707",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-06-24 09:43:04",
            "last_seen_utc": "2026-06-30 10:43:05",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1836682": [
        {
            "ioc_value": "cdn-speed.beer",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-06-24 06:36:16",
            "last_seen_utc": "2026-06-29 13:30:27",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "C2,ClickFix,Polygon",
            "anonymous": "0",
            "reporter": "varysz"
        }
    ],
    "1836684": [
        {
            "ioc_value": "merkantalolol.asia",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-06-24 06:36:16",
            "last_seen_utc": "2026-06-29 13:26:22",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "C2,ClickFix,Polygon",
            "anonymous": "0",
            "reporter": "varysz"
        }
    ],
    "1836683": [
        {
            "ioc_value": "code.verification-claude-cdn.beer",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-06-24 06:36:14",
            "last_seen_utc": "2026-06-29 13:30:26",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "C2,ClickFix,Polygon",
            "anonymous": "0",
            "reporter": "varysz"
        }
    ],
    "1836685": [
        {
            "ioc_value": "superboomer.world",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-06-24 06:36:13",
            "last_seen_utc": "2026-06-29 13:26:21",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "C2,ClickFix,Polygon",
            "anonymous": "0",
            "reporter": "varysz"
        }
    ],
    "1836687": [
        {
            "ioc_value": "129.212.233.8:8443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.aisuru",
            "malware_alias": null,
            "malware_printable": "Aisuru",
            "first_seen_utc": "2026-06-24 06:36:11",
            "last_seen_utc": "2026-06-30 01:00:13",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "Aisuru,c2",
            "anonymous": "0",
            "reporter": "Bitsight"
        }
    ],
    "1836710": [
        {
            "ioc_value": "kyard07v.vip1xbet.net",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-24 06:02:24",
            "last_seen_utc": "2026-06-30 10:03:39",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "clearfake",
            "anonymous": "1",
            "reporter": "ttakvam"
        }
    ],
    "1836704": [
        {
            "ioc_value": "49.233.9.4:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-06-24 03:46:33",
            "last_seen_utc": "2026-06-30 10:47:13",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1836703": [
        {
            "ioc_value": "www.rmsmarineservice.com.qwqqwq.ggff.net",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-06-24 03:45:54",
            "last_seen_utc": "2026-06-30 10:46:29",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1836674": [
        {
            "ioc_value": "91.92.242.235:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-06-23 19:45:49",
            "last_seen_utc": "2026-06-30 10:46:17",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1836673": [
        {
            "ioc_value": "82.29.100.224:6666",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-06-23 19:45:42",
            "last_seen_utc": "2026-06-30 10:46:09",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1836672": [
        {
            "ioc_value": "46.29.166.65:3481",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.bianlian",
            "malware_alias": null,
            "malware_printable": "BianLian",
            "first_seen_utc": "2026-06-23 19:45:22",
            "last_seen_utc": "2026-06-30 10:45:45",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "Bianlian,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1836671": [
        {
            "ioc_value": "45.74.7.161:4509",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-06-23 19:45:19",
            "last_seen_utc": "2026-06-30 10:45:40",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1836669": [
        {
            "ioc_value": "45.74.7.156:8015",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-06-23 19:45:18",
            "last_seen_utc": "2026-06-30 10:45:40",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1836670": [
        {
            "ioc_value": "45.74.7.159:5691",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-06-23 19:45:18",
            "last_seen_utc": "2026-06-30 10:45:40",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1836668": [
        {
            "ioc_value": "45.138.16.56:8008",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-06-23 19:45:14",
            "last_seen_utc": "2026-06-30 10:45:35",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1836667": [
        {
            "ioc_value": "2.26.17.59:6448",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-06-23 19:44:13",
            "last_seen_utc": "2026-06-30 10:44:24",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1836666": [
        {
            "ioc_value": "192.227.219.81:14641",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-06-23 19:44:04",
            "last_seen_utc": "2026-06-30 10:44:14",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1836665": [
        {
            "ioc_value": "188.23.173.69:8000",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.eye_pyramid",
            "malware_alias": null,
            "malware_printable": "Eye Pyramid",
            "first_seen_utc": "2026-06-23 19:44:02",
            "last_seen_utc": "2026-06-30 10:44:12",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,EyePyramid",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1836664": [
        {
            "ioc_value": "185.115.164.59:51227",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-06-23 19:43:54",
            "last_seen_utc": "2026-06-30 10:44:01",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1836663": [
        {
            "ioc_value": "178.73.192.17:8848",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.dcrat",
            "malware_alias": "DarkCrystal RAT",
            "malware_printable": "DCRat",
            "first_seen_utc": "2026-06-23 19:43:47",
            "last_seen_utc": "2026-06-30 10:43:54",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DCRat,drb-ra,RAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1836662": [
        {
            "ioc_value": "156.239.47.147:4221",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-06-23 19:43:29",
            "last_seen_utc": "2026-06-30 10:43:36",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1836660": [
        {
            "ioc_value": "147.124.213.155:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-06-23 19:43:23",
            "last_seen_utc": "2026-06-30 10:43:28",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1836661": [
        {
            "ioc_value": "147.93.191.75:20500",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-06-23 19:43:23",
            "last_seen_utc": "2026-06-30 10:43:29",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1836659": [
        {
            "ioc_value": "137.220.59.55:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.bianlian",
            "malware_alias": null,
            "malware_printable": "BianLian",
            "first_seen_utc": "2026-06-23 19:43:18",
            "last_seen_utc": "2026-06-30 10:43:23",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "Bianlian,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1836657": [
        {
            "ioc_value": "103.11.41.20:5195",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-06-23 19:43:05",
            "last_seen_utc": "2026-06-30 10:43:07",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1836658": [
        {
            "ioc_value": "103.11.41.20:53523",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-06-23 19:43:05",
            "last_seen_utc": "2026-06-30 10:43:08",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1836656": [
        {
            "ioc_value": "103.11.41.10:53496",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-06-23 19:43:04",
            "last_seen_utc": "2026-06-30 10:43:06",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1836655": [
        {
            "ioc_value": "102.220.160.250:8808",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-06-23 19:43:03",
            "last_seen_utc": "2026-06-30 10:43:05",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1836654": [
        {
            "ioc_value": "102.117.173.226:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-06-23 19:43:02",
            "last_seen_utc": "2026-06-30 10:43:03",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1836345": [
        {
            "ioc_value": "206.189.94.70:8001",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.aisuru",
            "malware_alias": null,
            "malware_printable": "Aisuru",
            "first_seen_utc": "2026-06-23 15:44:35",
            "last_seen_utc": "2026-06-30 11:20:01",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "Aisuru,c2",
            "anonymous": "0",
            "reporter": "Bitsight"
        }
    ],
    "1836346": [
        {
            "ioc_value": "129.212.233.8:8001",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.aisuru",
            "malware_alias": null,
            "malware_printable": "Aisuru",
            "first_seen_utc": "2026-06-23 15:44:35",
            "last_seen_utc": "2026-06-30 11:22:16",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "Aisuru,c2",
            "anonymous": "0",
            "reporter": "Bitsight"
        }
    ],
    "1836347": [
        {
            "ioc_value": "157.230.237.88:8001",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.aisuru",
            "malware_alias": null,
            "malware_printable": "Aisuru",
            "first_seen_utc": "2026-06-23 15:44:34",
            "last_seen_utc": "2026-06-30 11:17:47",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "Aisuru,c2",
            "anonymous": "0",
            "reporter": "Bitsight"
        }
    ],
    "1836348": [
        {
            "ioc_value": "147.182.217.141:8001",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.aisuru",
            "malware_alias": null,
            "malware_printable": "Aisuru",
            "first_seen_utc": "2026-06-23 15:44:34",
            "last_seen_utc": "2026-06-30 11:00:31",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "Aisuru,c2",
            "anonymous": "0",
            "reporter": "Bitsight"
        }
    ],
    "1836338": [
        {
            "ioc_value": "147.93.191.75:8008",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-06-23 13:31:17",
            "last_seen_utc": "2026-06-30 10:43:30",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "asyncrat",
            "anonymous": "1",
            "reporter": "_ik_"
        }
    ],
    "1836278": [
        {
            "ioc_value": "111.231.173.74:4444",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-06-23 07:14:51",
            "last_seen_utc": "2026-06-30 10:46:34",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1836178": [
        {
            "ioc_value": "claudverification-id.beer",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-06-23 06:51:46",
            "last_seen_utc": "2026-06-29 13:30:36",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "c2,Polygon,Vidar",
            "anonymous": "0",
            "reporter": "varysz"
        }
    ],
    "1836238": [
        {
            "ioc_value": "42.193.15.237:9001",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-06-23 03:46:19",
            "last_seen_utc": "2026-06-30 10:47:00",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1836201": [
        {
            "ioc_value": "62.234.22.228:51123",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-06-22 23:46:20",
            "last_seen_utc": "2026-06-30 10:47:14",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1836148": [
        {
            "ioc_value": "42.193.15.237:9002",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-06-22 19:46:25",
            "last_seen_utc": "2026-06-30 10:47:00",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1836146": [
        {
            "ioc_value": "72.56.68.200:8443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pupy",
            "malware_alias": "Patpoopy",
            "malware_printable": "pupy",
            "first_seen_utc": "2026-06-22 19:45:30",
            "last_seen_utc": "2026-06-30 10:46:05",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PupyRAT,RAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1836145": [
        {
            "ioc_value": "64.89.160.127:60859",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-06-22 19:45:27",
            "last_seen_utc": "2026-06-30 10:45:59",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1836144": [
        {
            "ioc_value": "217.60.195.194:14649",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-06-22 19:44:50",
            "last_seen_utc": "2026-06-30 10:45:18",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1836143": [
        {
            "ioc_value": "2.27.5.72:8015",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-06-22 19:44:11",
            "last_seen_utc": "2026-06-30 10:44:26",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1836141": [
        {
            "ioc_value": "185.115.164.59:50824",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-06-22 19:43:50",
            "last_seen_utc": "2026-06-30 10:44:01",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1836142": [
        {
            "ioc_value": "185.115.164.60:8455",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-06-22 19:43:50",
            "last_seen_utc": "2026-06-30 10:44:03",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1836140": [
        {
            "ioc_value": "150.40.117.39:4444",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.havoc",
            "malware_alias": "Havokiz",
            "malware_printable": "Havoc",
            "first_seen_utc": "2026-06-22 19:43:24",
            "last_seen_utc": "2026-06-30 10:43:32",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Havoc",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1836139": [
        {
            "ioc_value": "107.173.9.99:14649",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-06-22 19:43:10",
            "last_seen_utc": "2026-06-30 10:43:14",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1836137": [
        {
            "ioc_value": "103.11.41.10:9428",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-06-22 19:43:04",
            "last_seen_utc": "2026-06-30 10:43:06",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1836138": [
        {
            "ioc_value": "103.11.41.19:5213",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-06-22 19:43:04",
            "last_seen_utc": "2026-06-30 10:43:07",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1835600": [
        {
            "ioc_value": "web-protection.beer",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-06-22 11:41:17",
            "last_seen_utc": "2026-06-29 13:39:34",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "dead-drop-c2,polygon-deaddrop,SmartLoader,SmartLoader-MaaS",
            "anonymous": "1",
            "reporter": "turnasmyth015"
        }
    ],
    "1835590": [
        {
            "ioc_value": "llc-image-ico.click",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-06-22 11:41:16",
            "last_seen_utc": "2026-06-29 13:39:46",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "dead-drop-c2,polygon-deaddrop,SmartLoader,SmartLoader-MaaS",
            "anonymous": "1",
            "reporter": "turnasmyth015"
        }
    ],
    "1835573": [
        {
            "ioc_value": "204.194.54.198:53",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-06-22 09:46:29",
            "last_seen_utc": "2026-06-30 10:46:56",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1835572": [
        {
            "ioc_value": "ns2.msgkg.xyz",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-06-22 09:46:01",
            "last_seen_utc": "2026-06-30 10:46:27",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1835571": [
        {
            "ioc_value": "ns1.msgkg.xyz",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-06-22 09:45:59",
            "last_seen_utc": "2026-06-30 10:46:25",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1835570": [
        {
            "ioc_value": "5.101.86.23:8455",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-06-22 09:45:28",
            "last_seen_utc": "2026-06-30 10:45:50",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1835569": [
        {
            "ioc_value": "46.161.0.48:2428",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-06-22 09:45:23",
            "last_seen_utc": "2026-06-30 10:45:44",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1835568": [
        {
            "ioc_value": "45.81.243.44:8808",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-06-22 09:45:21",
            "last_seen_utc": "2026-06-30 10:45:42",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1835567": [
        {
            "ioc_value": "217.60.195.194:14648",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-06-22 09:44:56",
            "last_seen_utc": "2026-06-30 10:45:18",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1835565": [
        {
            "ioc_value": "205.209.106.158:6606",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-06-22 09:44:19",
            "last_seen_utc": "2026-06-30 10:44:29",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1835566": [
        {
            "ioc_value": "205.209.106.158:8808",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-06-22 09:44:19",
            "last_seen_utc": "2026-06-30 10:44:29",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1835564": [
        {
            "ioc_value": "205.209.106.158:4444",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-06-22 09:44:18",
            "last_seen_utc": "2026-06-30 10:44:29",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1835562": [
        {
            "ioc_value": "192.236.217.70:24047",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-06-22 09:44:05",
            "last_seen_utc": "2026-06-30 10:44:15",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1835563": [
        {
            "ioc_value": "192.236.217.70:24048",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-06-22 09:44:05",
            "last_seen_utc": "2026-06-30 10:44:15",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1835561": [
        {
            "ioc_value": "185.212.128.215:9000",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.evilginx",
            "malware_alias": null,
            "malware_printable": "Evilginx",
            "first_seen_utc": "2026-06-22 09:43:56",
            "last_seen_utc": "2026-06-30 10:44:06",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Evilginx,EvilGoPhish",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1835560": [
        {
            "ioc_value": "13.140.160.249:8808",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-06-22 09:43:16",
            "last_seen_utc": "2026-06-30 10:43:20",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1835559": [
        {
            "ioc_value": "107.173.9.99:14648",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-06-22 09:43:10",
            "last_seen_utc": "2026-06-30 10:43:14",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1835557": [
        {
            "ioc_value": "103.11.41.10:7408",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-06-22 09:43:04",
            "last_seen_utc": "2026-06-30 10:43:06",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1835558": [
        {
            "ioc_value": "103.11.41.19:126",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-06-22 09:43:04",
            "last_seen_utc": "2026-06-30 10:43:07",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1835556": [
        {
            "ioc_value": "102.220.160.250:7829",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-06-22 09:43:03",
            "last_seen_utc": "2026-06-30 10:43:05",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1835379": [
        {
            "ioc_value": "74.48.84.24:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-06-22 06:39:32",
            "last_seen_utc": "2026-06-30 10:47:15",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-666666666",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1835346": [
        {
            "ioc_value": "3.132.75.97:55510",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "apk.vo1d",
            "malware_alias": null,
            "malware_printable": "vo1d",
            "first_seen_utc": "2026-06-22 06:22:32",
            "last_seen_utc": "2026-06-30 01:02:01",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "redirector,Vo1d",
            "anonymous": "0",
            "reporter": "Bitsight"
        }
    ],
    "1835362": [
        {
            "ioc_value": "119.45.166.6:9876",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-06-22 03:45:53",
            "last_seen_utc": "2026-06-30 10:46:40",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1835339": [
        {
            "ioc_value": "115.190.149.214:58848",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-06-21 23:45:40",
            "last_seen_utc": "2026-06-30 10:46:36",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1834981": [
        {
            "ioc_value": "freesoftupdater.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-06-21 22:35:18",
            "last_seen_utc": "2026-06-29 13:25:00",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "C2,ClickFix,Polygon",
            "anonymous": "0",
            "reporter": "varysz"
        }
    ],
    "1834984": [
        {
            "ioc_value": "ocean-animals.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-06-21 22:35:18",
            "last_seen_utc": "2026-06-29 13:25:05",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "C2,ClickFix,Polygon",
            "anonymous": "0",
            "reporter": "varysz"
        }
    ],
    "1834985": [
        {
            "ioc_value": "park-lake.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-06-21 22:35:18",
            "last_seen_utc": "2026-06-29 13:25:03",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "C2,ClickFix,Polygon",
            "anonymous": "0",
            "reporter": "varysz"
        }
    ],
    "1834986": [
        {
            "ioc_value": "updatecurrent.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-06-21 22:35:18",
            "last_seen_utc": "2026-06-29 13:25:42",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "C2,ClickFix,Polygon",
            "anonymous": "0",
            "reporter": "varysz"
        }
    ],
    "1834987": [
        {
            "ioc_value": "updatemsnow.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-06-21 22:35:18",
            "last_seen_utc": "2026-06-29 13:25:40",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "C2,ClickFix,Polygon",
            "anonymous": "0",
            "reporter": "varysz"
        }
    ],
    "1834988": [
        {
            "ioc_value": "updateocean.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-06-21 22:35:18",
            "last_seen_utc": "2026-06-29 16:02:17",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "C2,ClickFix,Polygon",
            "anonymous": "0",
            "reporter": "varysz"
        }
    ],
    "1834989": [
        {
            "ioc_value": "updateyourprogram.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-06-21 22:35:18",
            "last_seen_utc": "2026-06-29 13:25:01",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "C2,ClickFix,Polygon",
            "anonymous": "0",
            "reporter": "varysz"
        }
    ],
    "1834990": [
        {
            "ioc_value": "updateyoursoft.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-06-21 22:35:18",
            "last_seen_utc": "2026-06-29 13:24:58",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "C2,ClickFix,Polygon",
            "anonymous": "0",
            "reporter": "varysz"
        }
    ],
    "1834991": [
        {
            "ioc_value": "uptodatehere.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-06-21 22:35:18",
            "last_seen_utc": "2026-06-29 13:25:38",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "C2,ClickFix,Polygon",
            "anonymous": "0",
            "reporter": "varysz"
        }
    ],
    "1834976": [
        {
            "ioc_value": "animal-zoo-lake.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-06-21 22:35:17",
            "last_seen_utc": "2026-06-29 13:25:07",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "C2,ClickFix,Polygon",
            "anonymous": "0",
            "reporter": "varysz"
        }
    ],
    "1834977": [
        {
            "ioc_value": "autoupdaters.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-06-21 22:35:17",
            "last_seen_utc": "2026-06-29 16:02:18",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "C2,ClickFix,Polygon",
            "anonymous": "0",
            "reporter": "varysz"
        }
    ],
    "1834978": [
        {
            "ioc_value": "autoupdatet.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-06-21 22:35:17",
            "last_seen_utc": "2026-06-29 16:02:19",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "C2,ClickFix,Polygon",
            "anonymous": "0",
            "reporter": "varysz"
        }
    ],
    "1834979": [
        {
            "ioc_value": "autoupdatethis.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-06-21 22:35:17",
            "last_seen_utc": "2026-06-29 16:02:21",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "C2,ClickFix,Polygon",
            "anonymous": "0",
            "reporter": "varysz"
        }
    ],
    "1834964": [
        {
            "ioc_value": "5.101.86.67:5691",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-06-21 19:45:25",
            "last_seen_utc": "2026-06-30 10:45:51",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1834962": [
        {
            "ioc_value": "45.154.98.254:2004",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-06-21 19:45:13",
            "last_seen_utc": "2026-06-30 10:45:36",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1834963": [
        {
            "ioc_value": "45.154.98.254:2006",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-06-21 19:45:13",
            "last_seen_utc": "2026-06-30 10:45:37",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1834960": [
        {
            "ioc_value": "217.60.195.194:14643",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-06-21 19:44:53",
            "last_seen_utc": "2026-06-30 10:45:17",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1834961": [
        {
            "ioc_value": "217.60.195.194:14647",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-06-21 19:44:53",
            "last_seen_utc": "2026-06-30 10:45:18",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1834959": [
        {
            "ioc_value": "198.23.185.136:7007",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-06-21 19:44:09",
            "last_seen_utc": "2026-06-30 10:44:22",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1834958": [
        {
            "ioc_value": "194.116.236.239:4020",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-06-21 19:44:05",
            "last_seen_utc": "2026-06-30 10:44:18",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1834957": [
        {
            "ioc_value": "185.115.164.60:13766",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-06-21 19:43:51",
            "last_seen_utc": "2026-06-30 10:44:03",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1834956": [
        {
            "ioc_value": "156.247.51.40:8848",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.dcrat",
            "malware_alias": "DarkCrystal RAT",
            "malware_printable": "DCRat",
            "first_seen_utc": "2026-06-21 19:43:28",
            "last_seen_utc": "2026-06-30 10:43:36",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DCRat,drb-ra,RAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1834955": [
        {
            "ioc_value": "147.93.191.75:90",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-06-21 19:43:23",
            "last_seen_utc": "2026-06-30 10:43:30",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1834954": [
        {
            "ioc_value": "137.220.154.16:8848",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.dcrat",
            "malware_alias": "DarkCrystal RAT",
            "malware_printable": "DCRat",
            "first_seen_utc": "2026-06-21 19:43:17",
            "last_seen_utc": "2026-06-30 10:43:22",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DCRat,drb-ra,RAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1834953": [
        {
            "ioc_value": "103.110.80.154:7444",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-06-21 19:43:05",
            "last_seen_utc": "2026-06-30 10:43:08",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "Covenant,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1834952": [
        {
            "ioc_value": "103.11.41.19:9233",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-06-21 19:43:04",
            "last_seen_utc": "2026-06-30 10:43:07",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1834788": [
        {
            "ioc_value": "birdybird.rest",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-06-21 18:27:36",
            "last_seen_utc": "2026-06-29 13:26:26",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "",
            "tags": "c2,ClickFix,Vidar",
            "anonymous": "0",
            "reporter": "varysz"
        }
    ],
    "1834789": [
        {
            "ioc_value": "codecerification.beer",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-06-21 18:27:36",
            "last_seen_utc": "2026-06-29 16:02:02",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "",
            "tags": "c2,ClickFix,Vidar",
            "anonymous": "0",
            "reporter": "varysz"
        }
    ],
    "1834790": [
        {
            "ioc_value": "holopebamiy.bond",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-06-21 18:27:36",
            "last_seen_utc": "2026-06-29 13:26:24",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "",
            "tags": "c2,ClickFix,Vidar",
            "anonymous": "0",
            "reporter": "varysz"
        }
    ],
    "1834792": [
        {
            "ioc_value": "idverification-code.beer",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-06-21 18:27:35",
            "last_seen_utc": "2026-06-29 12:29:09",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "",
            "tags": "c2,ClickFix,Vidar",
            "anonymous": "0",
            "reporter": "varysz"
        }
    ],
    "1834794": [
        {
            "ioc_value": "mampodik.asia",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-06-21 18:27:34",
            "last_seen_utc": "2026-06-29 13:26:31",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "",
            "tags": "c2,ClickFix,Vidar",
            "anonymous": "0",
            "reporter": "varysz"
        }
    ],
    "1834796": [
        {
            "ioc_value": "svs-verificationdate.beer",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-06-21 18:27:34",
            "last_seen_utc": "2026-06-29 13:30:41",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "",
            "tags": "c2,ClickFix,Vidar",
            "anonymous": "0",
            "reporter": "varysz"
        }
    ],
    "1834795": [
        {
            "ioc_value": "smenapodik.bond",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-06-21 18:27:33",
            "last_seen_utc": "2026-06-29 13:26:29",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "",
            "tags": "c2,ClickFix,Vidar",
            "anonymous": "0",
            "reporter": "varysz"
        }
    ],
    "1834782": [
        {
            "ioc_value": "87.199.196.12:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.havoc",
            "malware_alias": "Havokiz",
            "malware_printable": "Havoc",
            "first_seen_utc": "2026-06-21 14:00:20",
            "last_seen_utc": "2026-06-30 10:46:13",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "havoc",
            "anonymous": "1",
            "reporter": "_ik_"
        }
    ],
    "1834771": [
        {
            "ioc_value": "89.42.134.220:6606",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-06-21 09:45:40",
            "last_seen_utc": "2026-06-30 10:46:15",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1834770": [
        {
            "ioc_value": "51.79.51.255:4321",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-06-21 09:45:23",
            "last_seen_utc": "2026-06-30 10:45:54",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1834769": [
        {
            "ioc_value": "45.81.243.44:7707",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-06-21 09:45:12",
            "last_seen_utc": "2026-06-30 10:45:42",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1834768": [
        {
            "ioc_value": "45.140.14.29:1489",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-06-21 09:45:07",
            "last_seen_utc": "2026-06-30 10:45:35",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1834765": [
        {
            "ioc_value": "191.107.87.183:5010",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-06-21 09:43:59",
            "last_seen_utc": "2026-06-30 10:44:12",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1834766": [
        {
            "ioc_value": "191.107.87.183:8917",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-06-21 09:43:59",
            "last_seen_utc": "2026-06-30 10:44:13",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1834767": [
        {
            "ioc_value": "191.107.87.183:9140",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-06-21 09:43:59",
            "last_seen_utc": "2026-06-30 10:44:13",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1834764": [
        {
            "ioc_value": "185.115.164.59:808",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-06-21 09:43:51",
            "last_seen_utc": "2026-06-30 10:44:01",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1834763": [
        {
            "ioc_value": "150.40.117.39:43723",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.havoc",
            "malware_alias": "Havokiz",
            "malware_printable": "Havoc",
            "first_seen_utc": "2026-06-21 09:43:24",
            "last_seen_utc": "2026-06-30 10:43:32",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Havoc",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1834762": [
        {
            "ioc_value": "147.93.191.75:1111",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-06-21 09:43:22",
            "last_seen_utc": "2026-06-30 10:43:29",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1834761": [
        {
            "ioc_value": "141.98.10.150:14641",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-06-21 09:43:18",
            "last_seen_utc": "2026-06-30 10:43:24",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1834759": [
        {
            "ioc_value": "103.67.163.27:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-06-21 09:43:07",
            "last_seen_utc": "2026-06-30 10:43:10",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1834760": [
        {
            "ioc_value": "103.67.163.27:8080",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-06-21 09:43:07",
            "last_seen_utc": "2026-06-30 10:43:10",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1834758": [
        {
            "ioc_value": "103.6.219.25:6745",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-06-21 09:43:06",
            "last_seen_utc": "2026-06-30 10:43:10",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1834756": [
        {
            "ioc_value": "103.11.41.10:431",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-06-21 09:43:04",
            "last_seen_utc": "2026-06-30 10:43:06",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1834757": [
        {
            "ioc_value": "103.11.41.10:51490",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-06-21 09:43:04",
            "last_seen_utc": "2026-06-30 10:43:06",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1834559": [
        {
            "ioc_value": "116.213.42.110:5005",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-06-20 19:45:51",
            "last_seen_utc": "2026-06-30 10:46:37",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1834558": [
        {
            "ioc_value": "100.110.56.1:8000",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-06-20 19:45:45",
            "last_seen_utc": "2026-06-30 10:46:30",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1834557": [
        {
            "ioc_value": "89.124.107.161:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-06-20 19:45:29",
            "last_seen_utc": "2026-06-30 10:46:14",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1834556": [
        {
            "ioc_value": "80.211.129.141:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-06-20 19:45:24",
            "last_seen_utc": "2026-06-30 10:46:07",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1834555": [
        {
            "ioc_value": "8.217.141.231:636",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-06-20 19:45:23",
            "last_seen_utc": "2026-06-30 10:46:06",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1834554": [
        {
            "ioc_value": "5.200.176.105:55476",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.dcrat",
            "malware_alias": "DarkCrystal RAT",
            "malware_printable": "DCRat",
            "first_seen_utc": "2026-06-20 19:45:13",
            "last_seen_utc": "2026-06-30 10:45:52",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DCRat,drb-ra,RAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1834553": [
        {
            "ioc_value": "5.101.85.65:4321",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-06-20 19:45:10",
            "last_seen_utc": "2026-06-30 10:45:49",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1834552": [
        {
            "ioc_value": "47.243.211.244:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-06-20 19:45:07",
            "last_seen_utc": "2026-06-30 10:45:46",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1834551": [
        {
            "ioc_value": "45.81.243.44:6606",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-06-20 19:45:01",
            "last_seen_utc": "2026-06-30 10:45:42",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1834550": [
        {
            "ioc_value": "45.77.254.232:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-06-20 19:45:00",
            "last_seen_utc": "2026-06-30 10:45:42",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1834549": [
        {
            "ioc_value": "198.23.185.136:10900",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-06-20 19:44:03",
            "last_seen_utc": "2026-06-30 10:44:22",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1834547": [
        {
            "ioc_value": "195.20.115.197:7707",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-06-20 19:44:01",
            "last_seen_utc": "2026-06-30 10:44:20",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1834548": [
        {
            "ioc_value": "195.20.115.197:7829",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-06-20 19:44:01",
            "last_seen_utc": "2026-06-30 10:44:20",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1834546": [
        {
            "ioc_value": "195.20.115.197:6606",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-06-20 19:44:00",
            "last_seen_utc": "2026-06-30 10:44:20",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1834545": [
        {
            "ioc_value": "188.23.170.123:8000",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.eye_pyramid",
            "malware_alias": null,
            "malware_printable": "Eye Pyramid",
            "first_seen_utc": "2026-06-20 19:43:54",
            "last_seen_utc": "2026-06-30 10:44:11",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,EyePyramid",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1834544": [
        {
            "ioc_value": "162.216.241.206:7997",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.dcrat",
            "malware_alias": "DarkCrystal RAT",
            "malware_printable": "DCRat",
            "first_seen_utc": "2026-06-20 19:43:30",
            "last_seen_utc": "2026-06-30 10:43:41",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DCRat,drb-ra,RAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1834542": [
        {
            "ioc_value": "13.140.160.249:6606",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-06-20 19:43:13",
            "last_seen_utc": "2026-06-30 10:43:20",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1834543": [
        {
            "ioc_value": "13.140.160.249:7707",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-06-20 19:43:13",
            "last_seen_utc": "2026-06-30 10:43:20",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1834541": [
        {
            "ioc_value": "104.194.151.163:65381",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-06-20 19:43:06",
            "last_seen_utc": "2026-06-30 10:43:11",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1834540": [
        {
            "ioc_value": "102.220.160.217:6606",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-06-20 19:43:02",
            "last_seen_utc": "2026-06-30 10:43:03",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1834291": [
        {
            "ioc_value": "43.138.165.203:9002",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-06-20 14:00:22",
            "last_seen_utc": "2026-06-30 10:47:01",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "cobaltstrike",
            "anonymous": "1",
            "reporter": "_ik_"
        }
    ],
    "1834285": [
        {
            "ioc_value": "43.143.244.134:4443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-06-20 11:46:49",
            "last_seen_utc": "2026-06-30 10:47:04",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1834284": [
        {
            "ioc_value": "139.196.89.43:10443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-06-20 11:46:31",
            "last_seen_utc": "2026-06-30 10:46:45",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1834279": [
        {
            "ioc_value": "5.188.61.49:44443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.eye_pyramid",
            "malware_alias": null,
            "malware_printable": "Eye Pyramid",
            "first_seen_utc": "2026-06-20 09:45:43",
            "last_seen_utc": "2026-06-30 10:45:52",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,EyePyramid",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1834278": [
        {
            "ioc_value": "47.83.254.175:4321",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-06-20 09:45:38",
            "last_seen_utc": "2026-06-30 10:45:47",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1834277": [
        {
            "ioc_value": "45.32.64.12:4321",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-06-20 09:45:31",
            "last_seen_utc": "2026-06-30 10:45:39",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1834276": [
        {
            "ioc_value": "36.50.85.69:1235",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-06-20 09:45:20",
            "last_seen_utc": "2026-06-30 10:45:28",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1834275": [
        {
            "ioc_value": "217.60.195.176:2404",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-06-20 09:45:10",
            "last_seen_utc": "2026-06-30 10:45:17",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1834274": [
        {
            "ioc_value": "198.23.185.136:20600",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-06-20 09:44:18",
            "last_seen_utc": "2026-06-30 10:44:22",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1834273": [
        {
            "ioc_value": "188.253.104.174:2026",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-06-20 09:44:08",
            "last_seen_utc": "2026-06-30 10:44:12",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1834272": [
        {
            "ioc_value": "147.93.191.75:30400",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-06-20 09:43:25",
            "last_seen_utc": "2026-06-30 10:43:29",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1834121": [
        {
            "ioc_value": "213.209.159.66:5432",
            "ioc_type": "ip:port",
            "threat_type": "payload_delivery",
            "malware": "elf.xmrig",
            "malware_alias": null,
            "malware_printable": "XMRIG",
            "first_seen_utc": "2026-06-20 05:49:56",
            "last_seen_utc": "2026-06-28 21:15:59",
            "confidence_level": 80,
            "is_compromised": false,
            "reference": "https://twitter.com/NullBlue67",
            "tags": "postgres,takeover",
            "anonymous": "0",
            "reporter": "nullblue67"
        }
    ],
    "1834187": [
        {
            "ioc_value": "23.141.12.111:8899",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-06-19 23:46:13",
            "last_seen_utc": "2026-06-30 10:46:58",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1834186": [
        {
            "ioc_value": "149.88.66.234:8080",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-06-19 23:46:03",
            "last_seen_utc": "2026-06-30 10:46:46",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1834185": [
        {
            "ioc_value": "116.204.36.177:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-06-19 23:45:54",
            "last_seen_utc": "2026-06-30 10:46:37",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1834170": [
        {
            "ioc_value": "97.74.92.237:63334",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-06-19 19:45:40",
            "last_seen_utc": "2026-06-30 10:46:19",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1834169": [
        {
            "ioc_value": "45.81.243.44:7089",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-06-19 19:45:09",
            "last_seen_utc": "2026-06-30 10:45:42",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1834168": [
        {
            "ioc_value": "211.235.43.192:7707",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-06-19 19:44:17",
            "last_seen_utc": "2026-06-30 10:44:35",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1834167": [
        {
            "ioc_value": "205.209.106.158:5228",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-06-19 19:44:13",
            "last_seen_utc": "2026-06-30 10:44:29",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1834165": [
        {
            "ioc_value": "2.27.5.37:8912",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-06-19 19:44:09",
            "last_seen_utc": "2026-06-30 10:44:26",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1834166": [
        {
            "ioc_value": "2.27.5.42:6448",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-06-19 19:44:09",
            "last_seen_utc": "2026-06-30 10:44:26",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1834164": [
        {
            "ioc_value": "198.23.185.136:60",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-06-19 19:44:06",
            "last_seen_utc": "2026-06-30 10:44:22",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1834163": [
        {
            "ioc_value": "194.48.251.24:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.mirai",
            "malware_alias": "Katana",
            "malware_printable": "Mirai",
            "first_seen_utc": "2026-06-19 19:44:04",
            "last_seen_utc": "2026-06-30 10:44:20",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mirai",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1834162": [
        {
            "ioc_value": "155.103.71.115:14646",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-06-19 19:43:26",
            "last_seen_utc": "2026-06-30 10:43:35",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1834161": [
        {
            "ioc_value": "141.98.10.150:14646",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-06-19 19:43:18",
            "last_seen_utc": "2026-06-30 10:43:25",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1834160": [
        {
            "ioc_value": "107.172.238.13:14646",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-06-19 19:43:09",
            "last_seen_utc": "2026-06-30 10:43:13",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1834159": [
        {
            "ioc_value": "102.220.160.222:2025",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-06-19 19:43:03",
            "last_seen_utc": "2026-06-30 10:43:04",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1834134": [
        {
            "ioc_value": "81.69.253.132:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-06-19 15:46:33",
            "last_seen_utc": "2026-06-30 10:47:18",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1834132": [
        {
            "ioc_value": "47.242.0.207:8080",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-06-19 15:46:26",
            "last_seen_utc": "2026-06-30 10:47:11",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1834133": [
        {
            "ioc_value": "47.242.0.207:9999",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-06-19 15:46:26",
            "last_seen_utc": "2026-06-30 10:47:11",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1834131": [
        {
            "ioc_value": "114.134.187.38:9999",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-06-19 15:45:55",
            "last_seen_utc": "2026-06-30 10:46:36",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1834108": [
        {
            "ioc_value": "173.231.188.244:14641",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-06-19 13:55:35",
            "last_seen_utc": "2026-06-30 10:43:51",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://bazaar.abuse.ch/sample/d113f72b9248e3a89d72d1238a8465af7857822b82951681cff22391ffff3039/",
            "tags": "remcos",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1834100": [
        {
            "ioc_value": "64.90.3.208:7891",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-06-19 11:46:53",
            "last_seen_utc": "2026-06-30 10:47:14",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1834098": [
        {
            "ioc_value": "185.92.190.214:8896",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-06-19 11:46:35",
            "last_seen_utc": "2026-06-30 10:46:54",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1834099": [
        {
            "ioc_value": "185.92.190.216:8896",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-06-19 11:46:35",
            "last_seen_utc": "2026-06-30 10:46:54",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1834097": [
        {
            "ioc_value": "www.api-aws.xyz",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-06-19 11:46:11",
            "last_seen_utc": "2026-06-30 10:46:28",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1834066": [
        {
            "ioc_value": "91.92.242.67:7707",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-06-19 09:45:54",
            "last_seen_utc": "2026-06-30 10:46:17",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1834063": [
        {
            "ioc_value": "77.110.119.172:4321",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-06-19 09:45:43",
            "last_seen_utc": "2026-06-30 10:46:05",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1834064": [
        {
            "ioc_value": "78.108.56.64:9405",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-06-19 09:45:43",
            "last_seen_utc": "2026-06-30 10:46:05",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1834065": [
        {
            "ioc_value": "78.108.57.24:8912",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-06-19 09:45:43",
            "last_seen_utc": "2026-06-30 10:46:05",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1834060": [
        {
            "ioc_value": "45.32.66.51:6606",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-06-19 09:45:22",
            "last_seen_utc": "2026-06-30 10:45:39",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1834059": [
        {
            "ioc_value": "198.23.185.82:7777",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-06-19 09:44:13",
            "last_seen_utc": "2026-06-30 10:44:23",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1834058": [
        {
            "ioc_value": "194.116.236.239:4068",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-06-19 09:44:10",
            "last_seen_utc": "2026-06-30 10:44:18",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1834057": [
        {
            "ioc_value": "186.246.8.63:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.bianlian",
            "malware_alias": null,
            "malware_printable": "BianLian",
            "first_seen_utc": "2026-06-19 09:44:03",
            "last_seen_utc": "2026-06-30 10:44:11",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "Bianlian,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1834056": [
        {
            "ioc_value": "185.158.249.112:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-06-19 09:43:56",
            "last_seen_utc": "2026-06-30 10:44:03",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1834055": [
        {
            "ioc_value": "147.93.191.75:30700",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-06-19 09:43:24",
            "last_seen_utc": "2026-06-30 10:43:30",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1834054": [
        {
            "ioc_value": "139.180.190.68:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.havoc",
            "malware_alias": "Havokiz",
            "malware_printable": "Havoc",
            "first_seen_utc": "2026-06-19 09:43:19",
            "last_seen_utc": "2026-06-30 10:43:24",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Havoc",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1834053": [
        {
            "ioc_value": "138.2.120.11:61234",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-06-19 09:43:18",
            "last_seen_utc": "2026-06-30 10:43:23",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1834052": [
        {
            "ioc_value": "128.90.105.170:7203",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.dcrat",
            "malware_alias": "DarkCrystal RAT",
            "malware_printable": "DCRat",
            "first_seen_utc": "2026-06-19 09:43:15",
            "last_seen_utc": "2026-06-30 10:43:19",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DCRat,drb-ra,RAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1834051": [
        {
            "ioc_value": "103.153.254.32:6933",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-06-19 09:43:05",
            "last_seen_utc": "2026-06-30 10:43:09",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1834050": [
        {
            "ioc_value": "102.220.160.217:7707",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-06-19 09:43:03",
            "last_seen_utc": "2026-06-30 10:43:04",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1834034": [
        {
            "ioc_value": "198.23.185.136:3000",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-06-19 08:00:23",
            "last_seen_utc": "2026-06-30 10:44:22",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "asyncrat",
            "anonymous": "1",
            "reporter": "_ik_"
        }
    ],
    "1834029": [
        {
            "ioc_value": "151.239.24.122:9090",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-06-19 07:43:54",
            "last_seen_utc": "2026-06-30 10:46:46",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-987654321",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1833906": [
        {
            "ioc_value": "45.198.224.5:2375",
            "ioc_type": "ip:port",
            "threat_type": "payload_delivery",
            "malware": "elf.mirai",
            "malware_alias": "Katana",
            "malware_printable": "Mirai",
            "first_seen_utc": "2026-06-19 05:56:52",
            "last_seen_utc": "2026-06-29 09:40:42",
            "confidence_level": 80,
            "is_compromised": false,
            "reference": "https://twitter.com/NullBlue67",
            "tags": "docker-api,rotator",
            "anonymous": "0",
            "reporter": "nullblue67"
        }
    ],
    "1833917": [
        {
            "ioc_value": "115.190.147.66:63512",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-06-18 23:45:44",
            "last_seen_utc": "2026-06-30 10:46:36",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1833874": [
        {
            "ioc_value": "91.92.240.194:8848",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.dcrat",
            "malware_alias": "DarkCrystal RAT",
            "malware_printable": "DCRat",
            "first_seen_utc": "2026-06-18 19:45:29",
            "last_seen_utc": "2026-06-30 10:46:17",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DCRat,drb-ra,RAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1833873": [
        {
            "ioc_value": "91.124.19.150:4509",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-06-18 19:45:28",
            "last_seen_utc": "2026-06-30 10:46:15",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1833871": [
        {
            "ioc_value": "87.76.179.153:9521",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-06-18 19:45:26",
            "last_seen_utc": "2026-06-30 10:46:13",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1833872": [
        {
            "ioc_value": "87.76.179.22:8814",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-06-18 19:45:26",
            "last_seen_utc": "2026-06-30 10:46:13",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1833870": [
        {
            "ioc_value": "82.146.52.98:8790",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.bianlian",
            "malware_alias": null,
            "malware_printable": "BianLian",
            "first_seen_utc": "2026-06-18 19:45:22",
            "last_seen_utc": "2026-06-30 10:46:08",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "Bianlian,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1833868": [
        {
            "ioc_value": "77.237.119.204:4433",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.danabot",
            "malware_alias": "DanaTools",
            "malware_printable": "DanaBot",
            "first_seen_utc": "2026-06-18 19:45:19",
            "last_seen_utc": "2026-06-30 10:46:05",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DanBot,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1833867": [
        {
            "ioc_value": "64.89.160.127:8086",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-06-18 19:45:16",
            "last_seen_utc": "2026-06-30 10:45:59",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1833866": [
        {
            "ioc_value": "45.91.138.95:9019",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-06-18 19:44:59",
            "last_seen_utc": "2026-06-30 10:45:43",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1833865": [
        {
            "ioc_value": "38.242.144.218:4498",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-06-18 19:44:50",
            "last_seen_utc": "2026-06-30 10:45:30",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1833864": [
        {
            "ioc_value": "31.76.87.105:8455",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-06-18 19:44:47",
            "last_seen_utc": "2026-06-30 10:45:25",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1833863": [
        {
            "ioc_value": "23.95.103.214:6024",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-06-18 19:44:43",
            "last_seen_utc": "2026-06-30 10:45:20",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1833860": [
        {
            "ioc_value": "209.54.102.152:14641",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-06-18 19:44:10",
            "last_seen_utc": "2026-06-30 10:44:32",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1833861": [
        {
            "ioc_value": "209.54.102.152:14644",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-06-18 19:44:10",
            "last_seen_utc": "2026-06-30 10:44:32",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1833862": [
        {
            "ioc_value": "209.54.102.152:14646",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-06-18 19:44:10",
            "last_seen_utc": "2026-06-30 10:44:32",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1833859": [
        {
            "ioc_value": "176.12.64.118:8790",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.bianlian",
            "malware_alias": null,
            "malware_printable": "BianLian",
            "first_seen_utc": "2026-06-18 19:43:39",
            "last_seen_utc": "2026-06-30 10:43:52",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "Bianlian,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1833858": [
        {
            "ioc_value": "162.35.164.249:12262",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-06-18 19:43:31",
            "last_seen_utc": "2026-06-30 10:43:42",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1833857": [
        {
            "ioc_value": "147.93.191.75:5005",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-06-18 19:43:21",
            "last_seen_utc": "2026-06-30 10:43:30",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1833853": [
        {
            "ioc_value": "141.98.10.150:14642",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-06-18 19:43:17",
            "last_seen_utc": "2026-06-30 10:43:24",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1833854": [
        {
            "ioc_value": "141.98.10.150:14643",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-06-18 19:43:17",
            "last_seen_utc": "2026-06-30 10:43:24",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1833855": [
        {
            "ioc_value": "141.98.10.150:14644",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-06-18 19:43:17",
            "last_seen_utc": "2026-06-30 10:43:25",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1833856": [
        {
            "ioc_value": "141.98.10.150:14645",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-06-18 19:43:17",
            "last_seen_utc": "2026-06-30 10:43:25",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1833852": [
        {
            "ioc_value": "115.190.108.6:54233",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.poshc2",
            "malware_alias": null,
            "malware_printable": "PoshC2",
            "first_seen_utc": "2026-06-18 19:43:11",
            "last_seen_utc": "2026-06-30 10:43:17",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PoshC2",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1833851": [
        {
            "ioc_value": "107.172.238.14:14644",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-06-18 19:43:09",
            "last_seen_utc": "2026-06-30 10:43:13",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1833850": [
        {
            "ioc_value": "107.172.238.13:14644",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-06-18 19:43:08",
            "last_seen_utc": "2026-06-30 10:43:13",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1833848": [
        {
            "ioc_value": "102.220.160.217:8808",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-06-18 19:43:03",
            "last_seen_utc": "2026-06-30 10:43:04",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1833849": [
        {
            "ioc_value": "102.220.160.222:2600",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-06-18 19:43:03",
            "last_seen_utc": "2026-06-30 10:43:04",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1833770": [
        {
            "ioc_value": "188.227.14.105:547",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-06-18 11:46:05",
            "last_seen_utc": "2026-06-30 10:46:55",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1833753": [
        {
            "ioc_value": "98.142.241.170:31337",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.sliver",
            "malware_alias": null,
            "malware_printable": "Sliver",
            "first_seen_utc": "2026-06-18 09:46:05",
            "last_seen_utc": "2026-06-30 10:46:19",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Sliver",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1833754": [
        {
            "ioc_value": "98.142.241.170:8443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.sliver",
            "malware_alias": null,
            "malware_printable": "Sliver",
            "first_seen_utc": "2026-06-18 09:46:05",
            "last_seen_utc": "2026-06-30 10:46:19",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Sliver",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1833752": [
        {
            "ioc_value": "91.223.208.217:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-06-18 09:46:00",
            "last_seen_utc": "2026-06-30 10:46:16",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1833751": [
        {
            "ioc_value": "83.142.209.31:7829",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-06-18 09:45:54",
            "last_seen_utc": "2026-06-30 10:46:09",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1833750": [
        {
            "ioc_value": "54.38.94.225:8884",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.eye_pyramid",
            "malware_alias": null,
            "malware_printable": "Eye Pyramid",
            "first_seen_utc": "2026-06-18 09:45:43",
            "last_seen_utc": "2026-06-30 10:45:56",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,EyePyramid",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1833749": [
        {
            "ioc_value": "35.254.198.45:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-06-18 09:45:15",
            "last_seen_utc": "2026-06-30 10:45:27",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1833747": [
        {
            "ioc_value": "31.77.168.220:3009",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-06-18 09:45:13",
            "last_seen_utc": "2026-06-30 10:45:26",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1833748": [
        {
            "ioc_value": "31.77.168.220:3010",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-06-18 09:45:13",
            "last_seen_utc": "2026-06-30 10:45:26",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1833744": [
        {
            "ioc_value": "209.99.191.33:440",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-06-18 09:44:25",
            "last_seen_utc": "2026-06-30 10:44:34",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1833743": [
        {
            "ioc_value": "198.23.185.136:8008",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-06-18 09:44:14",
            "last_seen_utc": "2026-06-30 10:44:22",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1833742": [
        {
            "ioc_value": "178.16.55.204:5022",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.dcrat",
            "malware_alias": "DarkCrystal RAT",
            "malware_printable": "DCRat",
            "first_seen_utc": "2026-06-18 09:43:47",
            "last_seen_utc": "2026-06-30 10:43:53",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DCRat,drb-ra,RAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1833741": [
        {
            "ioc_value": "172.245.195.233:14643",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-06-18 09:43:41",
            "last_seen_utc": "2026-06-30 10:43:48",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1833740": [
        {
            "ioc_value": "147.124.212.146:3096",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-06-18 09:43:23",
            "last_seen_utc": "2026-06-30 10:43:28",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1833623": [
        {
            "ioc_value": "62.113.59.64:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-06-17 23:46:03",
            "last_seen_utc": "2026-06-30 10:47:14",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1833622": [
        {
            "ioc_value": "106.13.189.138:56000",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-06-17 23:45:31",
            "last_seen_utc": "2026-06-30 10:46:32",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1833607": [
        {
            "ioc_value": "221.132.29.137:81",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-06-17 20:00:17",
            "last_seen_utc": "2026-06-30 10:46:57",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "cobaltstrike",
            "anonymous": "1",
            "reporter": "_ik_"
        }
    ],
    "1833605": [
        {
            "ioc_value": "96.44.167.215:14649",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-06-17 19:45:31",
            "last_seen_utc": "2026-06-30 10:46:19",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1833604": [
        {
            "ioc_value": "85.11.167.9:8443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.bianlian",
            "malware_alias": null,
            "malware_printable": "BianLian",
            "first_seen_utc": "2026-06-17 19:45:24",
            "last_seen_utc": "2026-06-30 10:46:11",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "Bianlian,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1833603": [
        {
            "ioc_value": "64.89.160.127:1960",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-06-17 19:45:16",
            "last_seen_utc": "2026-06-30 10:45:59",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1833602": [
        {
            "ioc_value": "5.101.82.60:27015",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-06-17 19:45:06",
            "last_seen_utc": "2026-06-30 10:45:49",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1833601": [
        {
            "ioc_value": "45.151.102.251:7528",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-06-17 19:44:54",
            "last_seen_utc": "2026-06-30 10:45:36",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1833600": [
        {
            "ioc_value": "209.54.102.152:14645",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-06-17 19:44:09",
            "last_seen_utc": "2026-06-30 10:44:32",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1833599": [
        {
            "ioc_value": "192.3.136.254:14648",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-06-17 19:43:56",
            "last_seen_utc": "2026-06-30 10:44:15",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1833598": [
        {
            "ioc_value": "185.212.128.176:9000",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.evilginx",
            "malware_alias": null,
            "malware_printable": "Evilginx",
            "first_seen_utc": "2026-06-17 19:43:49",
            "last_seen_utc": "2026-06-30 10:44:06",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Evilginx,EvilGoPhish",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1833597": [
        {
            "ioc_value": "182.23.2.163:7024",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-06-17 19:43:46",
            "last_seen_utc": "2026-06-30 10:43:59",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1833596": [
        {
            "ioc_value": "163.245.213.241:56893",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.bianlian",
            "malware_alias": null,
            "malware_printable": "BianLian",
            "first_seen_utc": "2026-06-17 19:43:31",
            "last_seen_utc": "2026-06-30 10:43:43",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "Bianlian,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1833595": [
        {
            "ioc_value": "147.93.191.75:7000",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-06-17 19:43:20",
            "last_seen_utc": "2026-06-30 10:43:30",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1833594": [
        {
            "ioc_value": "118.122.8.154:11534",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.netsupportmanager_rat",
            "malware_alias": "NetSupport",
            "malware_printable": "NetSupportManager RAT",
            "first_seen_utc": "2026-06-17 19:43:12",
            "last_seen_utc": "2026-06-30 10:43:18",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,NetSupport,RAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1833593": [
        {
            "ioc_value": "103.110.80.154:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-06-17 19:43:04",
            "last_seen_utc": "2026-06-30 10:43:08",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1833590": [
        {
            "ioc_value": "1.92.101.103:8006",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-06-17 19:00:16",
            "last_seen_utc": "2026-06-30 10:46:29",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "cobaltstrike",
            "anonymous": "1",
            "reporter": "_ik_"
        }
    ],
    "1833497": [
        {
            "ioc_value": "102.220.160.222:5333",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-06-17 17:00:12",
            "last_seen_utc": "2026-06-30 10:43:04",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "asyncrat",
            "anonymous": "1",
            "reporter": "_ik_"
        }
    ],
    "1833420": [
        {
            "ioc_value": "code-verification-js.beer",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-06-17 15:59:26",
            "last_seen_utc": "2026-06-29 16:01:59",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "ClickFix,Polygon",
            "anonymous": "0",
            "reporter": "varysz"
        }
    ],
    "1833421": [
        {
            "ioc_value": "verification-code-js.beer",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-06-17 15:59:26",
            "last_seen_utc": "2026-06-29 12:29:09",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "ClickFix,Polygon",
            "anonymous": "0",
            "reporter": "varysz"
        }
    ],
    "1833422": [
        {
            "ioc_value": "chinarice.asia",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-06-17 15:59:24",
            "last_seen_utc": "2026-06-29 13:26:27",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "ClickFix,Polygon",
            "anonymous": "0",
            "reporter": "varysz"
        }
    ],
    "1833483": [
        {
            "ioc_value": "43.138.165.203:9003",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-06-17 15:46:35",
            "last_seen_utc": "2026-06-30 10:47:01",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1833482": [
        {
            "ioc_value": "42.193.15.237:9003",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-06-17 15:46:34",
            "last_seen_utc": "2026-06-30 10:47:00",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1833481": [
        {
            "ioc_value": "156.234.211.242:7661",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-06-17 15:46:23",
            "last_seen_utc": "2026-06-30 10:46:49",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1833471": [
        {
            "ioc_value": "102.220.160.222:7001",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-06-17 15:00:14",
            "last_seen_utc": "2026-06-30 10:43:04",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "asyncrat",
            "anonymous": "1",
            "reporter": "_ik_"
        }
    ],
    "1833454": [
        {
            "ioc_value": "147.93.191.75:6006",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-06-17 13:00:12",
            "last_seen_utc": "2026-06-30 10:43:30",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "asyncrat",
            "anonymous": "1",
            "reporter": "_ik_"
        }
    ],
    "1833436": [
        {
            "ioc_value": "91.219.96.131:58908",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-06-17 11:47:00",
            "last_seen_utc": "2026-06-30 10:47:20",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1833435": [
        {
            "ioc_value": "185.92.190.217:8896",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-06-17 11:46:36",
            "last_seen_utc": "2026-06-30 10:46:54",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1833434": [
        {
            "ioc_value": "1.13.141.229:8480",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-06-17 11:46:12",
            "last_seen_utc": "2026-06-30 10:46:29",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1833405": [
        {
            "ioc_value": "98.191.176.222:8080",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.deimos_c2",
            "malware_alias": null,
            "malware_printable": "DeimosC2",
            "first_seen_utc": "2026-06-17 09:48:23",
            "last_seen_utc": "2026-06-30 10:46:20",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "Deimos,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1833404": [
        {
            "ioc_value": "85.137.58.53:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-06-17 09:48:10",
            "last_seen_utc": "2026-06-30 10:46:11",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1833403": [
        {
            "ioc_value": "31.77.189.2:6064",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-06-17 09:46:53",
            "last_seen_utc": "2026-06-30 10:45:26",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1833402": [
        {
            "ioc_value": "31.77.168.195:3009",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-06-17 09:46:52",
            "last_seen_utc": "2026-06-30 10:45:26",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1833401": [
        {
            "ioc_value": "31.76.87.242:3305",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-06-17 09:46:51",
            "last_seen_utc": "2026-06-30 10:45:26",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1833400": [
        {
            "ioc_value": "2.26.74.90:7312",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-06-17 09:45:18",
            "last_seen_utc": "2026-06-30 10:44:24",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1833399": [
        {
            "ioc_value": "186.169.48.87:8092",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.dcrat",
            "malware_alias": "DarkCrystal RAT",
            "malware_printable": "DCRat",
            "first_seen_utc": "2026-06-17 09:44:51",
            "last_seen_utc": "2026-06-30 10:44:10",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DCRat,drb-ra,RAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1833398": [
        {
            "ioc_value": "182.23.2.163:11667",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-06-17 09:44:33",
            "last_seen_utc": "2026-06-30 10:43:56",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1833397": [
        {
            "ioc_value": "178.128.116.134:3443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-06-17 09:44:26",
            "last_seen_utc": "2026-06-30 10:43:53",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1833396": [
        {
            "ioc_value": "177.22.117.148:9001",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.danabot",
            "malware_alias": "DanaTools",
            "malware_printable": "DanaBot",
            "first_seen_utc": "2026-06-17 09:44:25",
            "last_seen_utc": "2026-06-30 10:43:52",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DanBot,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1833395": [
        {
            "ioc_value": "172.245.195.233:14649",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-06-17 09:44:16",
            "last_seen_utc": "2026-06-30 10:43:49",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1833394": [
        {
            "ioc_value": "147.93.191.75:2414",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-06-17 09:43:39",
            "last_seen_utc": "2026-06-30 10:43:29",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1833393": [
        {
            "ioc_value": "138.199.59.5:53522",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-06-17 09:43:33",
            "last_seen_utc": "2026-06-30 10:43:23",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1833392": [
        {
            "ioc_value": "103.53.80.201:1235",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-06-17 09:43:10",
            "last_seen_utc": "2026-06-30 10:43:10",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1833372": [
        {
            "ioc_value": "223.166.31.185:2082",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-06-17 08:24:49",
            "last_seen_utc": "2026-06-30 10:46:58",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-987654321",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1833011": [
        {
            "ioc_value": "8.138.23.63:8999",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-06-16 23:46:15",
            "last_seen_utc": "2026-06-30 10:47:16",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1833010": [
        {
            "ioc_value": "43.138.225.166:6615",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-06-16 23:46:04",
            "last_seen_utc": "2026-06-30 10:47:02",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1833008": [
        {
            "ioc_value": "212.14.244.222:807",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-06-16 23:46:00",
            "last_seen_utc": "2026-06-30 10:46:57",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1833009": [
        {
            "ioc_value": "212.14.244.222:809",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-06-16 23:46:00",
            "last_seen_utc": "2026-06-30 10:46:57",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1833007": [
        {
            "ioc_value": "122.51.50.44:2222",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-06-16 23:45:48",
            "last_seen_utc": "2026-06-30 10:46:42",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1832786": [
        {
            "ioc_value": "96.44.167.215:14643",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-06-16 19:45:41",
            "last_seen_utc": "2026-06-30 10:46:19",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1832784": [
        {
            "ioc_value": "85.215.105.23:1231",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-06-16 19:45:35",
            "last_seen_utc": "2026-06-30 10:46:12",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1832785": [
        {
            "ioc_value": "87.182.39.55:51124",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-06-16 19:45:35",
            "last_seen_utc": "2026-06-30 10:46:12",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1832783": [
        {
            "ioc_value": "74.208.13.152:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-06-16 19:45:29",
            "last_seen_utc": "2026-06-30 10:46:05",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1832780": [
        {
            "ioc_value": "45.198.224.210:4321",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-06-16 19:45:06",
            "last_seen_utc": "2026-06-30 10:45:37",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1832781": [
        {
            "ioc_value": "45.198.224.211:4321",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-06-16 19:45:06",
            "last_seen_utc": "2026-06-30 10:45:37",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1832782": [
        {
            "ioc_value": "45.198.224.212:4321",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-06-16 19:45:06",
            "last_seen_utc": "2026-06-30 10:45:37",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1832779": [
        {
            "ioc_value": "31.77.168.195:3011",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-06-16 19:44:53",
            "last_seen_utc": "2026-06-30 10:45:26",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1832778": [
        {
            "ioc_value": "31.76.32.159:9521",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-06-16 19:44:52",
            "last_seen_utc": "2026-06-30 10:45:25",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1832776": [
        {
            "ioc_value": "2.26.75.102:2428",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-06-16 19:44:06",
            "last_seen_utc": "2026-06-30 10:44:25",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1832777": [
        {
            "ioc_value": "2.26.75.121:8912",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-06-16 19:44:06",
            "last_seen_utc": "2026-06-30 10:44:25",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1832774": [
        {
            "ioc_value": "2.26.228.27:4321",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-06-16 19:44:05",
            "last_seen_utc": "2026-06-30 10:44:24",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1832775": [
        {
            "ioc_value": "2.26.74.90:8455",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-06-16 19:44:05",
            "last_seen_utc": "2026-06-30 10:44:24",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1832773": [
        {
            "ioc_value": "194.116.236.239:4098",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-06-16 19:44:02",
            "last_seen_utc": "2026-06-30 10:44:19",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1832771": [
        {
            "ioc_value": "192.3.136.254:14646",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-06-16 19:43:58",
            "last_seen_utc": "2026-06-30 10:44:15",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1832772": [
        {
            "ioc_value": "192.3.136.254:14649",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-06-16 19:43:58",
            "last_seen_utc": "2026-06-30 10:44:15",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1832770": [
        {
            "ioc_value": "185.141.61.187:7707",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-06-16 19:43:49",
            "last_seen_utc": "2026-06-30 10:44:03",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1832769": [
        {
            "ioc_value": "182.23.2.163:2598",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-06-16 19:43:46",
            "last_seen_utc": "2026-06-30 10:43:57",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1832765": [
        {
            "ioc_value": "156.247.54.11:8848",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.dcrat",
            "malware_alias": "DarkCrystal RAT",
            "malware_printable": "DCRat",
            "first_seen_utc": "2026-06-16 19:43:26",
            "last_seen_utc": "2026-06-30 10:43:37",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DCRat,drb-ra,RAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1832766": [
        {
            "ioc_value": "156.247.54.12:8848",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.dcrat",
            "malware_alias": "DarkCrystal RAT",
            "malware_printable": "DCRat",
            "first_seen_utc": "2026-06-16 19:43:26",
            "last_seen_utc": "2026-06-30 10:43:37",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DCRat,drb-ra,RAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1832767": [
        {
            "ioc_value": "156.247.54.13:8848",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.dcrat",
            "malware_alias": "DarkCrystal RAT",
            "malware_printable": "DCRat",
            "first_seen_utc": "2026-06-16 19:43:26",
            "last_seen_utc": "2026-06-30 10:43:37",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DCRat,drb-ra,RAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1832768": [
        {
            "ioc_value": "156.247.54.14:8848",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.dcrat",
            "malware_alias": "DarkCrystal RAT",
            "malware_printable": "DCRat",
            "first_seen_utc": "2026-06-16 19:43:26",
            "last_seen_utc": "2026-06-30 10:43:37",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DCRat,drb-ra,RAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1832764": [
        {
            "ioc_value": "147.93.191.75:85",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-06-16 19:43:20",
            "last_seen_utc": "2026-06-30 10:43:30",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1832763": [
        {
            "ioc_value": "142.111.135.162:16080",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.bianlian",
            "malware_alias": null,
            "malware_printable": "BianLian",
            "first_seen_utc": "2026-06-16 19:43:17",
            "last_seen_utc": "2026-06-30 10:43:25",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "Bianlian,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1832762": [
        {
            "ioc_value": "119.59.118.75:4321",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-06-16 19:43:12",
            "last_seen_utc": "2026-06-30 10:43:19",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1832761": [
        {
            "ioc_value": "102.220.160.222:7707",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-06-16 19:43:02",
            "last_seen_utc": "2026-06-30 10:43:04",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1832647": [
        {
            "ioc_value": "39.106.205.6:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-06-16 11:00:15",
            "last_seen_utc": "2026-06-30 10:47:00",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "cobaltstrike",
            "anonymous": "1",
            "reporter": "_ik_"
        }
    ],
    "1832634": [
        {
            "ioc_value": "96.44.167.215:14642",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-06-16 09:45:51",
            "last_seen_utc": "2026-06-30 10:46:18",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1832633": [
        {
            "ioc_value": "91.132.161.21:4321",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-06-16 09:45:48",
            "last_seen_utc": "2026-06-30 10:46:15",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1832632": [
        {
            "ioc_value": "5.89.155.59:9002",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.brute_ratel_c4",
            "malware_alias": "BOLDBADGER,BruteRatel",
            "malware_printable": "Brute Ratel C4",
            "first_seen_utc": "2026-06-16 09:45:30",
            "last_seen_utc": "2026-06-30 10:45:53",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "BruteRatel,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1832630": [
        {
            "ioc_value": "45.198.224.214:4321",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-06-16 09:45:16",
            "last_seen_utc": "2026-06-30 10:45:38",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1832631": [
        {
            "ioc_value": "45.198.224.215:4321",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-06-16 09:45:16",
            "last_seen_utc": "2026-06-30 10:45:38",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1832629": [
        {
            "ioc_value": "2.26.229.254:4321",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-06-16 09:44:09",
            "last_seen_utc": "2026-06-30 10:44:24",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1832628": [
        {
            "ioc_value": "194.116.236.239:4099",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-06-16 09:44:05",
            "last_seen_utc": "2026-06-30 10:44:19",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1832627": [
        {
            "ioc_value": "182.23.2.163:8415",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-06-16 09:43:52",
            "last_seen_utc": "2026-06-30 10:44:00",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1832626": [
        {
            "ioc_value": "182.23.2.163:21845",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-06-16 09:43:49",
            "last_seen_utc": "2026-06-30 10:43:57",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1832625": [
        {
            "ioc_value": "177.104.165.104:8443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.havoc",
            "malware_alias": "Havokiz",
            "malware_printable": "Havoc",
            "first_seen_utc": "2026-06-16 09:43:44",
            "last_seen_utc": "2026-06-30 10:43:52",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Havoc",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1832623": [
        {
            "ioc_value": "172.232.105.92:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-06-16 09:43:39",
            "last_seen_utc": "2026-06-30 10:43:47",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1832624": [
        {
            "ioc_value": "172.234.16.151:4321",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-06-16 09:43:39",
            "last_seen_utc": "2026-06-30 10:43:47",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1832622": [
        {
            "ioc_value": "156.247.54.11:12159",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.dcrat",
            "malware_alias": "DarkCrystal RAT",
            "malware_printable": "DCRat",
            "first_seen_utc": "2026-06-16 09:43:27",
            "last_seen_utc": "2026-06-30 10:43:37",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DCRat,drb-ra,RAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1832621": [
        {
            "ioc_value": "15.237.111.251:8443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.evilginx",
            "malware_alias": null,
            "malware_printable": "Evilginx",
            "first_seen_utc": "2026-06-16 09:43:23",
            "last_seen_utc": "2026-06-30 10:43:31",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Evilginx,EvilGoPhish",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1832619": [
        {
            "ioc_value": "147.93.191.75:3000",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-06-16 09:43:22",
            "last_seen_utc": "2026-06-30 10:43:29",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1832620": [
        {
            "ioc_value": "147.93.191.75:3001",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-06-16 09:43:22",
            "last_seen_utc": "2026-06-30 10:43:29",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1832617": [
        {
            "ioc_value": "147.93.191.75:1008",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-06-16 09:43:21",
            "last_seen_utc": "2026-06-30 10:43:29",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1832618": [
        {
            "ioc_value": "147.93.191.75:2222",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-06-16 09:43:21",
            "last_seen_utc": "2026-06-30 10:43:29",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1832615": [
        {
            "ioc_value": "136.111.38.101:7707",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-06-16 09:43:15",
            "last_seen_utc": "2026-06-30 10:43:22",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1832616": [
        {
            "ioc_value": "136.111.38.101:8808",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-06-16 09:43:15",
            "last_seen_utc": "2026-06-30 10:43:22",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1832614": [
        {
            "ioc_value": "13.140.187.194:40056",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.sliver",
            "malware_alias": null,
            "malware_printable": "Sliver",
            "first_seen_utc": "2026-06-16 09:43:14",
            "last_seen_utc": "2026-06-30 10:43:20",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Sliver",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1832613": [
        {
            "ioc_value": "13.140.187.194:31337",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.sliver",
            "malware_alias": null,
            "malware_printable": "Sliver",
            "first_seen_utc": "2026-06-16 09:43:13",
            "last_seen_utc": "2026-06-30 10:43:20",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Sliver",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1832612": [
        {
            "ioc_value": "118.107.5.209:4321",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-06-16 09:43:12",
            "last_seen_utc": "2026-06-30 10:43:18",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1832611": [
        {
            "ioc_value": "102.220.160.222:2026",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-06-16 09:43:02",
            "last_seen_utc": "2026-06-30 10:43:04",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1832603": [
        {
            "ioc_value": "154.29.72.62:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-06-16 09:00:13",
            "last_seen_utc": "2026-06-30 10:43:33",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "asyncrat",
            "anonymous": "1",
            "reporter": "_ik_"
        }
    ],
    "1832600": [
        {
            "ioc_value": "151.239.24.160:9090",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-06-16 08:39:04",
            "last_seen_utc": "2026-06-30 10:46:47",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-987654321",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1832567": [
        {
            "ioc_value": "66.94.119.99:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.amadey",
            "malware_alias": null,
            "malware_printable": "Amadey",
            "first_seen_utc": "2026-06-16 06:36:02",
            "last_seen_utc": "2026-06-30 11:24:03",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": "https://tracker.viriback.com/index.php?q=66.94.119.99",
            "tags": "Amadey,ViriBack",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1832558": [
        {
            "ioc_value": "177.3.40.2:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-06-16 05:46:04",
            "last_seen_utc": "2026-06-30 10:46:52",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1832557": [
        {
            "ioc_value": "mlcs.mlface.net",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-06-16 05:45:39",
            "last_seen_utc": "2026-06-30 10:46:24",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1832539": [
        {
            "ioc_value": "45.151.101.97:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-06-16 03:46:04",
            "last_seen_utc": "2026-06-30 10:47:05",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1832522": [
        {
            "ioc_value": "129.204.14.131:57000",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-06-15 23:45:48",
            "last_seen_utc": "2026-06-30 10:46:44",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1832487": [
        {
            "ioc_value": "96.44.167.215:14647",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-06-15 19:45:35",
            "last_seen_utc": "2026-06-30 10:46:19",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1832486": [
        {
            "ioc_value": "72.52.132.8:8081",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.chaos",
            "malware_alias": "FakeRyuk,RyukJoke,Yashma",
            "malware_printable": "Chaos",
            "first_seen_utc": "2026-06-15 19:45:22",
            "last_seen_utc": "2026-06-30 10:46:04",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CHAOS,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1832485": [
        {
            "ioc_value": "212.193.5.199:9000",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.evilginx",
            "malware_alias": null,
            "malware_printable": "Evilginx",
            "first_seen_utc": "2026-06-15 19:44:11",
            "last_seen_utc": "2026-06-30 10:44:35",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Evilginx,EvilGoPhish",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1832484": [
        {
            "ioc_value": "2.27.5.220:2428",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-06-15 19:44:03",
            "last_seen_utc": "2026-06-30 10:44:26",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1832483": [
        {
            "ioc_value": "185.190.142.121:8443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.havoc",
            "malware_alias": "Havokiz",
            "malware_printable": "Havoc",
            "first_seen_utc": "2026-06-15 19:43:48",
            "last_seen_utc": "2026-06-30 10:44:05",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Havoc",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1832482": [
        {
            "ioc_value": "182.23.2.163:7563",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-06-15 19:43:46",
            "last_seen_utc": "2026-06-30 10:43:59",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1832480": [
        {
            "ioc_value": "182.23.2.163:54257",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-06-15 19:43:45",
            "last_seen_utc": "2026-06-30 10:43:58",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1832481": [
        {
            "ioc_value": "182.23.2.163:625",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-06-15 19:43:45",
            "last_seen_utc": "2026-06-30 10:43:59",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1832479": [
        {
            "ioc_value": "172.245.195.233:14646",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-06-15 19:43:35",
            "last_seen_utc": "2026-06-30 10:43:48",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1832478": [
        {
            "ioc_value": "166.88.159.146:5353",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.bianlian",
            "malware_alias": null,
            "malware_printable": "BianLian",
            "first_seen_utc": "2026-06-15 19:43:31",
            "last_seen_utc": "2026-06-30 10:43:44",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "Bianlian,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1832473": [
        {
            "ioc_value": "156.247.54.10:12159",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.dcrat",
            "malware_alias": "DarkCrystal RAT",
            "malware_printable": "DCRat",
            "first_seen_utc": "2026-06-15 19:43:24",
            "last_seen_utc": "2026-06-30 10:43:36",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DCRat,drb-ra,RAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1832474": [
        {
            "ioc_value": "156.247.54.10:8848",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.dcrat",
            "malware_alias": "DarkCrystal RAT",
            "malware_printable": "DCRat",
            "first_seen_utc": "2026-06-15 19:43:24",
            "last_seen_utc": "2026-06-30 10:43:36",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DCRat,drb-ra,RAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1832475": [
        {
            "ioc_value": "156.247.54.12:12159",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.dcrat",
            "malware_alias": "DarkCrystal RAT",
            "malware_printable": "DCRat",
            "first_seen_utc": "2026-06-15 19:43:24",
            "last_seen_utc": "2026-06-30 10:43:37",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DCRat,drb-ra,RAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1832476": [
        {
            "ioc_value": "156.247.54.13:12159",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.dcrat",
            "malware_alias": "DarkCrystal RAT",
            "malware_printable": "DCRat",
            "first_seen_utc": "2026-06-15 19:43:24",
            "last_seen_utc": "2026-06-30 10:43:37",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DCRat,drb-ra,RAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1832477": [
        {
            "ioc_value": "156.247.54.14:12159",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.dcrat",
            "malware_alias": "DarkCrystal RAT",
            "malware_printable": "DCRat",
            "first_seen_utc": "2026-06-15 19:43:24",
            "last_seen_utc": "2026-06-30 10:43:37",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DCRat,drb-ra,RAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1832472": [
        {
            "ioc_value": "154.44.20.174:4321",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-06-15 19:43:21",
            "last_seen_utc": "2026-06-30 10:43:33",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1832471": [
        {
            "ioc_value": "144.31.236.223:9405",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-06-15 19:43:17",
            "last_seen_utc": "2026-06-30 10:43:26",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1832469": [
        {
            "ioc_value": "102.220.160.222:8808",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-06-15 19:43:02",
            "last_seen_utc": "2026-06-30 10:43:04",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1832470": [
        {
            "ioc_value": "102.46.221.148:7707",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-06-15 19:43:02",
            "last_seen_utc": "2026-06-30 10:43:05",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1832399": [
        {
            "ioc_value": "23.95.170.223:18443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-06-15 15:46:19",
            "last_seen_utc": "2026-06-30 10:46:58",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1832398": [
        {
            "ioc_value": "cs.tpedu2metricstw.dpdns.org",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-06-15 15:45:49",
            "last_seen_utc": "2026-06-30 10:46:22",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1832397": [
        {
            "ioc_value": "ardaplumeit.top",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-06-15 15:45:48",
            "last_seen_utc": "2026-06-30 10:46:21",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1832389": [
        {
            "ioc_value": "47.236.102.8:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-06-15 15:00:11",
            "last_seen_utc": "2026-06-30 10:47:10",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "cobaltstrike",
            "anonymous": "1",
            "reporter": "_ik_"
        }
    ],
    "1832378": [
        {
            "ioc_value": "79.175.189.207:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-06-15 14:00:16",
            "last_seen_utc": "2026-06-30 10:47:15",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "cobaltstrike",
            "anonymous": "1",
            "reporter": "_ik_"
        }
    ],
    "1832323": [
        {
            "ioc_value": "89.42.134.220:1803",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-06-15 09:45:54",
            "last_seen_utc": "2026-06-30 10:46:14",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1832322": [
        {
            "ioc_value": "87.182.39.55:51123",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-06-15 09:45:52",
            "last_seen_utc": "2026-06-30 10:46:12",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1832321": [
        {
            "ioc_value": "83.229.85.74:6606",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-06-15 09:45:50",
            "last_seen_utc": "2026-06-30 10:46:10",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1832320": [
        {
            "ioc_value": "8.210.84.56:8000",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-06-15 09:45:46",
            "last_seen_utc": "2026-06-30 10:46:06",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1832319": [
        {
            "ioc_value": "31.76.87.112:7716",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-06-15 09:45:09",
            "last_seen_utc": "2026-06-30 10:45:25",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1832318": [
        {
            "ioc_value": "31.6.11.162:7070",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-06-15 09:45:08",
            "last_seen_utc": "2026-06-30 10:45:24",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1832317": [
        {
            "ioc_value": "213.193.20.192:9281",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-06-15 09:44:22",
            "last_seen_utc": "2026-06-30 10:44:36",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1832316": [
        {
            "ioc_value": "209.99.187.37:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-06-15 09:44:19",
            "last_seen_utc": "2026-06-30 10:44:33",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1832315": [
        {
            "ioc_value": "20.224.219.169:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.havoc",
            "malware_alias": "Havokiz",
            "malware_printable": "Havoc",
            "first_seen_utc": "2026-06-15 09:44:14",
            "last_seen_utc": "2026-06-30 10:44:27",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Havoc",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1832314": [
        {
            "ioc_value": "198.23.185.231:70",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-06-15 09:44:10",
            "last_seen_utc": "2026-06-30 10:44:23",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1832313": [
        {
            "ioc_value": "131.143.251.246:53921",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-06-15 09:43:17",
            "last_seen_utc": "2026-06-30 10:43:21",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1832312": [
        {
            "ioc_value": "107.172.133.182:56002",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-06-15 09:43:09",
            "last_seen_utc": "2026-06-30 10:43:12",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1832302": [
        {
            "ioc_value": "http://cacywears.ga/index.php",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.smokeloader",
            "malware_alias": "Dofoil,Sharik,Smoke,Smoke Loader",
            "malware_printable": "SmokeLoader",
            "first_seen_utc": "2026-06-15 08:44:17",
            "last_seen_utc": "2026-06-30 09:35:27",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "c2,SmokeLoader",
            "anonymous": "0",
            "reporter": "Bitsight"
        }
    ],
    "1832283": [
        {
            "ioc_value": "45.202.1.194:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-06-15 06:51:54",
            "last_seen_utc": "2026-06-30 10:47:06",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-987654321",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1832205": [
        {
            "ioc_value": "8.152.2.86:8889",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-06-14 23:46:04",
            "last_seen_utc": "2026-06-30 10:47:16",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1832204": [
        {
            "ioc_value": "124.222.218.12:18443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-06-14 23:45:41",
            "last_seen_utc": "2026-06-30 10:46:43",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1832163": [
        {
            "ioc_value": "89.42.134.220:8808",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-06-14 19:45:30",
            "last_seen_utc": "2026-06-30 10:46:15",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1832162": [
        {
            "ioc_value": "83.229.85.74:8808",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-06-14 19:45:27",
            "last_seen_utc": "2026-06-30 10:46:10",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1832161": [
        {
            "ioc_value": "82.47.101.191:8848",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.dcrat",
            "malware_alias": "DarkCrystal RAT",
            "malware_printable": "DCRat",
            "first_seen_utc": "2026-06-14 19:45:26",
            "last_seen_utc": "2026-06-30 10:46:09",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DCRat,drb-ra,RAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1832160": [
        {
            "ioc_value": "5.230.69.118:8930",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-06-14 19:45:13",
            "last_seen_utc": "2026-06-30 10:45:53",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1832159": [
        {
            "ioc_value": "46.246.82.18:8848",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.dcrat",
            "malware_alias": "DarkCrystal RAT",
            "malware_printable": "DCRat",
            "first_seen_utc": "2026-06-14 19:45:04",
            "last_seen_utc": "2026-06-30 10:45:45",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DCRat,drb-ra,RAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1832158": [
        {
            "ioc_value": "43.133.164.200:4321",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-06-14 19:44:54",
            "last_seen_utc": "2026-06-30 10:45:32",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1832157": [
        {
            "ioc_value": "213.152.161.157:18856",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-06-14 19:44:12",
            "last_seen_utc": "2026-06-30 10:44:36",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1832156": [
        {
            "ioc_value": "209.99.185.96:1002",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-06-14 19:44:10",
            "last_seen_utc": "2026-06-30 10:44:33",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1832155": [
        {
            "ioc_value": "207.211.163.106:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-06-14 19:44:09",
            "last_seen_utc": "2026-06-30 10:44:31",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1832154": [
        {
            "ioc_value": "204.194.54.9:2682",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-06-14 19:44:06",
            "last_seen_utc": "2026-06-30 10:44:29",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1832153": [
        {
            "ioc_value": "182.23.2.163:26972",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-06-14 19:43:44",
            "last_seen_utc": "2026-06-30 10:43:57",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1832152": [
        {
            "ioc_value": "172.245.195.233:14642",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-06-14 19:43:36",
            "last_seen_utc": "2026-06-30 10:43:48",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1832151": [
        {
            "ioc_value": "163.245.196.102:5400",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.bianlian",
            "malware_alias": null,
            "malware_printable": "BianLian",
            "first_seen_utc": "2026-06-14 19:43:31",
            "last_seen_utc": "2026-06-30 10:43:43",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "Bianlian,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1832150": [
        {
            "ioc_value": "161.97.166.38:6006",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-06-14 19:43:29",
            "last_seen_utc": "2026-06-30 10:43:41",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1832149": [
        {
            "ioc_value": "144.31.236.224:4509",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-06-14 19:43:19",
            "last_seen_utc": "2026-06-30 10:43:26",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1832074": [
        {
            "ioc_value": "23.254.129.251:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-06-14 11:45:50",
            "last_seen_utc": "2026-06-30 10:46:58",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1832073": [
        {
            "ioc_value": "207.56.229.234:4545",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-06-14 11:45:48",
            "last_seen_utc": "2026-06-30 10:46:56",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1832072": [
        {
            "ioc_value": "sys.systemworld.info",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-06-14 11:45:27",
            "last_seen_utc": "2026-06-30 10:46:27",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1832021": [
        {
            "ioc_value": "35.243.42.203:8808",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-06-14 11:00:16",
            "last_seen_utc": "2026-06-30 10:45:27",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "asyncrat",
            "anonymous": "1",
            "reporter": "_ik_"
        }
    ],
    "1832010": [
        {
            "ioc_value": "103.47.83.115:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-06-14 10:35:04",
            "last_seen_utc": "2026-06-30 10:46:32",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-987654321",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1831999": [
        {
            "ioc_value": "165.154.254.203:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-06-14 10:00:22",
            "last_seen_utc": "2026-06-30 10:46:51",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "cobaltstrike",
            "anonymous": "1",
            "reporter": "_ik_"
        }
    ],
    "1831996": [
        {
            "ioc_value": "66.29.131.145:5000",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.evilginx",
            "malware_alias": null,
            "malware_printable": "Evilginx",
            "first_seen_utc": "2026-06-14 09:45:10",
            "last_seen_utc": "2026-06-30 10:46:01",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Evilginx,EvilGoPhish",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1831995": [
        {
            "ioc_value": "64.225.102.218:31400",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.evilginx",
            "malware_alias": null,
            "malware_printable": "Evilginx",
            "first_seen_utc": "2026-06-14 09:45:07",
            "last_seen_utc": "2026-06-30 10:45:58",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Evilginx,EvilGoPhish",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1831994": [
        {
            "ioc_value": "45.61.150.88:5000",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.evilginx",
            "malware_alias": null,
            "malware_printable": "Evilginx",
            "first_seen_utc": "2026-06-14 09:44:50",
            "last_seen_utc": "2026-06-30 10:45:40",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Evilginx,EvilGoPhish",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1831993": [
        {
            "ioc_value": "45.198.224.213:4321",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-06-14 09:44:49",
            "last_seen_utc": "2026-06-30 10:45:38",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1831992": [
        {
            "ioc_value": "23.235.185.42:12159",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.dcrat",
            "malware_alias": "DarkCrystal RAT",
            "malware_printable": "DCRat",
            "first_seen_utc": "2026-06-14 09:44:35",
            "last_seen_utc": "2026-06-30 10:45:19",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DCRat,drb-ra,RAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1831989": [
        {
            "ioc_value": "209.99.185.96:2222",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-06-14 09:44:04",
            "last_seen_utc": "2026-06-30 10:44:33",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1831990": [
        {
            "ioc_value": "209.99.189.198:7004",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-06-14 09:44:04",
            "last_seen_utc": "2026-06-30 10:44:34",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1831991": [
        {
            "ioc_value": "209.99.189.198:7007",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-06-14 09:44:04",
            "last_seen_utc": "2026-06-30 10:44:34",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1831987": [
        {
            "ioc_value": "185.207.154.11:4848",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-06-14 09:43:43",
            "last_seen_utc": "2026-06-30 10:44:05",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1831986": [
        {
            "ioc_value": "182.23.2.163:11954",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-06-14 09:43:38",
            "last_seen_utc": "2026-06-30 10:43:56",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1831985": [
        {
            "ioc_value": "172.245.195.233:14645",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-06-14 09:43:32",
            "last_seen_utc": "2026-06-30 10:43:48",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1831984": [
        {
            "ioc_value": "103.241.64.92:4782",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-06-14 09:43:05",
            "last_seen_utc": "2026-06-30 10:43:10",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1831983": [
        {
            "ioc_value": "1.14.234.107:8989",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-06-14 09:43:02",
            "last_seen_utc": "2026-06-30 10:43:02",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1831979": [
        {
            "ioc_value": "49.232.4.71:81",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-06-14 09:00:14",
            "last_seen_utc": "2026-06-30 10:47:12",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "cobaltstrike",
            "anonymous": "1",
            "reporter": "_ik_"
        }
    ],
    "1831980": [
        {
            "ioc_value": "216.250.249.36:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-06-14 09:00:14",
            "last_seen_utc": "2026-06-30 10:45:17",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "asyncrat",
            "anonymous": "1",
            "reporter": "_ik_"
        }
    ],
    "1831974": [
        {
            "ioc_value": "49.232.4.71:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-06-14 08:00:20",
            "last_seen_utc": "2026-06-30 10:47:12",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "cobaltstrike",
            "anonymous": "1",
            "reporter": "_ik_"
        }
    ],
    "1831853": [
        {
            "ioc_value": "120.27.245.127:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-06-13 20:00:21",
            "last_seen_utc": "2026-06-30 10:46:41",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "cobaltstrike",
            "anonymous": "1",
            "reporter": "_ik_"
        }
    ],
    "1831845": [
        {
            "ioc_value": "96.44.167.215:14644",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-06-13 19:45:41",
            "last_seen_utc": "2026-06-30 10:46:19",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1831846": [
        {
            "ioc_value": "96.44.167.215:14646",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-06-13 19:45:41",
            "last_seen_utc": "2026-06-30 10:46:19",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1831847": [
        {
            "ioc_value": "96.44.167.215:14648",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-06-13 19:45:41",
            "last_seen_utc": "2026-06-30 10:46:19",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1831844": [
        {
            "ioc_value": "94.103.1.223:3421",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-06-13 19:45:40",
            "last_seen_utc": "2026-06-30 10:46:17",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1831843": [
        {
            "ioc_value": "9.141.105.20:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-06-13 19:45:37",
            "last_seen_utc": "2026-06-30 10:46:15",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1831842": [
        {
            "ioc_value": "85.121.176.239:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-06-13 19:45:34",
            "last_seen_utc": "2026-06-30 10:46:11",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1831840": [
        {
            "ioc_value": "72.51.57.131:5202",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.dcrat",
            "malware_alias": "DarkCrystal RAT",
            "malware_printable": "DCRat",
            "first_seen_utc": "2026-06-13 19:45:28",
            "last_seen_utc": "2026-06-30 10:46:04",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DCRat,drb-ra,RAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1831841": [
        {
            "ioc_value": "72.51.57.131:7997",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.dcrat",
            "malware_alias": "DarkCrystal RAT",
            "malware_printable": "DCRat",
            "first_seen_utc": "2026-06-13 19:45:28",
            "last_seen_utc": "2026-06-30 10:46:04",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DCRat,drb-ra,RAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1831839": [
        {
            "ioc_value": "46.246.4.9:8848",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.dcrat",
            "malware_alias": "DarkCrystal RAT",
            "malware_printable": "DCRat",
            "first_seen_utc": "2026-06-13 19:45:11",
            "last_seen_utc": "2026-06-30 10:45:45",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DCRat,drb-ra,RAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1831838": [
        {
            "ioc_value": "45.153.127.224:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.chaos",
            "malware_alias": "FakeRyuk,RyukJoke,Yashma",
            "malware_printable": "Chaos",
            "first_seen_utc": "2026-06-13 19:45:04",
            "last_seen_utc": "2026-06-30 10:45:36",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CHAOS,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1831836": [
        {
            "ioc_value": "31.76.32.181:8455",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-06-13 19:44:52",
            "last_seen_utc": "2026-06-30 10:45:25",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1831837": [
        {
            "ioc_value": "31.76.87.218:9405",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-06-13 19:44:52",
            "last_seen_utc": "2026-06-30 10:45:26",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1831834": [
        {
            "ioc_value": "209.99.189.198:7005",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-06-13 19:44:13",
            "last_seen_utc": "2026-06-30 10:44:34",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1831835": [
        {
            "ioc_value": "209.99.189.198:7006",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-06-13 19:44:13",
            "last_seen_utc": "2026-06-30 10:44:34",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1831833": [
        {
            "ioc_value": "209.99.185.96:2025",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-06-13 19:44:12",
            "last_seen_utc": "2026-06-30 10:44:33",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1831832": [
        {
            "ioc_value": "2.27.5.179:4509",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-06-13 19:44:06",
            "last_seen_utc": "2026-06-30 10:44:25",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1831831": [
        {
            "ioc_value": "2.26.75.218:6913",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-06-13 19:44:05",
            "last_seen_utc": "2026-06-30 10:44:25",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1831830": [
        {
            "ioc_value": "193.187.91.216:51842",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-06-13 19:43:59",
            "last_seen_utc": "2026-06-30 10:44:17",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1831829": [
        {
            "ioc_value": "191.107.87.183:5469",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-06-13 19:43:56",
            "last_seen_utc": "2026-06-30 10:44:12",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1831828": [
        {
            "ioc_value": "191.107.87.183:5011",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-06-13 19:43:55",
            "last_seen_utc": "2026-06-30 10:44:12",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1831826": [
        {
            "ioc_value": "182.23.2.163:49415",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-06-13 19:43:46",
            "last_seen_utc": "2026-06-30 10:43:58",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1831827": [
        {
            "ioc_value": "182.23.2.163:5814",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-06-13 19:43:46",
            "last_seen_utc": "2026-06-30 10:43:59",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1831825": [
        {
            "ioc_value": "172.245.195.233:14644",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-06-13 19:43:37",
            "last_seen_utc": "2026-06-30 10:43:48",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1831824": [
        {
            "ioc_value": "157.22.185.5:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-06-13 19:43:28",
            "last_seen_utc": "2026-06-30 10:43:38",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1831823": [
        {
            "ioc_value": "155.103.71.115:14409",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-06-13 19:43:25",
            "last_seen_utc": "2026-06-30 10:43:35",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1831822": [
        {
            "ioc_value": "144.91.78.57:207",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.dcrat",
            "malware_alias": "DarkCrystal RAT",
            "malware_printable": "DCRat",
            "first_seen_utc": "2026-06-13 19:43:19",
            "last_seen_utc": "2026-06-30 10:43:26",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DCRat,drb-ra,RAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1831821": [
        {
            "ioc_value": "107.172.133.182:56003",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-06-13 19:43:08",
            "last_seen_utc": "2026-06-30 10:43:13",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1831769": [
        {
            "ioc_value": "framework-css-styles-js.beer",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-06-13 15:05:28",
            "last_seen_utc": "2026-06-29 12:29:09",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "c2,errtraffic,Polygon",
            "anonymous": "0",
            "reporter": "varysz"
        }
    ],
    "1831770": [
        {
            "ioc_value": "ethercdnns.beer",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-06-13 15:05:28",
            "last_seen_utc": "2026-06-29 12:29:09",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "c2,errtraffic,Polygon",
            "anonymous": "0",
            "reporter": "varysz"
        }
    ],
    "1831771": [
        {
            "ioc_value": "misterslivker.asia",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-06-13 15:05:27",
            "last_seen_utc": "2026-06-29 13:26:34",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "c2,errtraffic,Polygon",
            "anonymous": "0",
            "reporter": "varysz"
        }
    ],
    "1831772": [
        {
            "ioc_value": "mylovedomen.asia",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-06-13 15:05:27",
            "last_seen_utc": "2026-06-29 13:26:37",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "c2,errtraffic,Polygon",
            "anonymous": "0",
            "reporter": "varysz"
        }
    ],
    "1831773": [
        {
            "ioc_value": "slivkishow.asia",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-06-13 15:05:25",
            "last_seen_utc": "2026-06-29 13:26:32",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "c2,errtraffic,Polygon",
            "anonymous": "0",
            "reporter": "varysz"
        }
    ],
    "1831774": [
        {
            "ioc_value": "thisismine.asia",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-06-13 15:05:24",
            "last_seen_utc": "2026-06-29 13:26:36",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "c2,errtraffic,Polygon",
            "anonymous": "0",
            "reporter": "varysz"
        }
    ],
    "1831775": [
        {
            "ioc_value": "verification-js-cdn.boats",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-06-13 15:05:23",
            "last_seen_utc": "2026-06-29 12:29:09",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "c2,errtraffic,Polygon",
            "anonymous": "0",
            "reporter": "varysz"
        }
    ],
    "1831779": [
        {
            "ioc_value": "18.232.64.100:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-06-13 15:00:14",
            "last_seen_utc": "2026-06-30 10:46:53",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "cobaltstrike",
            "anonymous": "1",
            "reporter": "_ik_"
        }
    ],
    "1831768": [
        {
            "ioc_value": "18.232.64.100:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-06-13 14:00:19",
            "last_seen_utc": "2026-06-30 10:46:53",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "cobaltstrike",
            "anonymous": "1",
            "reporter": "_ik_"
        }
    ],
    "1831747": [
        {
            "ioc_value": "118.24.128.201:64727",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-06-13 11:46:23",
            "last_seen_utc": "2026-06-30 10:46:39",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1831738": [
        {
            "ioc_value": "43.130.246.23:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-06-13 10:00:20",
            "last_seen_utc": "2026-06-30 10:47:01",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "cobaltstrike",
            "anonymous": "1",
            "reporter": "_ik_"
        }
    ],
    "1831733": [
        {
            "ioc_value": "98.191.176.231:8080",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.deimos_c2",
            "malware_alias": null,
            "malware_printable": "DeimosC2",
            "first_seen_utc": "2026-06-13 09:46:13",
            "last_seen_utc": "2026-06-30 10:46:20",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "Deimos,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1831732": [
        {
            "ioc_value": "89.42.134.220:1991",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-06-13 09:46:08",
            "last_seen_utc": "2026-06-30 10:46:15",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1831731": [
        {
            "ioc_value": "69.164.245.165:8930",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-06-13 09:45:57",
            "last_seen_utc": "2026-06-30 10:46:03",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1831730": [
        {
            "ioc_value": "34.123.214.16:8443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.bianlian",
            "malware_alias": null,
            "malware_printable": "BianLian",
            "first_seen_utc": "2026-06-13 09:45:23",
            "last_seen_utc": "2026-06-30 10:45:27",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "Bianlian,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1831728": [
        {
            "ioc_value": "31.76.32.201:1377",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-06-13 09:45:22",
            "last_seen_utc": "2026-06-30 10:45:25",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1831729": [
        {
            "ioc_value": "31.76.32.230:1499",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-06-13 09:45:22",
            "last_seen_utc": "2026-06-30 10:45:25",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1831727": [
        {
            "ioc_value": "23.235.185.44:12159",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.dcrat",
            "malware_alias": "DarkCrystal RAT",
            "malware_printable": "DCRat",
            "first_seen_utc": "2026-06-13 09:45:15",
            "last_seen_utc": "2026-06-30 10:45:19",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DCRat,drb-ra,RAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1831726": [
        {
            "ioc_value": "188.121.162.153:5000",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-06-13 09:44:10",
            "last_seen_utc": "2026-06-30 10:44:11",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1831725": [
        {
            "ioc_value": "185.212.129.185:9000",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.evilginx",
            "malware_alias": null,
            "malware_printable": "Evilginx",
            "first_seen_utc": "2026-06-13 09:44:06",
            "last_seen_utc": "2026-06-30 10:44:07",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Evilginx,EvilGoPhish",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1831724": [
        {
            "ioc_value": "182.23.2.163:59678",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-06-13 09:43:59",
            "last_seen_utc": "2026-06-30 10:43:59",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1831723": [
        {
            "ioc_value": "172.245.195.233:14641",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-06-13 09:43:46",
            "last_seen_utc": "2026-06-30 10:43:48",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1831722": [
        {
            "ioc_value": "130.185.82.117:5641",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-06-13 09:43:18",
            "last_seen_utc": "2026-06-30 10:43:21",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1831720": [
        {
            "ioc_value": "108.181.115.254:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.ransomhub",
            "malware_alias": null,
            "malware_printable": "RansomHub",
            "first_seen_utc": "2026-06-13 09:43:12",
            "last_seen_utc": "2026-06-30 10:43:15",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RansomHub",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1831721": [
        {
            "ioc_value": "108.181.115.254:7045",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.ransomhub",
            "malware_alias": null,
            "malware_printable": "RansomHub",
            "first_seen_utc": "2026-06-13 09:43:12",
            "last_seen_utc": "2026-06-30 10:43:15",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RansomHub",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1831719": [
        {
            "ioc_value": "107.173.9.88:8000",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-06-13 09:43:11",
            "last_seen_utc": "2026-06-30 10:43:14",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1831718": [
        {
            "ioc_value": "102.46.221.148:6606",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-06-13 09:43:04",
            "last_seen_utc": "2026-06-30 10:43:05",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1831717": [
        {
            "ioc_value": "101.33.202.134:9989",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-06-13 09:43:02",
            "last_seen_utc": "2026-06-30 10:43:03",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1831647": [
        {
            "ioc_value": "153.0.197.184:8555",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-06-12 23:45:46",
            "last_seen_utc": "2026-06-30 10:46:47",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1831619": [
        {
            "ioc_value": "102.46.221.148:8808",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-06-12 20:00:19",
            "last_seen_utc": "2026-06-30 10:43:05",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "asyncrat",
            "anonymous": "1",
            "reporter": "_ik_"
        }
    ],
    "1831617": [
        {
            "ioc_value": "69.172.210.50:8808",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-06-12 19:45:16",
            "last_seen_utc": "2026-06-30 10:46:04",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1831616": [
        {
            "ioc_value": "39.96.188.57:4321",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-06-12 19:44:48",
            "last_seen_utc": "2026-06-30 10:45:31",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1831615": [
        {
            "ioc_value": "31.76.32.161:9405",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-06-12 19:44:44",
            "last_seen_utc": "2026-06-30 10:45:25",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1831614": [
        {
            "ioc_value": "198.23.177.222:14641",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-06-12 19:43:57",
            "last_seen_utc": "2026-06-30 10:44:21",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1831613": [
        {
            "ioc_value": "194.213.18.93:991",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.bianlian",
            "malware_alias": null,
            "malware_printable": "BianLian",
            "first_seen_utc": "2026-06-12 19:43:55",
            "last_seen_utc": "2026-06-30 10:44:19",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "Bianlian,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1831612": [
        {
            "ioc_value": "182.23.2.163:7649",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-06-12 19:43:43",
            "last_seen_utc": "2026-06-30 10:43:59",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1831611": [
        {
            "ioc_value": "172.94.18.103:72",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-06-12 19:43:35",
            "last_seen_utc": "2026-06-30 10:43:50",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1831610": [
        {
            "ioc_value": "172.245.195.233:14648",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-06-12 19:43:34",
            "last_seen_utc": "2026-06-30 10:43:48",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1831609": [
        {
            "ioc_value": "158.220.96.15:3319",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-06-12 19:43:25",
            "last_seen_utc": "2026-06-30 10:43:39",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1831608": [
        {
            "ioc_value": "149.104.28.77:4321",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-06-12 19:43:19",
            "last_seen_utc": "2026-06-30 10:43:30",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1831607": [
        {
            "ioc_value": "107.172.44.141:45699",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-06-12 19:43:08",
            "last_seen_utc": "2026-06-30 10:43:13",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1831606": [
        {
            "ioc_value": "101.99.92.220:8264",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-06-12 19:43:03",
            "last_seen_utc": "2026-06-30 10:43:03",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1830877": [
        {
            "ioc_value": "8.217.12.212:48080",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-06-12 11:46:40",
            "last_seen_utc": "2026-06-30 10:47:17",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1830851": [
        {
            "ioc_value": "78.141.208.70:46337",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-06-12 09:45:24",
            "last_seen_utc": "2026-06-30 10:46:06",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1830850": [
        {
            "ioc_value": "69.172.210.50:5333",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-06-12 09:45:23",
            "last_seen_utc": "2026-06-30 10:46:03",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1830848": [
        {
            "ioc_value": "64.89.162.10:2404",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-06-12 09:45:21",
            "last_seen_utc": "2026-06-30 10:46:00",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1830849": [
        {
            "ioc_value": "64.89.162.178:5903",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-06-12 09:45:21",
            "last_seen_utc": "2026-06-30 10:46:00",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1830847": [
        {
            "ioc_value": "61.158.61.134:8848",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.dcrat",
            "malware_alias": "DarkCrystal RAT",
            "malware_printable": "DCRat",
            "first_seen_utc": "2026-06-12 09:45:18",
            "last_seen_utc": "2026-06-30 10:45:56",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DCRat,drb-ra,RAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1830846": [
        {
            "ioc_value": "45.32.120.188:4321",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-06-12 09:44:57",
            "last_seen_utc": "2026-06-30 10:45:39",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1830845": [
        {
            "ioc_value": "45.137.99.3:8989",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-06-12 09:44:55",
            "last_seen_utc": "2026-06-30 10:45:35",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1830844": [
        {
            "ioc_value": "31.76.32.160:7716",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-06-12 09:44:47",
            "last_seen_utc": "2026-06-30 10:45:25",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1830843": [
        {
            "ioc_value": "31.57.184.154:7008",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-06-12 09:44:45",
            "last_seen_utc": "2026-06-30 10:45:24",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1830842": [
        {
            "ioc_value": "2.26.21.17:4323",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-06-12 09:44:00",
            "last_seen_utc": "2026-06-30 10:44:24",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1830841": [
        {
            "ioc_value": "193.163.203.183:2404",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-06-12 09:43:55",
            "last_seen_utc": "2026-06-30 10:44:16",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1830839": [
        {
            "ioc_value": "182.23.2.163:602",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-06-12 09:43:44",
            "last_seen_utc": "2026-06-30 10:43:59",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1830840": [
        {
            "ioc_value": "182.23.2.163:8206",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-06-12 09:43:44",
            "last_seen_utc": "2026-06-30 10:43:59",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1830837": [
        {
            "ioc_value": "182.23.2.163:49552",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-06-12 09:43:43",
            "last_seen_utc": "2026-06-30 10:43:58",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1830838": [
        {
            "ioc_value": "182.23.2.163:5137",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-06-12 09:43:43",
            "last_seen_utc": "2026-06-30 10:43:58",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1830836": [
        {
            "ioc_value": "182.23.2.163:12615",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-06-12 09:43:42",
            "last_seen_utc": "2026-06-30 10:43:57",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1830835": [
        {
            "ioc_value": "144.31.236.19:3305",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-06-12 09:43:18",
            "last_seen_utc": "2026-06-30 10:43:26",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1830834": [
        {
            "ioc_value": "114.132.238.70:4321",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-06-12 09:43:11",
            "last_seen_utc": "2026-06-30 10:43:17",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1830833": [
        {
            "ioc_value": "110.42.34.220:4321",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-06-12 09:43:10",
            "last_seen_utc": "2026-06-30 10:43:16",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1830832": [
        {
            "ioc_value": "104.234.240.68:7707",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-06-12 09:43:06",
            "last_seen_utc": "2026-06-30 10:43:12",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1830532": [
        {
            "ioc_value": "95.182.114.29:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-06-12 07:20:03",
            "last_seen_utc": "2026-06-30 10:47:20",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-666666666",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1830533": [
        {
            "ioc_value": "60.205.126.246:8443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-06-12 07:20:03",
            "last_seen_utc": "2026-06-30 10:47:13",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-987654321",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1830531": [
        {
            "ioc_value": "1.13.141.229:8443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-06-12 07:19:49",
            "last_seen_utc": "2026-06-30 10:46:29",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-987654321",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1830416": [
        {
            "ioc_value": "49.233.136.227:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-06-11 21:00:15",
            "last_seen_utc": "2026-06-30 10:47:13",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "cobaltstrike",
            "anonymous": "1",
            "reporter": "_ik_"
        }
    ],
    "1830402": [
        {
            "ioc_value": "1364170351-9enmkvd46p.ap-guangzhou.tencentscf.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-06-11 19:45:26",
            "last_seen_utc": "2026-06-30 10:46:20",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1830401": [
        {
            "ioc_value": "64.89.162.59:4422",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-06-11 19:45:11",
            "last_seen_utc": "2026-06-30 10:46:00",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1830400": [
        {
            "ioc_value": "46.246.80.2:8848",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.dcrat",
            "malware_alias": "DarkCrystal RAT",
            "malware_printable": "DCRat",
            "first_seen_utc": "2026-06-11 19:44:53",
            "last_seen_utc": "2026-06-30 10:45:45",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DCRat,drb-ra,RAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1830398": [
        {
            "ioc_value": "46.101.195.123:31400",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.evilginx",
            "malware_alias": null,
            "malware_printable": "Evilginx",
            "first_seen_utc": "2026-06-11 19:44:52",
            "last_seen_utc": "2026-06-30 10:45:44",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Evilginx,EvilGoPhish",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1830399": [
        {
            "ioc_value": "46.151.182.181:2404",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-06-11 19:44:52",
            "last_seen_utc": "2026-06-30 10:45:44",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1830395": [
        {
            "ioc_value": "45.225.135.43:6606",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-06-11 19:44:49",
            "last_seen_utc": "2026-06-30 10:45:38",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1830396": [
        {
            "ioc_value": "45.225.135.43:7707",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-06-11 19:44:49",
            "last_seen_utc": "2026-06-30 10:45:38",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1830397": [
        {
            "ioc_value": "45.225.135.43:8808",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-06-11 19:44:49",
            "last_seen_utc": "2026-06-30 10:45:38",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1830394": [
        {
            "ioc_value": "31.76.93.193:4321",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-06-11 19:44:40",
            "last_seen_utc": "2026-06-30 10:45:26",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1830392": [
        {
            "ioc_value": "23.235.185.45:12159",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.dcrat",
            "malware_alias": "DarkCrystal RAT",
            "malware_printable": "DCRat",
            "first_seen_utc": "2026-06-11 19:44:35",
            "last_seen_utc": "2026-06-30 10:45:20",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DCRat,drb-ra,RAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1830393": [
        {
            "ioc_value": "23.235.185.46:12159",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.dcrat",
            "malware_alias": "DarkCrystal RAT",
            "malware_printable": "DCRat",
            "first_seen_utc": "2026-06-11 19:44:35",
            "last_seen_utc": "2026-06-30 10:45:20",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DCRat,drb-ra,RAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1830391": [
        {
            "ioc_value": "213.165.40.206:8887",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.bianlian",
            "malware_alias": null,
            "malware_printable": "BianLian",
            "first_seen_utc": "2026-06-11 19:44:04",
            "last_seen_utc": "2026-06-30 10:44:36",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "Bianlian,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1830390": [
        {
            "ioc_value": "209.99.188.193:43221",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-06-11 19:44:02",
            "last_seen_utc": "2026-06-30 10:44:33",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1830389": [
        {
            "ioc_value": "2.27.62.228:60204",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-06-11 19:43:57",
            "last_seen_utc": "2026-06-30 10:44:26",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1830388": [
        {
            "ioc_value": "194.116.236.239:4069",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-06-11 19:43:52",
            "last_seen_utc": "2026-06-30 10:44:18",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1830387": [
        {
            "ioc_value": "192.3.139.18:15221",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-06-11 19:43:50",
            "last_seen_utc": "2026-06-30 10:44:15",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1830384": [
        {
            "ioc_value": "188.137.242.166:6606",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-06-11 19:43:47",
            "last_seen_utc": "2026-06-30 10:44:11",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1830385": [
        {
            "ioc_value": "188.137.242.166:7707",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-06-11 19:43:47",
            "last_seen_utc": "2026-06-30 10:44:11",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1830386": [
        {
            "ioc_value": "188.137.242.166:8808",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-06-11 19:43:47",
            "last_seen_utc": "2026-06-30 10:44:11",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1830383": [
        {
            "ioc_value": "182.23.2.163:8307",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-06-11 19:43:41",
            "last_seen_utc": "2026-06-30 10:44:00",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1830382": [
        {
            "ioc_value": "178.255.126.146:7707",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-06-11 19:43:36",
            "last_seen_utc": "2026-06-30 10:43:54",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1830381": [
        {
            "ioc_value": "155.103.71.115:14408",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-06-11 19:43:22",
            "last_seen_utc": "2026-06-30 10:43:35",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1830380": [
        {
            "ioc_value": "130.94.18.95:24321",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-06-11 19:43:12",
            "last_seen_utc": "2026-06-30 10:43:21",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1830378": [
        {
            "ioc_value": "109.199.109.62:31337",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.sliver",
            "malware_alias": null,
            "malware_printable": "Sliver",
            "first_seen_utc": "2026-06-11 19:43:09",
            "last_seen_utc": "2026-06-30 10:43:16",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Sliver",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1830379": [
        {
            "ioc_value": "109.199.109.62:40056",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.sliver",
            "malware_alias": null,
            "malware_printable": "Sliver",
            "first_seen_utc": "2026-06-11 19:43:09",
            "last_seen_utc": "2026-06-30 10:43:16",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Sliver",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1830357": [
        {
            "ioc_value": "139.59.106.160:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.havoc",
            "malware_alias": "Havokiz",
            "malware_printable": "Havoc",
            "first_seen_utc": "2026-06-11 17:00:11",
            "last_seen_utc": "2026-06-30 10:43:24",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "havoc",
            "anonymous": "1",
            "reporter": "_ik_"
        }
    ],
    "1830348": [
        {
            "ioc_value": "139.59.106.160:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.havoc",
            "malware_alias": "Havokiz",
            "malware_printable": "Havoc",
            "first_seen_utc": "2026-06-11 16:00:23",
            "last_seen_utc": "2026-06-30 10:43:24",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "havoc",
            "anonymous": "1",
            "reporter": "_ik_"
        }
    ],
    "1830338": [
        {
            "ioc_value": "mlcos.cdnupdate.net",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-06-11 15:45:51",
            "last_seen_utc": "2026-06-30 10:46:24",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1830310": [
        {
            "ioc_value": "122.51.50.44:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-06-11 14:00:22",
            "last_seen_utc": "2026-06-30 10:46:42",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "cobaltstrike",
            "anonymous": "1",
            "reporter": "_ik_"
        }
    ],
    "1830307": [
        {
            "ioc_value": "172.94.18.103:79",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-06-11 14:00:17",
            "last_seen_utc": "2026-06-30 10:43:51",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "asyncrat",
            "anonymous": "1",
            "reporter": "_ik_"
        }
    ],
    "1830289": [
        {
            "ioc_value": "113.44.64.117:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-06-11 12:46:30",
            "last_seen_utc": "2026-06-30 10:43:17",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": "https://www.shodan.io/host/113.44.64.117#7443",
            "tags": "c2,mythic,shodan",
            "anonymous": "0",
            "reporter": "juroots"
        }
    ],
    "1830291": [
        {
            "ioc_value": "159.89.48.54:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-06-11 12:46:30",
            "last_seen_utc": "2026-06-30 10:43:40",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": "https://www.shodan.io/host/159.89.48.54#7443",
            "tags": "c2,mythic,shodan",
            "anonymous": "0",
            "reporter": "juroots"
        }
    ],
    "1830206": [
        {
            "ioc_value": "117.72.159.215:8080",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-06-11 12:42:24",
            "last_seen_utc": "2026-06-30 10:46:37",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": "https://www.shodan.io/host/117.72.159.215#8080",
            "tags": "c2,cobaltstrike,cs-watermark-987654321,shodan",
            "anonymous": "0",
            "reporter": "juroots"
        }
    ],
    "1830053": [
        {
            "ioc_value": "206.81.21.156:4321",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-06-11 09:44:07",
            "last_seen_utc": "2026-06-30 10:44:30",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1830051": [
        {
            "ioc_value": "182.23.2.163:4048",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-06-11 09:43:44",
            "last_seen_utc": "2026-06-30 10:43:58",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1830052": [
        {
            "ioc_value": "182.23.2.163:4814",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-06-11 09:43:44",
            "last_seen_utc": "2026-06-30 10:43:58",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1830050": [
        {
            "ioc_value": "182.23.2.163:1230",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-06-11 09:43:42",
            "last_seen_utc": "2026-06-30 10:43:56",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1830046": [
        {
            "ioc_value": "64.89.162.82:6606",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-06-11 09:00:15",
            "last_seen_utc": "2026-06-30 10:46:00",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "asyncrat",
            "anonymous": "1",
            "reporter": "_ik_"
        }
    ],
    "1830018": [
        {
            "ioc_value": "2.26.228.27:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.havoc",
            "malware_alias": "Havokiz",
            "malware_printable": "Havoc",
            "first_seen_utc": "2026-06-11 08:00:17",
            "last_seen_utc": "2026-06-30 10:44:24",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "havoc",
            "anonymous": "1",
            "reporter": "_ik_"
        }
    ],
    "1830007": [
        {
            "ioc_value": "45.87.53.6:8443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-06-11 06:43:05",
            "last_seen_utc": "2026-06-30 10:47:07",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-987654321",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1830006": [
        {
            "ioc_value": "120.55.3.157:10000",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-06-11 06:43:04",
            "last_seen_utc": "2026-06-30 09:53:53",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-987654321",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1830004": [
        {
            "ioc_value": "43.136.180.88:8080",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-06-11 06:42:48",
            "last_seen_utc": "2026-06-30 10:47:01",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-666666666",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1830002": [
        {
            "ioc_value": "43.136.180.88:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-06-11 06:42:47",
            "last_seen_utc": "2026-06-30 10:47:01",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-666666666",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1830003": [
        {
            "ioc_value": "47.121.181.148:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-06-11 06:42:47",
            "last_seen_utc": "2026-06-30 10:47:09",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-666666",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1830001": [
        {
            "ioc_value": "124.220.41.22:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-06-11 06:42:46",
            "last_seen_utc": "2026-06-30 10:46:42",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-100000",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1829999": [
        {
            "ioc_value": "160.202.230.103:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-06-11 06:42:44",
            "last_seen_utc": "2026-06-30 10:46:50",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-666666666",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1829997": [
        {
            "ioc_value": "139.5.108.17:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-06-11 06:42:41",
            "last_seen_utc": "2026-06-30 10:46:45",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-987654321",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1829953": [
        {
            "ioc_value": "156.234.211.138:8821",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-06-11 05:26:07",
            "last_seen_utc": "2026-06-30 10:46:48",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": null,
            "tags": "138195,c2,censys,cobalt strike",
            "anonymous": "0",
            "reporter": "sojubear"
        }
    ],
    "1829954": [
        {
            "ioc_value": "156.234.211.165:8821",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-06-11 05:26:06",
            "last_seen_utc": "2026-06-30 10:46:49",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": null,
            "tags": "138195,c2,censys,cobalt strike",
            "anonymous": "0",
            "reporter": "sojubear"
        }
    ],
    "1829957": [
        {
            "ioc_value": "192.144.213.21:18443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-06-11 05:26:05",
            "last_seen_utc": "2026-06-30 10:46:55",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": null,
            "tags": "45090,c2,censys,cobalt strike",
            "anonymous": "0",
            "reporter": "sojubear"
        }
    ],
    "1829946": [
        {
            "ioc_value": "85.137.240.208:18443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-06-10 23:45:53",
            "last_seen_utc": "2026-06-30 10:47:19",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1829910": [
        {
            "ioc_value": "1364170351-5ezc7c8ssf.ap-guangzhou.tencentscf.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-06-10 19:45:25",
            "last_seen_utc": "2026-06-30 10:46:20",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1829909": [
        {
            "ioc_value": "87.182.39.55:51125",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-06-10 19:45:19",
            "last_seen_utc": "2026-06-30 10:46:13",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1829908": [
        {
            "ioc_value": "82.221.139.243:52281",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.havoc",
            "malware_alias": "Havokiz",
            "malware_printable": "Havoc",
            "first_seen_utc": "2026-06-10 19:45:15",
            "last_seen_utc": "2026-06-30 10:46:09",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Havoc",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1829907": [
        {
            "ioc_value": "64.89.162.178:5902",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-06-10 19:45:10",
            "last_seen_utc": "2026-06-30 10:46:00",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1829905": [
        {
            "ioc_value": "45.157.116.119:29476",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-06-10 19:44:49",
            "last_seen_utc": "2026-06-30 10:45:37",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1829906": [
        {
            "ioc_value": "45.38.41.27:4321",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-06-10 19:44:49",
            "last_seen_utc": "2026-06-30 10:45:39",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1829904": [
        {
            "ioc_value": "45.140.14.29:1488",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-06-10 19:44:47",
            "last_seen_utc": "2026-06-30 10:45:35",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1829903": [
        {
            "ioc_value": "23.235.185.43:12159",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.dcrat",
            "malware_alias": "DarkCrystal RAT",
            "malware_printable": "DCRat",
            "first_seen_utc": "2026-06-10 19:44:35",
            "last_seen_utc": "2026-06-30 10:45:19",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DCRat,drb-ra,RAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1829902": [
        {
            "ioc_value": "216.158.235.73:3333",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.evilginx",
            "malware_alias": null,
            "malware_printable": "Evilginx",
            "first_seen_utc": "2026-06-10 19:44:33",
            "last_seen_utc": "2026-06-30 10:45:17",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Evilginx,EvilGoPhish",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1829900": [
        {
            "ioc_value": "198.23.185.231:20200",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-06-10 19:43:55",
            "last_seen_utc": "2026-06-30 10:44:23",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1829901": [
        {
            "ioc_value": "198.23.185.231:20800",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-06-10 19:43:55",
            "last_seen_utc": "2026-06-30 10:44:23",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1829899": [
        {
            "ioc_value": "193.135.137.240:4321",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-06-10 19:43:51",
            "last_seen_utc": "2026-06-30 10:44:15",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1829898": [
        {
            "ioc_value": "191.107.87.183:5471",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-06-10 19:43:49",
            "last_seen_utc": "2026-06-30 10:44:13",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1829897": [
        {
            "ioc_value": "188.23.170.168:8000",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.eye_pyramid",
            "malware_alias": null,
            "malware_printable": "Eye Pyramid",
            "first_seen_utc": "2026-06-10 19:43:48",
            "last_seen_utc": "2026-06-30 10:44:11",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,EyePyramid",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1829896": [
        {
            "ioc_value": "185.33.84.183:3000",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.evilginx",
            "malware_alias": null,
            "malware_printable": "Evilginx",
            "first_seen_utc": "2026-06-10 19:43:46",
            "last_seen_utc": "2026-06-30 10:44:09",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Evilginx,EvilGoPhish",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1829895": [
        {
            "ioc_value": "182.23.2.163:9800",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-06-10 19:43:41",
            "last_seen_utc": "2026-06-30 10:44:00",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1829894": [
        {
            "ioc_value": "181.235.14.94:3588",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.dcrat",
            "malware_alias": "DarkCrystal RAT",
            "malware_printable": "DCRat",
            "first_seen_utc": "2026-06-10 19:43:38",
            "last_seen_utc": "2026-06-30 10:43:55",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DCRat,drb-ra,RAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1829893": [
        {
            "ioc_value": "172.94.18.103:71",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-06-10 19:43:34",
            "last_seen_utc": "2026-06-30 10:43:50",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1829892": [
        {
            "ioc_value": "170.39.185.141:2030",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.evilginx",
            "malware_alias": null,
            "malware_printable": "Evilginx",
            "first_seen_utc": "2026-06-10 19:43:32",
            "last_seen_utc": "2026-06-30 10:43:46",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Evilginx,EvilGoPhish",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1829891": [
        {
            "ioc_value": "163.245.217.90:3333",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.evilginx",
            "malware_alias": null,
            "malware_printable": "Evilginx",
            "first_seen_utc": "2026-06-10 19:43:29",
            "last_seen_utc": "2026-06-30 10:43:43",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Evilginx,EvilGoPhish",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1829889": [
        {
            "ioc_value": "159.69.59.93:4550",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-06-10 19:43:26",
            "last_seen_utc": "2026-06-30 10:43:40",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1829888": [
        {
            "ioc_value": "153.75.249.13:4321",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-06-10 19:43:20",
            "last_seen_utc": "2026-06-30 10:43:32",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1829887": [
        {
            "ioc_value": "146.70.51.74:7898",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.dcrat",
            "malware_alias": "DarkCrystal RAT",
            "malware_printable": "DCRat",
            "first_seen_utc": "2026-06-10 19:43:18",
            "last_seen_utc": "2026-06-30 10:43:28",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DCRat,drb-ra,RAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1829886": [
        {
            "ioc_value": "130.94.95.135:2404",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-06-10 19:43:13",
            "last_seen_utc": "2026-06-30 10:43:21",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1829786": [
        {
            "ioc_value": "8.148.201.210:10553",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-06-10 11:46:09",
            "last_seen_utc": "2026-06-30 10:47:16",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1829785": [
        {
            "ioc_value": "38.76.164.56:8083",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-06-10 11:45:58",
            "last_seen_utc": "2026-06-30 10:47:00",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1829784": [
        {
            "ioc_value": "38.14.248.138:8085",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-06-10 11:45:57",
            "last_seen_utc": "2026-06-30 10:46:59",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1829779": [
        {
            "ioc_value": "185.92.190.214:5896",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-06-10 11:45:53",
            "last_seen_utc": "2026-06-30 10:46:54",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1829780": [
        {
            "ioc_value": "185.92.190.215:5896",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-06-10 11:45:53",
            "last_seen_utc": "2026-06-30 10:46:54",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1829781": [
        {
            "ioc_value": "185.92.190.215:8896",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-06-10 11:45:53",
            "last_seen_utc": "2026-06-30 10:46:54",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1829782": [
        {
            "ioc_value": "185.92.190.216:5896",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-06-10 11:45:53",
            "last_seen_utc": "2026-06-30 10:46:54",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1829783": [
        {
            "ioc_value": "185.92.190.217:5896",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-06-10 11:45:53",
            "last_seen_utc": "2026-06-30 10:46:54",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1829777": [
        {
            "ioc_value": "185.92.190.213:5896",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-06-10 11:45:52",
            "last_seen_utc": "2026-06-30 10:46:53",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1829778": [
        {
            "ioc_value": "185.92.190.213:8896",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-06-10 11:45:52",
            "last_seen_utc": "2026-06-30 10:46:53",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1825873": [
        {
            "ioc_value": "38.47.122.34:8888",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-06-10 10:00:17",
            "last_seen_utc": "2026-06-30 10:46:59",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "cobaltstrike",
            "anonymous": "1",
            "reporter": "_ik_"
        }
    ],
    "1825867": [
        {
            "ioc_value": "64.89.162.117:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-06-10 09:45:40",
            "last_seen_utc": "2026-06-30 10:46:00",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1825866": [
        {
            "ioc_value": "46.246.82.4:8848",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.dcrat",
            "malware_alias": "DarkCrystal RAT",
            "malware_printable": "DCRat",
            "first_seen_utc": "2026-06-10 09:45:22",
            "last_seen_utc": "2026-06-30 10:45:45",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DCRat,drb-ra,RAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1825865": [
        {
            "ioc_value": "45.81.17.44:6606",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-06-10 09:45:19",
            "last_seen_utc": "2026-06-30 10:45:42",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1825864": [
        {
            "ioc_value": "45.147.28.58:42461",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-06-10 09:45:16",
            "last_seen_utc": "2026-06-30 10:45:36",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1825863": [
        {
            "ioc_value": "31.76.87.188:4034",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-06-10 09:45:01",
            "last_seen_utc": "2026-06-30 10:45:25",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1825862": [
        {
            "ioc_value": "23.95.220.192:43999",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-06-10 09:44:56",
            "last_seen_utc": "2026-06-30 10:45:21",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1825860": [
        {
            "ioc_value": "207.180.250.181:1111",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-06-10 09:44:15",
            "last_seen_utc": "2026-06-30 10:44:31",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1825861": [
        {
            "ioc_value": "207.180.250.181:6606",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-06-10 09:44:15",
            "last_seen_utc": "2026-06-30 10:44:31",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1825858": [
        {
            "ioc_value": "2.27.5.120:6448",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-06-10 09:44:10",
            "last_seen_utc": "2026-06-30 10:44:25",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1825859": [
        {
            "ioc_value": "2.27.5.236:1377",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-06-10 09:44:10",
            "last_seen_utc": "2026-06-30 10:44:26",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1825857": [
        {
            "ioc_value": "2.26.75.249:7312",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-06-10 09:44:09",
            "last_seen_utc": "2026-06-30 10:44:25",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1825855": [
        {
            "ioc_value": "198.23.177.222:14646",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-06-10 09:44:08",
            "last_seen_utc": "2026-06-30 10:44:22",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1825856": [
        {
            "ioc_value": "198.23.185.231:20100",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-06-10 09:44:08",
            "last_seen_utc": "2026-06-30 10:44:23",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1825854": [
        {
            "ioc_value": "192.3.96.82:45683",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-06-10 09:44:01",
            "last_seen_utc": "2026-06-30 10:44:15",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1825853": [
        {
            "ioc_value": "192.208.12.91:3000",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.evilginx",
            "malware_alias": null,
            "malware_printable": "Evilginx",
            "first_seen_utc": "2026-06-10 09:44:00",
            "last_seen_utc": "2026-06-30 10:44:14",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Evilginx,EvilGoPhish",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1825852": [
        {
            "ioc_value": "182.23.2.163:12489",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-06-10 09:43:47",
            "last_seen_utc": "2026-06-30 10:43:56",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1825851": [
        {
            "ioc_value": "178.236.46.43:7912",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.dcrat",
            "malware_alias": "DarkCrystal RAT",
            "malware_printable": "DCRat",
            "first_seen_utc": "2026-06-10 09:43:45",
            "last_seen_utc": "2026-06-30 10:43:54",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DCRat,drb-ra,RAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1825850": [
        {
            "ioc_value": "163.245.217.48:3333",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.evilginx",
            "malware_alias": null,
            "malware_printable": "Evilginx",
            "first_seen_utc": "2026-06-10 09:43:35",
            "last_seen_utc": "2026-06-30 10:43:43",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Evilginx,EvilGoPhish",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1825849": [
        {
            "ioc_value": "158.94.210.30:8848",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.dcrat",
            "malware_alias": "DarkCrystal RAT",
            "malware_printable": "DCRat",
            "first_seen_utc": "2026-06-10 09:43:31",
            "last_seen_utc": "2026-06-30 10:43:39",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DCRat,drb-ra,RAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1825848": [
        {
            "ioc_value": "158.94.208.192:1030",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-06-10 09:43:30",
            "last_seen_utc": "2026-06-30 10:43:39",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1825847": [
        {
            "ioc_value": "154.83.186.106:30159",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-06-10 09:43:25",
            "last_seen_utc": "2026-06-30 10:43:33",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1825846": [
        {
            "ioc_value": "107.175.87.234:65321",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-06-10 09:43:10",
            "last_seen_utc": "2026-06-30 10:43:15",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1825845": [
        {
            "ioc_value": "107.172.133.178:56003",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-06-10 09:43:09",
            "last_seen_utc": "2026-06-30 10:43:12",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1825844": [
        {
            "ioc_value": "104.251.181.62:3421",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-06-10 09:43:08",
            "last_seen_utc": "2026-06-30 10:43:12",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1825843": [
        {
            "ioc_value": "104.143.206.116:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.mirai",
            "malware_alias": "Katana",
            "malware_printable": "Mirai",
            "first_seen_utc": "2026-06-10 09:43:07",
            "last_seen_utc": "2026-06-30 10:43:11",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mirai",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1825788": [
        {
            "ioc_value": "34.92.128.98:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-06-10 07:18:53",
            "last_seen_utc": "2026-06-30 10:46:58",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-987654321",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1825772": [
        {
            "ioc_value": "167.71.217.41:7538",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remus",
            "malware_alias": null,
            "malware_printable": "Remus",
            "first_seen_utc": "2026-06-10 06:47:18",
            "last_seen_utc": "2026-06-28 13:10:44",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://bazaar.abuse.ch/sample/2194042f5f4a385486b259dd6f174748a5fbc260dcafe8abac842382010f3b10/",
            "tags": "remus",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1825703": [
        {
            "ioc_value": "8.163.59.20:8008",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-06-10 06:00:25",
            "last_seen_utc": "2026-06-30 10:47:17",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "cobaltstrike",
            "anonymous": "1",
            "reporter": "_ik_"
        }
    ],
    "1825685": [
        {
            "ioc_value": "142.93.96.42:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-06-10 04:00:23",
            "last_seen_utc": "2026-06-30 10:43:26",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "mythic",
            "anonymous": "1",
            "reporter": "_ik_"
        }
    ],
    "1825679": [
        {
            "ioc_value": "8.219.158.30:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-06-10 03:45:50",
            "last_seen_utc": "2026-06-30 10:47:17",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1825678": [
        {
            "ioc_value": "218.244.142.4:8889",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-06-10 03:45:38",
            "last_seen_utc": "2026-06-30 10:46:57",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1825676": [
        {
            "ioc_value": "156.234.114.122:8821",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-06-10 03:45:33",
            "last_seen_utc": "2026-06-30 10:46:48",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1825677": [
        {
            "ioc_value": "156.234.211.220:8821",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-06-10 03:45:33",
            "last_seen_utc": "2026-06-30 10:46:49",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1825675": [
        {
            "ioc_value": "google.dns-1.help",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-06-10 03:45:13",
            "last_seen_utc": "2026-06-30 10:46:23",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1825647": [
        {
            "ioc_value": "130.94.17.180:8082",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-06-09 23:45:35",
            "last_seen_utc": "2026-06-30 10:46:44",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1825631": [
        {
            "ioc_value": "198.46.199.110:53",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-06-09 21:45:51",
            "last_seen_utc": "2026-06-30 10:46:55",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1825622": [
        {
            "ioc_value": "181.215.18.135:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-06-09 21:00:13",
            "last_seen_utc": "2026-06-30 10:46:53",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "cobaltstrike",
            "anonymous": "1",
            "reporter": "_ik_"
        }
    ],
    "1825614": [
        {
            "ioc_value": "45.87.53.6:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-06-09 20:00:17",
            "last_seen_utc": "2026-06-30 09:54:11",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "cobaltstrike",
            "anonymous": "1",
            "reporter": "_ik_"
        }
    ],
    "1825613": [
        {
            "ioc_value": "46.151.182.16:1011",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-06-09 19:44:51",
            "last_seen_utc": "2026-06-30 10:45:44",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1825612": [
        {
            "ioc_value": "202.73.4.137:8443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.havoc",
            "malware_alias": "Havokiz",
            "malware_printable": "Havoc",
            "first_seen_utc": "2026-06-09 19:43:58",
            "last_seen_utc": "2026-06-30 10:44:28",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Havoc",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1825611": [
        {
            "ioc_value": "2.27.5.234:4509",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-06-09 19:43:56",
            "last_seen_utc": "2026-06-30 10:44:26",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1825610": [
        {
            "ioc_value": "2.26.75.243:9521",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-06-09 19:43:55",
            "last_seen_utc": "2026-06-30 10:44:25",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1825609": [
        {
            "ioc_value": "198.23.177.222:14644",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-06-09 19:43:54",
            "last_seen_utc": "2026-06-30 10:44:21",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1825608": [
        {
            "ioc_value": "182.23.2.163:15646",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-06-09 19:43:40",
            "last_seen_utc": "2026-06-30 10:43:57",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1825607": [
        {
            "ioc_value": "167.160.186.140:62738",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-06-09 19:43:30",
            "last_seen_utc": "2026-06-30 10:43:44",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1825606": [
        {
            "ioc_value": "162.35.161.101:8080",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.chaos",
            "malware_alias": "FakeRyuk,RyukJoke,Yashma",
            "malware_printable": "Chaos",
            "first_seen_utc": "2026-06-09 19:43:28",
            "last_seen_utc": "2026-06-30 10:43:42",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CHAOS,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1825605": [
        {
            "ioc_value": "107.172.135.27:14644",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-06-09 19:43:08",
            "last_seen_utc": "2026-06-30 10:43:13",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1825604": [
        {
            "ioc_value": "104.168.0.29:52203",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-06-09 19:43:06",
            "last_seen_utc": "2026-06-30 10:43:11",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1825593": [
        {
            "ioc_value": "pilotkadomen.club",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "unknown_stealer",
            "malware_alias": null,
            "malware_printable": "Unknown Stealer",
            "first_seen_utc": "2026-06-09 18:51:52",
            "last_seen_utc": "2026-06-29 13:26:39",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "c2,etherhiding,Polygon",
            "anonymous": "0",
            "reporter": "varysz"
        }
    ],
    "1825594": [
        {
            "ioc_value": "nihaoclub.asia",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "unknown_stealer",
            "malware_alias": null,
            "malware_printable": "Unknown Stealer",
            "first_seen_utc": "2026-06-09 18:51:52",
            "last_seen_utc": "2026-06-29 13:26:41",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "c2,etherhiding,Polygon",
            "anonymous": "0",
            "reporter": "varysz"
        }
    ],
    "1825585": [
        {
            "ioc_value": "spasopro.at",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.amadey",
            "malware_alias": null,
            "malware_printable": "Amadey",
            "first_seen_utc": "2026-06-09 18:36:01",
            "last_seen_utc": "2026-06-30 11:24:03",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": "https://tracker.viriback.com/index.php?q=spasopro.at",
            "tags": "Amadey,ViriBack",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1825435": [
        {
            "ioc_value": "204.194.54.9:7707",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-06-09 09:44:07",
            "last_seen_utc": "2026-06-30 10:44:29",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1825436": [
        {
            "ioc_value": "204.194.54.9:8808",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-06-09 09:44:07",
            "last_seen_utc": "2026-06-30 10:44:29",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1825434": [
        {
            "ioc_value": "204.194.54.9:6606",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-06-09 09:44:06",
            "last_seen_utc": "2026-06-30 10:44:29",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1825433": [
        {
            "ioc_value": "2.26.75.248:2428",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-06-09 09:44:03",
            "last_seen_utc": "2026-06-30 10:44:25",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1825432": [
        {
            "ioc_value": "2.26.75.241:4509",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-06-09 09:44:02",
            "last_seen_utc": "2026-06-30 10:44:25",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1825430": [
        {
            "ioc_value": "194.11.246.191:4404",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-06-09 09:43:58",
            "last_seen_utc": "2026-06-30 10:44:18",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1825431": [
        {
            "ioc_value": "194.11.246.191:6606",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-06-09 09:43:58",
            "last_seen_utc": "2026-06-30 10:44:18",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1825429": [
        {
            "ioc_value": "182.23.2.163:10616",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-06-09 09:43:43",
            "last_seen_utc": "2026-06-30 10:43:55",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1825428": [
        {
            "ioc_value": "175.178.123.42:28443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-06-09 09:43:39",
            "last_seen_utc": "2026-06-30 10:43:51",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1825427": [
        {
            "ioc_value": "170.62.130.191:4321",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-06-09 09:43:35",
            "last_seen_utc": "2026-06-30 10:43:46",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1825381": [
        {
            "ioc_value": "110.42.219.9:8080",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-06-09 07:00:14",
            "last_seen_utc": "2026-06-30 10:46:33",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "cobaltstrike",
            "anonymous": "1",
            "reporter": "_ik_"
        }
    ],
    "1825293": [
        {
            "ioc_value": "8.219.158.30:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-06-09 05:11:01",
            "last_seen_utc": "2026-06-30 10:47:18",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": null,
            "tags": "45102,c2,censys,cobalt strike",
            "anonymous": "0",
            "reporter": "sojubear"
        }
    ],
    "1825237": [
        {
            "ioc_value": "webflare.beer",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "unknown_stealer",
            "malware_alias": null,
            "malware_printable": "Unknown Stealer",
            "first_seen_utc": "2026-06-09 05:10:52",
            "last_seen_utc": "2026-06-29 13:39:32",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "c2,etherhiding,Polygon",
            "anonymous": "0",
            "reporter": "varysz"
        }
    ],
    "1825308": [
        {
            "ioc_value": "120.55.246.213:18443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-06-09 02:45:24",
            "last_seen_utc": "2026-06-30 10:46:41",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1825289": [
        {
            "ioc_value": "149.88.66.234:20050",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-06-08 23:45:33",
            "last_seen_utc": "2026-06-30 10:46:46",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1825227": [
        {
            "ioc_value": "182.23.2.163:12297",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-06-08 19:43:41",
            "last_seen_utc": "2026-06-30 10:43:56",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1825226": [
        {
            "ioc_value": "155.103.70.100:13407",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-06-08 19:43:23",
            "last_seen_utc": "2026-06-30 10:43:34",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1825189": [
        {
            "ioc_value": "robodomain.sbs",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "unknown_stealer",
            "malware_alias": null,
            "malware_printable": "Unknown Stealer",
            "first_seen_utc": "2026-06-08 18:14:02",
            "last_seen_utc": "2026-06-29 13:34:30",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "c2,etherhiding,Polygon",
            "anonymous": "0",
            "reporter": "varysz"
        }
    ],
    "1825192": [
        {
            "ioc_value": "sirata.asia",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "unknown_stealer",
            "malware_alias": null,
            "malware_printable": "Unknown Stealer",
            "first_seen_utc": "2026-06-08 17:54:08",
            "last_seen_utc": "2026-06-29 13:35:24",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "c2,etherhiding,Polygon",
            "anonymous": "0",
            "reporter": "varysz"
        }
    ],
    "1825194": [
        {
            "ioc_value": "smackit.lat",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "unknown_stealer",
            "malware_alias": null,
            "malware_printable": "Unknown Stealer",
            "first_seen_utc": "2026-06-08 17:54:08",
            "last_seen_utc": "2026-06-29 13:34:17",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "c2,etherhiding,Polygon",
            "anonymous": "0",
            "reporter": "varysz"
        }
    ],
    "1825196": [
        {
            "ioc_value": "spartanec.lat",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "unknown_stealer",
            "malware_alias": null,
            "malware_printable": "Unknown Stealer",
            "first_seen_utc": "2026-06-08 17:54:08",
            "last_seen_utc": "2026-06-29 13:34:20",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "c2,etherhiding,Polygon",
            "anonymous": "0",
            "reporter": "varysz"
        }
    ],
    "1825197": [
        {
            "ioc_value": "superpooper.click",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "unknown_stealer",
            "malware_alias": null,
            "malware_printable": "Unknown Stealer",
            "first_seen_utc": "2026-06-08 17:54:08",
            "last_seen_utc": "2026-06-29 13:34:35",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "c2,etherhiding,Polygon",
            "anonymous": "0",
            "reporter": "varysz"
        }
    ],
    "1825199": [
        {
            "ioc_value": "whynotebanarot.xyz",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "unknown_stealer",
            "malware_alias": null,
            "malware_printable": "Unknown Stealer",
            "first_seen_utc": "2026-06-08 17:54:08",
            "last_seen_utc": "2026-06-29 13:34:40",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "c2,etherhiding,Polygon",
            "anonymous": "0",
            "reporter": "varysz"
        }
    ],
    "1825200": [
        {
            "ioc_value": "yanepidor.mom",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "unknown_stealer",
            "malware_alias": null,
            "malware_printable": "Unknown Stealer",
            "first_seen_utc": "2026-06-08 17:54:08",
            "last_seen_utc": "2026-06-29 13:35:19",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "c2,etherhiding,Polygon",
            "anonymous": "0",
            "reporter": "varysz"
        }
    ],
    "1825201": [
        {
            "ioc_value": "yoshicity.xyz",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "unknown_stealer",
            "malware_alias": null,
            "malware_printable": "Unknown Stealer",
            "first_seen_utc": "2026-06-08 17:54:08",
            "last_seen_utc": "2026-06-29 13:34:47",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "c2,etherhiding,Polygon",
            "anonymous": "0",
            "reporter": "varysz"
        }
    ],
    "1825181": [
        {
            "ioc_value": "nenadopapa.cfd",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "unknown_stealer",
            "malware_alias": null,
            "malware_printable": "Unknown Stealer",
            "first_seen_utc": "2026-06-08 17:54:07",
            "last_seen_utc": "2026-06-29 13:35:18",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "c2,etherhiding,Polygon",
            "anonymous": "0",
            "reporter": "varysz"
        }
    ],
    "1825182": [
        {
            "ioc_value": "peachbro.bond",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "unknown_stealer",
            "malware_alias": null,
            "malware_printable": "Unknown Stealer",
            "first_seen_utc": "2026-06-08 17:54:07",
            "last_seen_utc": "2026-06-29 13:26:49",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "c2,etherhiding,Polygon",
            "anonymous": "0",
            "reporter": "varysz"
        }
    ],
    "1825183": [
        {
            "ioc_value": "pinokros.xyz",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "unknown_stealer",
            "malware_alias": null,
            "malware_printable": "Unknown Stealer",
            "first_seen_utc": "2026-06-08 17:54:07",
            "last_seen_utc": "2026-06-29 13:26:53",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "c2,etherhiding,Polygon",
            "anonymous": "0",
            "reporter": "varysz"
        }
    ],
    "1825184": [
        {
            "ioc_value": "pohuimne.lol",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "unknown_stealer",
            "malware_alias": null,
            "malware_printable": "Unknown Stealer",
            "first_seen_utc": "2026-06-08 17:54:07",
            "last_seen_utc": "2026-06-29 13:35:12",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "c2,etherhiding,Polygon",
            "anonymous": "0",
            "reporter": "varysz"
        }
    ],
    "1825185": [
        {
            "ioc_value": "ponikas.cyou",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "unknown_stealer",
            "malware_alias": null,
            "malware_printable": "Unknown Stealer",
            "first_seen_utc": "2026-06-08 17:54:07",
            "last_seen_utc": "2026-06-29 13:34:27",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "c2,etherhiding,Polygon",
            "anonymous": "0",
            "reporter": "varysz"
        }
    ],
    "1825186": [
        {
            "ioc_value": "pringlesbob.cfd",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "unknown_stealer",
            "malware_alias": null,
            "malware_printable": "Unknown Stealer",
            "first_seen_utc": "2026-06-08 17:54:07",
            "last_seen_utc": "2026-06-29 13:26:51",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "c2,etherhiding,Polygon",
            "anonymous": "0",
            "reporter": "varysz"
        }
    ],
    "1825188": [
        {
            "ioc_value": "prokladka.lol",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "unknown_stealer",
            "malware_alias": null,
            "malware_printable": "Unknown Stealer",
            "first_seen_utc": "2026-06-08 17:54:07",
            "last_seen_utc": "2026-06-29 13:35:09",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "c2,etherhiding,Polygon",
            "anonymous": "0",
            "reporter": "varysz"
        }
    ],
    "1825190": [
        {
            "ioc_value": "sandman.bond",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "unknown_stealer",
            "malware_alias": null,
            "malware_printable": "Unknown Stealer",
            "first_seen_utc": "2026-06-08 17:54:07",
            "last_seen_utc": "2026-06-29 13:34:57",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "c2,etherhiding,Polygon",
            "anonymous": "0",
            "reporter": "varysz"
        }
    ],
    "1825191": [
        {
            "ioc_value": "sandman.lat",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "unknown_stealer",
            "malware_alias": null,
            "malware_printable": "Unknown Stealer",
            "first_seen_utc": "2026-06-08 17:54:07",
            "last_seen_utc": "2026-06-29 13:34:50",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "c2,etherhiding,Polygon",
            "anonymous": "0",
            "reporter": "varysz"
        }
    ],
    "1825166": [
        {
            "ioc_value": "marmelad.lat",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "unknown_stealer",
            "malware_alias": null,
            "malware_printable": "Unknown Stealer",
            "first_seen_utc": "2026-06-08 17:54:06",
            "last_seen_utc": "2026-06-29 13:34:37",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "c2,etherhiding,Polygon",
            "anonymous": "0",
            "reporter": "varysz"
        }
    ],
    "1825167": [
        {
            "ioc_value": "megamegalodon.click",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "unknown_stealer",
            "malware_alias": null,
            "malware_printable": "Unknown Stealer",
            "first_seen_utc": "2026-06-08 17:54:06",
            "last_seen_utc": "2026-06-29 13:27:07",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "c2,etherhiding,Polygon",
            "anonymous": "0",
            "reporter": "varysz"
        }
    ],
    "1825168": [
        {
            "ioc_value": "merindashop.cyou",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "unknown_stealer",
            "malware_alias": null,
            "malware_printable": "Unknown Stealer",
            "first_seen_utc": "2026-06-08 17:54:06",
            "last_seen_utc": "2026-06-29 13:26:56",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "c2,etherhiding,Polygon",
            "anonymous": "0",
            "reporter": "varysz"
        }
    ],
    "1825169": [
        {
            "ioc_value": "mexicodreams.bond",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "unknown_stealer",
            "malware_alias": null,
            "malware_printable": "Unknown Stealer",
            "first_seen_utc": "2026-06-08 17:54:06",
            "last_seen_utc": "2026-06-29 13:26:46",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "c2,etherhiding,Polygon",
            "anonymous": "0",
            "reporter": "varysz"
        }
    ],
    "1825171": [
        {
            "ioc_value": "microchlen.lat",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "unknown_stealer",
            "malware_alias": null,
            "malware_printable": "Unknown Stealer",
            "first_seen_utc": "2026-06-08 17:54:06",
            "last_seen_utc": "2026-06-29 13:34:45",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "c2,etherhiding,Polygon",
            "anonymous": "0",
            "reporter": "varysz"
        }
    ],
    "1825173": [
        {
            "ioc_value": "milksos.cfd",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "unknown_stealer",
            "malware_alias": null,
            "malware_printable": "Unknown Stealer",
            "first_seen_utc": "2026-06-08 17:54:06",
            "last_seen_utc": "2026-06-29 13:34:29",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "c2,etherhiding,Polygon",
            "anonymous": "0",
            "reporter": "varysz"
        }
    ],
    "1825174": [
        {
            "ioc_value": "mnepohui.sbs",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "unknown_stealer",
            "malware_alias": null,
            "malware_printable": "Unknown Stealer",
            "first_seen_utc": "2026-06-08 17:54:06",
            "last_seen_utc": "2026-06-29 13:34:42",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "c2,etherhiding,Polygon",
            "anonymous": "0",
            "reporter": "varysz"
        }
    ],
    "1825175": [
        {
            "ioc_value": "mob.lanjut.in",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "unknown_stealer",
            "malware_alias": null,
            "malware_printable": "Unknown Stealer",
            "first_seen_utc": "2026-06-08 17:54:06",
            "last_seen_utc": "2026-06-29 13:26:58",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "c2,etherhiding,Polygon",
            "anonymous": "0",
            "reporter": "varysz"
        }
    ],
    "1825176": [
        {
            "ioc_value": "myblobtop.site",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "unknown_stealer",
            "malware_alias": null,
            "malware_printable": "Unknown Stealer",
            "first_seen_utc": "2026-06-08 17:54:06",
            "last_seen_utc": "2026-06-29 13:35:23",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "c2,etherhiding,Polygon",
            "anonymous": "0",
            "reporter": "varysz"
        }
    ],
    "1825154": [
        {
            "ioc_value": "etomoe.cfd",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "unknown_stealer",
            "malware_alias": null,
            "malware_printable": "Unknown Stealer",
            "first_seen_utc": "2026-06-08 17:54:05",
            "last_seen_utc": "2026-06-29 13:34:59",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "c2,etherhiding,Polygon",
            "anonymous": "0",
            "reporter": "varysz"
        }
    ],
    "1825155": [
        {
            "ioc_value": "etomoidomen.cfd",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "unknown_stealer",
            "malware_alias": null,
            "malware_printable": "Unknown Stealer",
            "first_seen_utc": "2026-06-08 17:54:05",
            "last_seen_utc": "2026-06-29 13:35:07",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "c2,etherhiding,Polygon",
            "anonymous": "0",
            "reporter": "varysz"
        }
    ],
    "1825156": [
        {
            "ioc_value": "ganiballektor.cfd",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "unknown_stealer",
            "malware_alias": null,
            "malware_printable": "Unknown Stealer",
            "first_seen_utc": "2026-06-08 17:54:05",
            "last_seen_utc": "2026-06-29 13:27:08",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "c2,etherhiding,Polygon",
            "anonymous": "0",
            "reporter": "varysz"
        }
    ],
    "1825157": [
        {
            "ioc_value": "gdedengikarlos.cfd",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "unknown_stealer",
            "malware_alias": null,
            "malware_printable": "Unknown Stealer",
            "first_seen_utc": "2026-06-08 17:54:05",
            "last_seen_utc": "2026-06-29 13:34:25",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "c2,etherhiding,Polygon",
            "anonymous": "0",
            "reporter": "varysz"
        }
    ],
    "1825160": [
        {
            "ioc_value": "gppcdnns.beer",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "unknown_stealer",
            "malware_alias": null,
            "malware_printable": "Unknown Stealer",
            "first_seen_utc": "2026-06-08 17:54:05",
            "last_seen_utc": "2026-06-29 13:27:05",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "c2,etherhiding,Polygon",
            "anonymous": "0",
            "reporter": "varysz"
        }
    ],
    "1825161": [
        {
            "ioc_value": "ivangay.bond",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "unknown_stealer",
            "malware_alias": null,
            "malware_printable": "Unknown Stealer",
            "first_seen_utc": "2026-06-08 17:54:05",
            "last_seen_utc": "2026-06-29 13:35:01",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "c2,etherhiding,Polygon",
            "anonymous": "0",
            "reporter": "varysz"
        }
    ],
    "1825162": [
        {
            "ioc_value": "lenders.digital",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "unknown_stealer",
            "malware_alias": null,
            "malware_printable": "Unknown Stealer",
            "first_seen_utc": "2026-06-08 17:54:05",
            "last_seen_utc": "2026-06-29 13:27:12",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "c2,etherhiding,Polygon",
            "anonymous": "0",
            "reporter": "varysz"
        }
    ],
    "1825163": [
        {
            "ioc_value": "lizablud.shop",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "unknown_stealer",
            "malware_alias": null,
            "malware_printable": "Unknown Stealer",
            "first_seen_utc": "2026-06-08 17:54:05",
            "last_seen_utc": "2026-06-29 13:26:44",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "c2,etherhiding,Polygon",
            "anonymous": "0",
            "reporter": "varysz"
        }
    ],
    "1825164": [
        {
            "ioc_value": "mambet.lol",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "unknown_stealer",
            "malware_alias": null,
            "malware_printable": "Unknown Stealer",
            "first_seen_utc": "2026-06-08 17:54:05",
            "last_seen_utc": "2026-06-29 13:34:52",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "c2,etherhiding,Polygon",
            "anonymous": "0",
            "reporter": "varysz"
        }
    ],
    "1825165": [
        {
            "ioc_value": "marinaradom.cfd",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "unknown_stealer",
            "malware_alias": null,
            "malware_printable": "Unknown Stealer",
            "first_seen_utc": "2026-06-08 17:54:05",
            "last_seen_utc": "2026-06-29 13:34:19",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "c2,etherhiding,Polygon",
            "anonymous": "0",
            "reporter": "varysz"
        }
    ],
    "1825143": [
        {
            "ioc_value": "biletors.cfd",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "unknown_stealer",
            "malware_alias": null,
            "malware_printable": "Unknown Stealer",
            "first_seen_utc": "2026-06-08 17:54:04",
            "last_seen_utc": "2026-06-29 13:34:15",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "c2,etherhiding,Polygon",
            "anonymous": "0",
            "reporter": "varysz"
        }
    ],
    "1825144": [
        {
            "ioc_value": "blobtop.sbs",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "unknown_stealer",
            "malware_alias": null,
            "malware_printable": "Unknown Stealer",
            "first_seen_utc": "2026-06-08 17:54:04",
            "last_seen_utc": "2026-06-29 13:35:26",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "c2,etherhiding,Polygon",
            "anonymous": "0",
            "reporter": "varysz"
        }
    ],
    "1825145": [
        {
            "ioc_value": "bobik.cfd",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "unknown_stealer",
            "malware_alias": null,
            "malware_printable": "Unknown Stealer",
            "first_seen_utc": "2026-06-08 17:54:04",
            "last_seen_utc": "2026-06-29 13:34:44",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "c2,etherhiding,Polygon",
            "anonymous": "0",
            "reporter": "varysz"
        }
    ],
    "1825146": [
        {
            "ioc_value": "bulletpop.cyou",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "unknown_stealer",
            "malware_alias": null,
            "malware_printable": "Unknown Stealer",
            "first_seen_utc": "2026-06-08 17:54:04",
            "last_seen_utc": "2026-06-29 13:34:22",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "c2,etherhiding,Polygon",
            "anonymous": "0",
            "reporter": "varysz"
        }
    ],
    "1825147": [
        {
            "ioc_value": "chinabowl.club",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "unknown_stealer",
            "malware_alias": null,
            "malware_printable": "Unknown Stealer",
            "first_seen_utc": "2026-06-08 17:54:04",
            "last_seen_utc": "2026-06-29 13:26:43",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "c2,etherhiding,Polygon",
            "anonymous": "0",
            "reporter": "varysz"
        }
    ],
    "1825148": [
        {
            "ioc_value": "chubrik.sbs",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "unknown_stealer",
            "malware_alias": null,
            "malware_printable": "Unknown Stealer",
            "first_seen_utc": "2026-06-08 17:54:04",
            "last_seen_utc": "2026-06-29 13:34:34",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "c2,etherhiding,Polygon",
            "anonymous": "0",
            "reporter": "varysz"
        }
    ],
    "1825150": [
        {
            "ioc_value": "comicstar.lat",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "unknown_stealer",
            "malware_alias": null,
            "malware_printable": "Unknown Stealer",
            "first_seen_utc": "2026-06-08 17:54:04",
            "last_seen_utc": "2026-06-29 13:27:13",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "c2,etherhiding,Polygon",
            "anonymous": "0",
            "reporter": "varysz"
        }
    ],
    "1825152": [
        {
            "ioc_value": "cosmostars.shop",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "unknown_stealer",
            "malware_alias": null,
            "malware_printable": "Unknown Stealer",
            "first_seen_utc": "2026-06-08 17:54:04",
            "last_seen_utc": "2026-06-29 13:26:54",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "c2,etherhiding,Polygon",
            "anonymous": "0",
            "reporter": "varysz"
        }
    ],
    "1825134": [
        {
            "ioc_value": "abrikos.xyz",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "unknown_stealer",
            "malware_alias": null,
            "malware_printable": "Unknown Stealer",
            "first_seen_utc": "2026-06-08 17:54:03",
            "last_seen_utc": "2026-06-29 13:34:39",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "c2,etherhiding,Polygon",
            "anonymous": "0",
            "reporter": "varysz"
        }
    ],
    "1825135": [
        {
            "ioc_value": "anakondabob.club",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "unknown_stealer",
            "malware_alias": null,
            "malware_printable": "Unknown Stealer",
            "first_seen_utc": "2026-06-08 17:54:03",
            "last_seen_utc": "2026-06-29 13:34:32",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "c2,etherhiding,Polygon",
            "anonymous": "0",
            "reporter": "varysz"
        }
    ],
    "1825136": [
        {
            "ioc_value": "ap7.supportly.au",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "unknown_stealer",
            "malware_alias": null,
            "malware_printable": "Unknown Stealer",
            "first_seen_utc": "2026-06-08 17:54:03",
            "last_seen_utc": "2026-06-29 13:37:32",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "c2,etherhiding,Polygon",
            "anonymous": "0",
            "reporter": "varysz"
        }
    ],
    "1825137": [
        {
            "ioc_value": "arigatodomen.sbs",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "unknown_stealer",
            "malware_alias": null,
            "malware_printable": "Unknown Stealer",
            "first_seen_utc": "2026-06-08 17:54:03",
            "last_seen_utc": "2026-06-29 13:26:48",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "c2,etherhiding,Polygon",
            "anonymous": "0",
            "reporter": "varysz"
        }
    ],
    "1825138": [
        {
            "ioc_value": "babybon.cfd",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "unknown_stealer",
            "malware_alias": null,
            "malware_printable": "Unknown Stealer",
            "first_seen_utc": "2026-06-08 17:54:03",
            "last_seen_utc": "2026-06-29 13:34:24",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "c2,etherhiding,Polygon",
            "anonymous": "0",
            "reporter": "varysz"
        }
    ],
    "1825139": [
        {
            "ioc_value": "bearman.bond",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "unknown_stealer",
            "malware_alias": null,
            "malware_printable": "Unknown Stealer",
            "first_seen_utc": "2026-06-08 17:54:03",
            "last_seen_utc": "2026-06-29 13:27:01",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "c2,etherhiding,Polygon",
            "anonymous": "0",
            "reporter": "varysz"
        }
    ],
    "1825140": [
        {
            "ioc_value": "bigbadwolf.click",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "unknown_stealer",
            "malware_alias": null,
            "malware_printable": "Unknown Stealer",
            "first_seen_utc": "2026-06-08 17:54:03",
            "last_seen_utc": "2026-06-29 13:35:31",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "c2,etherhiding,Polygon",
            "anonymous": "0",
            "reporter": "varysz"
        }
    ],
    "1825065": [
        {
            "ioc_value": "106.14.116.17:19443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-06-08 11:45:41",
            "last_seen_utc": "2026-06-30 10:46:32",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1824915": [
        {
            "ioc_value": "94.183.232.247:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.mirai",
            "malware_alias": "Katana",
            "malware_printable": "Mirai",
            "first_seen_utc": "2026-06-08 09:45:29",
            "last_seen_utc": "2026-06-30 10:46:18",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mirai",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1824913": [
        {
            "ioc_value": "89.125.255.5:43026",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.havoc",
            "malware_alias": "Havokiz",
            "malware_printable": "Havoc",
            "first_seen_utc": "2026-06-08 09:45:25",
            "last_seen_utc": "2026-06-30 10:46:14",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Havoc",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1824914": [
        {
            "ioc_value": "89.125.255.5:9999",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.havoc",
            "malware_alias": "Havokiz",
            "malware_printable": "Havoc",
            "first_seen_utc": "2026-06-08 09:45:25",
            "last_seen_utc": "2026-06-30 10:46:14",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Havoc",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1824912": [
        {
            "ioc_value": "87.237.52.176:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-06-08 09:45:24",
            "last_seen_utc": "2026-06-30 10:46:13",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1824910": [
        {
            "ioc_value": "182.23.2.163:3252",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-06-08 09:43:40",
            "last_seen_utc": "2026-06-30 10:43:57",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1824909": [
        {
            "ioc_value": "155.103.70.100:13408",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-06-08 09:43:22",
            "last_seen_utc": "2026-06-30 10:43:34",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1824638": [
        {
            "ioc_value": "altecva.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.iclickfix",
            "malware_alias": null,
            "malware_printable": "IClickFix",
            "first_seen_utc": "2026-06-08 08:02:09",
            "last_seen_utc": "2026-06-30 06:05:31",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": "",
            "tags": "ClickFix,compromised,etherhiding,Polygon",
            "anonymous": "0",
            "reporter": "varysz"
        }
    ],
    "1824646": [
        {
            "ioc_value": "camtechpotiskum.edu.ng",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.iclickfix",
            "malware_alias": null,
            "malware_printable": "IClickFix",
            "first_seen_utc": "2026-06-08 08:02:05",
            "last_seen_utc": "2026-06-30 06:03:07",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": "",
            "tags": "ClickFix,compromised,etherhiding,Polygon",
            "anonymous": "0",
            "reporter": "varysz"
        }
    ],
    "1824655": [
        {
            "ioc_value": "evolutionairfilter.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.iclickfix",
            "malware_alias": null,
            "malware_printable": "IClickFix",
            "first_seen_utc": "2026-06-08 08:01:59",
            "last_seen_utc": "2026-06-30 06:05:31",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": "",
            "tags": "ClickFix,compromised,etherhiding,Polygon",
            "anonymous": "0",
            "reporter": "varysz"
        }
    ],
    "1824672": [
        {
            "ioc_value": "stroycenter.net",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.iclickfix",
            "malware_alias": null,
            "malware_printable": "IClickFix",
            "first_seen_utc": "2026-06-08 08:01:50",
            "last_seen_utc": "2026-06-30 06:03:07",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": "",
            "tags": "ClickFix,compromised,etherhiding,Polygon",
            "anonymous": "0",
            "reporter": "varysz"
        }
    ],
    "1824673": [
        {
            "ioc_value": "thepesthunter.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.iclickfix",
            "malware_alias": null,
            "malware_printable": "IClickFix",
            "first_seen_utc": "2026-06-08 08:01:49",
            "last_seen_utc": "2026-06-30 06:03:09",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": "",
            "tags": "ClickFix,compromised,etherhiding,Polygon",
            "anonymous": "0",
            "reporter": "varysz"
        }
    ],
    "1824679": [
        {
            "ioc_value": "visualimpressao.com.br",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.iclickfix",
            "malware_alias": null,
            "malware_printable": "IClickFix",
            "first_seen_utc": "2026-06-08 08:01:47",
            "last_seen_utc": "2026-06-30 06:03:08",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": "",
            "tags": "ClickFix,compromised,etherhiding,Polygon",
            "anonymous": "0",
            "reporter": "varysz"
        }
    ],
    "1824680": [
        {
            "ioc_value": "vitb.ac.in",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.iclickfix",
            "malware_alias": null,
            "malware_printable": "IClickFix",
            "first_seen_utc": "2026-06-08 07:54:40",
            "last_seen_utc": "2026-06-30 06:05:29",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": "",
            "tags": "ClickFix,compromised,etherhiding,Polygon",
            "anonymous": "0",
            "reporter": "varysz"
        }
    ],
    "1824383": [
        {
            "ioc_value": "antongandon.club",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.deerstealer",
            "malware_alias": null,
            "malware_printable": "DeerStealer",
            "first_seen_utc": "2026-06-08 03:34:45",
            "last_seen_utc": "2026-06-29 13:37:50",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": null,
            "anonymous": "0",
            "reporter": "uwucutecatgirl"
        }
    ],
    "1824508": [
        {
            "ioc_value": "209.200.246.194:17568",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-06-07 23:45:14",
            "last_seen_utc": "2026-06-30 10:46:57",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1824436": [
        {
            "ioc_value": "87.107.191.39:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-06-07 19:45:57",
            "last_seen_utc": "2026-06-30 10:47:19",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1824435": [
        {
            "ioc_value": "94.183.232.247:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.mirai",
            "malware_alias": "Katana",
            "malware_printable": "Mirai",
            "first_seen_utc": "2026-06-07 19:45:13",
            "last_seen_utc": "2026-06-30 10:46:17",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mirai",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1824434": [
        {
            "ioc_value": "93.127.141.93:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "apk.hook",
            "malware_alias": null,
            "malware_printable": "Hook",
            "first_seen_utc": "2026-06-07 19:45:12",
            "last_seen_utc": "2026-06-30 10:46:17",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Hook",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1824433": [
        {
            "ioc_value": "82.156.224.184:8080",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.havoc",
            "malware_alias": "Havokiz",
            "malware_printable": "Havoc",
            "first_seen_utc": "2026-06-07 19:45:00",
            "last_seen_utc": "2026-06-30 10:46:08",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Havoc",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1824432": [
        {
            "ioc_value": "52.90.29.87:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.havoc",
            "malware_alias": "Havokiz",
            "malware_printable": "Havoc",
            "first_seen_utc": "2026-06-07 19:44:52",
            "last_seen_utc": "2026-06-30 10:45:54",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Havoc",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1824431": [
        {
            "ioc_value": "46.246.96.214:8082",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.havoc",
            "malware_alias": "Havokiz",
            "malware_printable": "Havoc",
            "first_seen_utc": "2026-06-07 19:44:43",
            "last_seen_utc": "2026-06-30 10:45:45",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Havoc",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1824430": [
        {
            "ioc_value": "45.38.20.122:8989",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-06-07 19:44:40",
            "last_seen_utc": "2026-06-30 10:45:39",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1824429": [
        {
            "ioc_value": "40.83.75.96:4000",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.havoc",
            "malware_alias": "Havokiz",
            "malware_printable": "Havoc",
            "first_seen_utc": "2026-06-07 19:44:35",
            "last_seen_utc": "2026-06-30 10:45:31",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Havoc",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1824428": [
        {
            "ioc_value": "209.99.185.96:20100",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-06-07 19:43:55",
            "last_seen_utc": "2026-06-30 10:44:33",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1824427": [
        {
            "ioc_value": "182.23.2.163:8211",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-06-07 19:43:38",
            "last_seen_utc": "2026-06-30 10:43:59",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1824426": [
        {
            "ioc_value": "172.189.57.198:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.havoc",
            "malware_alias": "Havokiz",
            "malware_printable": "Havoc",
            "first_seen_utc": "2026-06-07 19:43:30",
            "last_seen_utc": "2026-06-30 10:43:47",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Havoc",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1824397": [
        {
            "ioc_value": "npanssltejs.beer",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-07 16:19:10",
            "last_seen_utc": "2026-06-29 13:33:02",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "ClearFake,Polygon",
            "anonymous": "0",
            "reporter": "varysz"
        }
    ],
    "1824262": [
        {
            "ioc_value": "89.125.255.5:4321",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-06-07 09:45:38",
            "last_seen_utc": "2026-06-30 10:46:14",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1824260": [
        {
            "ioc_value": "80.253.249.67:2404",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-06-07 09:45:31",
            "last_seen_utc": "2026-06-30 10:46:07",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1824261": [
        {
            "ioc_value": "80.66.72.174:8080",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-06-07 09:45:31",
            "last_seen_utc": "2026-06-30 10:46:07",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1824259": [
        {
            "ioc_value": "60.191.87.107:4506",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.deimos_c2",
            "malware_alias": null,
            "malware_printable": "DeimosC2",
            "first_seen_utc": "2026-06-07 09:45:24",
            "last_seen_utc": "2026-06-30 10:45:56",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "Deimos,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1824258": [
        {
            "ioc_value": "45.13.212.232:4321",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-06-07 09:44:59",
            "last_seen_utc": "2026-06-30 10:45:35",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1824256": [
        {
            "ioc_value": "43.136.92.170:31337",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.sliver",
            "malware_alias": null,
            "malware_printable": "Sliver",
            "first_seen_utc": "2026-06-07 09:44:57",
            "last_seen_utc": "2026-06-30 10:45:33",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Sliver",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1824257": [
        {
            "ioc_value": "43.136.92.170:8443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.sliver",
            "malware_alias": null,
            "malware_printable": "Sliver",
            "first_seen_utc": "2026-06-07 09:44:57",
            "last_seen_utc": "2026-06-30 10:45:33",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Sliver",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1824255": [
        {
            "ioc_value": "31.57.184.154:2505",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-06-07 09:44:50",
            "last_seen_utc": "2026-06-30 10:45:23",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1824254": [
        {
            "ioc_value": "209.99.188.193:4323",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-06-07 09:44:10",
            "last_seen_utc": "2026-06-30 10:44:34",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1824253": [
        {
            "ioc_value": "182.23.2.163:17001",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-06-07 09:43:45",
            "last_seen_utc": "2026-06-30 10:43:57",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1824252": [
        {
            "ioc_value": "172.81.61.108:2030",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-06-07 09:43:38",
            "last_seen_utc": "2026-06-30 10:43:49",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1824251": [
        {
            "ioc_value": "154.94.232.165:4321",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-06-07 09:43:26",
            "last_seen_utc": "2026-06-30 10:43:33",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1824249": [
        {
            "ioc_value": "146.70.41.174:3000",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.evilginx",
            "malware_alias": null,
            "malware_printable": "Evilginx",
            "first_seen_utc": "2026-06-07 09:43:23",
            "last_seen_utc": "2026-06-30 10:43:28",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Evilginx,EvilGoPhish",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1824250": [
        {
            "ioc_value": "147.124.210.158:7707",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-06-07 09:43:23",
            "last_seen_utc": "2026-06-30 10:43:28",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1824248": [
        {
            "ioc_value": "138.9.118.222:8015",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-06-07 09:43:17",
            "last_seen_utc": "2026-06-30 10:43:23",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1824247": [
        {
            "ioc_value": "137.184.163.27:5613",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-06-07 09:43:16",
            "last_seen_utc": "2026-06-30 10:43:22",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1824151": [
        {
            "ioc_value": "154.198.49.31:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-06-06 22:45:25",
            "last_seen_utc": "2026-06-30 10:46:47",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1824136": [
        {
            "ioc_value": "173.249.41.141:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.havoc",
            "malware_alias": "Havokiz",
            "malware_printable": "Havoc",
            "first_seen_utc": "2026-06-06 20:00:20",
            "last_seen_utc": "2026-06-30 10:43:51",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "havoc",
            "anonymous": "1",
            "reporter": "_ik_"
        }
    ],
    "1824135": [
        {
            "ioc_value": "13.140.132.118:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.havoc",
            "malware_alias": "Havokiz",
            "malware_printable": "Havoc",
            "first_seen_utc": "2026-06-06 20:00:19",
            "last_seen_utc": "2026-06-30 10:43:20",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "havoc",
            "anonymous": "1",
            "reporter": "_ik_"
        }
    ],
    "1824134": [
        {
            "ioc_value": "95.211.182.120:6794",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-06-06 19:44:54",
            "last_seen_utc": "2026-06-30 10:46:18",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1824133": [
        {
            "ioc_value": "91.221.191.167:4323",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-06-06 19:44:51",
            "last_seen_utc": "2026-06-30 10:46:16",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1824132": [
        {
            "ioc_value": "5.230.201.36:6606",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-06-06 19:44:38",
            "last_seen_utc": "2026-06-30 10:45:52",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1824131": [
        {
            "ioc_value": "5.230.201.242:1994",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.dcrat",
            "malware_alias": "DarkCrystal RAT",
            "malware_printable": "DCRat",
            "first_seen_utc": "2026-06-06 19:44:37",
            "last_seen_utc": "2026-06-30 10:45:52",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DCRat,drb-ra,RAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1824130": [
        {
            "ioc_value": "46.151.182.243:55380",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.dcrat",
            "malware_alias": "DarkCrystal RAT",
            "malware_printable": "DCRat",
            "first_seen_utc": "2026-06-06 19:44:30",
            "last_seen_utc": "2026-06-30 10:45:44",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DCRat,drb-ra,RAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1824129": [
        {
            "ioc_value": "2.26.75.239:1971",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-06-06 19:43:45",
            "last_seen_utc": "2026-06-30 10:44:25",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1824127": [
        {
            "ioc_value": "192.159.99.26:6969",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-06-06 19:43:40",
            "last_seen_utc": "2026-06-30 10:44:13",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1824128": [
        {
            "ioc_value": "192.177.111.89:7788",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-06-06 19:43:40",
            "last_seen_utc": "2026-06-30 10:44:14",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1824126": [
        {
            "ioc_value": "185.192.124.218:2177",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.dcrat",
            "malware_alias": "DarkCrystal RAT",
            "malware_printable": "DCRat",
            "first_seen_utc": "2026-06-06 19:43:35",
            "last_seen_utc": "2026-06-30 10:44:05",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DCRat,drb-ra,RAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1824125": [
        {
            "ioc_value": "158.94.211.253:7777",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.dcrat",
            "malware_alias": "DarkCrystal RAT",
            "malware_printable": "DCRat",
            "first_seen_utc": "2026-06-06 19:43:22",
            "last_seen_utc": "2026-06-30 10:43:39",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DCRat,drb-ra,RAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1824124": [
        {
            "ioc_value": "157.254.223.135:2600",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-06-06 19:43:21",
            "last_seen_utc": "2026-06-30 10:43:38",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1824123": [
        {
            "ioc_value": "156.225.22.201:1337",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-06-06 19:43:19",
            "last_seen_utc": "2026-06-30 10:43:36",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1824029": [
        {
            "ioc_value": "154.12.86.154:55555",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-06-06 11:45:14",
            "last_seen_utc": "2026-06-30 10:46:47",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1824030": [
        {
            "ioc_value": "154.12.86.154:8889",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-06-06 11:45:14",
            "last_seen_utc": "2026-06-30 10:46:47",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1824031": [
        {
            "ioc_value": "154.12.86.154:9004",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-06-06 11:45:14",
            "last_seen_utc": "2026-06-30 10:46:47",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1824012": [
        {
            "ioc_value": "47.101.51.235:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-06-06 10:32:30",
            "last_seen_utc": "2026-06-30 10:47:07",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-666666",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1824008": [
        {
            "ioc_value": "167.71.233.187:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-06-06 10:32:23",
            "last_seen_utc": "2026-06-30 10:46:51",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-987654321",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1824001": [
        {
            "ioc_value": "91.215.85.121:8849",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.dcrat",
            "malware_alias": "DarkCrystal RAT",
            "malware_printable": "DCRat",
            "first_seen_utc": "2026-06-06 09:44:56",
            "last_seen_utc": "2026-06-30 10:46:16",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DCRat,drb-ra,RAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1823978": [
        {
            "ioc_value": "113.45.226.61:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-06-06 09:00:18",
            "last_seen_utc": "2026-06-30 10:46:35",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "cobaltstrike",
            "anonymous": "1",
            "reporter": "_ik_"
        }
    ],
    "1823974": [
        {
            "ioc_value": "188.126.90.12:2003",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.dcrat",
            "malware_alias": "DarkCrystal RAT",
            "malware_printable": "DCRat",
            "first_seen_utc": "2026-06-06 09:00:14",
            "last_seen_utc": "2026-06-30 10:44:11",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "dcrat",
            "anonymous": "1",
            "reporter": "_ik_"
        }
    ],
    "1823700": [
        {
            "ioc_value": "45.81.17.44:8808",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-06-06 06:01:08",
            "last_seen_utc": "2026-06-30 10:45:42",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": null,
            "tags": "211056,asyncrat,c2,censys",
            "anonymous": "0",
            "reporter": "sojubear"
        }
    ],
    "1823853": [
        {
            "ioc_value": "https://pas.sm188star.top/",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-06-06 05:24:31",
            "last_seen_utc": "2026-06-30 11:24:15",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "ar3k0,Vidar",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1823854": [
        {
            "ioc_value": "pas.sm188star.top",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-06-06 05:24:31",
            "last_seen_utc": "2026-06-30 11:24:15",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "ar3k0,Vidar",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1823730": [
        {
            "ioc_value": "101.43.103.154:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-06-06 03:44:58",
            "last_seen_utc": "2026-06-30 10:46:31",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1823661": [
        {
            "ioc_value": "149.104.29.125:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-06-05 21:00:16",
            "last_seen_utc": "2026-06-30 10:46:46",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "cobaltstrike",
            "anonymous": "1",
            "reporter": "_ik_"
        }
    ],
    "1823644": [
        {
            "ioc_value": "87.107.191.39:53",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-06-05 19:45:55",
            "last_seen_utc": "2026-06-30 10:47:19",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1823641": [
        {
            "ioc_value": "ns1.newchatsits.ir",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-06-05 19:45:18",
            "last_seen_utc": "2026-06-30 10:46:25",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1823640": [
        {
            "ioc_value": "62.109.19.44:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.havoc",
            "malware_alias": "Havokiz",
            "malware_printable": "Havoc",
            "first_seen_utc": "2026-06-05 19:44:53",
            "last_seen_utc": "2026-06-30 10:45:57",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Havoc",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1823639": [
        {
            "ioc_value": "207.174.2.85:7997",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.dcrat",
            "malware_alias": "DarkCrystal RAT",
            "malware_printable": "DCRat",
            "first_seen_utc": "2026-06-05 19:43:56",
            "last_seen_utc": "2026-06-30 10:44:30",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DCRat,drb-ra,RAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1823638": [
        {
            "ioc_value": "182.23.2.163:12364",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-06-05 19:43:38",
            "last_seen_utc": "2026-06-30 10:43:56",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1822772": [
        {
            "ioc_value": "119.45.166.6:9443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-06-05 09:46:05",
            "last_seen_utc": "2026-06-30 10:46:40",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1822771": [
        {
            "ioc_value": "64.94.85.14:4321",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-06-05 09:45:27",
            "last_seen_utc": "2026-06-30 10:46:01",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1822770": [
        {
            "ioc_value": "5.249.160.112:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-06-05 09:45:20",
            "last_seen_utc": "2026-06-30 10:45:53",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1822769": [
        {
            "ioc_value": "195.26.86.134:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-06-05 09:44:00",
            "last_seen_utc": "2026-06-30 10:44:21",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1822768": [
        {
            "ioc_value": "193.149.190.156:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-06-05 09:43:56",
            "last_seen_utc": "2026-06-30 10:44:16",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1822767": [
        {
            "ioc_value": "182.23.2.163:58222",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-06-05 09:43:46",
            "last_seen_utc": "2026-06-30 10:43:59",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1822765": [
        {
            "ioc_value": "182.23.2.163:10401",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-06-05 09:43:44",
            "last_seen_utc": "2026-06-30 10:43:55",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1822766": [
        {
            "ioc_value": "182.23.2.163:11742",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-06-05 09:43:44",
            "last_seen_utc": "2026-06-30 10:43:56",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1822764": [
        {
            "ioc_value": "158.247.194.144:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.havoc",
            "malware_alias": "Havokiz",
            "malware_printable": "Havoc",
            "first_seen_utc": "2026-06-05 09:43:29",
            "last_seen_utc": "2026-06-30 10:43:39",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Havoc",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1822558": [
        {
            "ioc_value": "104.236.83.40:2375",
            "ioc_type": "ip:port",
            "threat_type": "payload_delivery",
            "malware": "elf.redtail",
            "malware_alias": null,
            "malware_printable": "RedTail",
            "first_seen_utc": "2026-06-05 05:19:16",
            "last_seen_utc": "2026-06-28 21:16:04",
            "confidence_level": 80,
            "is_compromised": false,
            "reference": "https://twitter.com/NullBlue67",
            "tags": "DigitalOcean,docker-api,dual-role,libredtail-http,Redtail,spreader",
            "anonymous": "0",
            "reporter": "nullblue67"
        }
    ],
    "1822567": [
        {
            "ioc_value": "b0e1ae6d73d656b203514f498b59cbcf29f067edf6fbd3803a3de7d21960848d",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "elf.xmrig",
            "malware_alias": null,
            "malware_printable": "XMRIG",
            "first_seen_utc": "2026-06-05 05:19:11",
            "last_seen_utc": "2026-06-29 15:50:31",
            "confidence_level": 80,
            "is_compromised": false,
            "reference": "https://twitter.com/NullBlue67",
            "tags": "cryptojacking,docker-api,elf,miner,XMRig",
            "anonymous": "0",
            "reporter": "nullblue67"
        }
    ],
    "1822643": [
        {
            "ioc_value": "186.169.71.201:6000",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-06-05 03:00:15",
            "last_seen_utc": "2026-06-30 10:44:10",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "asyncrat",
            "anonymous": "1",
            "reporter": "_ik_"
        }
    ],
    "1822640": [
        {
            "ioc_value": "89.124.78.101:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.amadey",
            "malware_alias": null,
            "malware_printable": "Amadey",
            "first_seen_utc": "2026-06-05 02:36:02",
            "last_seen_utc": "2026-06-30 11:24:04",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": "https://tracker.viriback.com/index.php?q=89.124.78.101",
            "tags": "Amadey,ViriBack",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1822613": [
        {
            "ioc_value": "5.230.201.36:8808",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-06-05 01:00:17",
            "last_seen_utc": "2026-06-30 10:45:53",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "asyncrat",
            "anonymous": "1",
            "reporter": "_ik_"
        }
    ],
    "1822602": [
        {
            "ioc_value": "185.165.36.162:5000",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-06-05 00:00:22",
            "last_seen_utc": "2026-06-30 10:44:04",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "asyncrat",
            "anonymous": "1",
            "reporter": "_ik_"
        }
    ],
    "1822600": [
        {
            "ioc_value": "34.202.161.96:53",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-06-04 23:45:28",
            "last_seen_utc": "2026-06-30 10:46:58",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1822599": [
        {
            "ioc_value": "updates.fisgloval.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-06-04 23:45:07",
            "last_seen_utc": "2026-06-30 10:46:28",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1822528": [
        {
            "ioc_value": "182.23.2.163:2046",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-06-04 19:43:37",
            "last_seen_utc": "2026-06-30 10:43:57",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1822526": [
        {
            "ioc_value": "163.172.174.237:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.brute_ratel_c4",
            "malware_alias": "BOLDBADGER,BruteRatel",
            "malware_printable": "Brute Ratel C4",
            "first_seen_utc": "2026-06-04 19:43:27",
            "last_seen_utc": "2026-06-30 10:43:42",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "BruteRatel,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1822527": [
        {
            "ioc_value": "163.172.174.237:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.brute_ratel_c4",
            "malware_alias": "BOLDBADGER,BruteRatel",
            "malware_printable": "Brute Ratel C4",
            "first_seen_utc": "2026-06-04 19:43:27",
            "last_seen_utc": "2026-06-30 10:43:43",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "BruteRatel,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1822515": [
        {
            "ioc_value": "185.165.36.162:8000",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-06-04 19:00:14",
            "last_seen_utc": "2026-06-30 10:44:04",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "asyncrat",
            "anonymous": "1",
            "reporter": "_ik_"
        }
    ],
    "1822499": [
        {
            "ioc_value": "107.150.105.91:8443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-06-04 17:45:22",
            "last_seen_utc": "2026-06-30 10:46:32",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1822488": [
        {
            "ioc_value": "20.64.242.233:1024",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.dcrat",
            "malware_alias": "DarkCrystal RAT",
            "malware_printable": "DCRat",
            "first_seen_utc": "2026-06-04 17:00:13",
            "last_seen_utc": "2026-06-30 10:44:27",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "dcrat",
            "anonymous": "1",
            "reporter": "_ik_"
        }
    ],
    "1822451": [
        {
            "ioc_value": "124.222.155.113:8443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-06-04 15:45:34",
            "last_seen_utc": "2026-06-30 10:46:43",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1822448": [
        {
            "ioc_value": "api1.haedalcompany.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-06-04 15:45:16",
            "last_seen_utc": "2026-06-30 10:46:21",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1822415": [
        {
            "ioc_value": "120.26.208.96:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-06-04 14:50:35",
            "last_seen_utc": "2026-06-30 10:46:40",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": "",
            "tags": "Agentemis,BEACON,Cobalt Strike,CobaltStrike,cobeacon",
            "anonymous": "0",
            "reporter": "whoamix302"
        }
    ],
    "1822346": [
        {
            "ioc_value": "154.12.86.154:44444",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-06-04 11:46:46",
            "last_seen_utc": "2026-06-30 10:46:47",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1822302": [
        {
            "ioc_value": "91.92.241.80:8848",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.dcrat",
            "malware_alias": "DarkCrystal RAT",
            "malware_printable": "DCRat",
            "first_seen_utc": "2026-06-04 09:45:43",
            "last_seen_utc": "2026-06-30 10:46:17",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DCRat,drb-ra,RAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1822301": [
        {
            "ioc_value": "82.23.246.160:8848",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.dcrat",
            "malware_alias": "DarkCrystal RAT",
            "malware_printable": "DCRat",
            "first_seen_utc": "2026-06-04 09:45:35",
            "last_seen_utc": "2026-06-30 10:46:09",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DCRat,drb-ra,RAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1822299": [
        {
            "ioc_value": "185.72.9.227:8848",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.dcrat",
            "malware_alias": "DarkCrystal RAT",
            "malware_printable": "DCRat",
            "first_seen_utc": "2026-06-04 09:43:56",
            "last_seen_utc": "2026-06-30 10:44:10",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DCRat,drb-ra,RAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1822298": [
        {
            "ioc_value": "182.23.2.163:49002",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-06-04 09:43:50",
            "last_seen_utc": "2026-06-30 10:43:58",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1822297": [
        {
            "ioc_value": "172.238.15.96:9443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.netsupportmanager_rat",
            "malware_alias": "NetSupport",
            "malware_printable": "NetSupportManager RAT",
            "first_seen_utc": "2026-06-04 09:43:40",
            "last_seen_utc": "2026-06-30 10:43:48",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,NetSupport,RAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1822296": [
        {
            "ioc_value": "156.247.40.190:8848",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.dcrat",
            "malware_alias": "DarkCrystal RAT",
            "malware_printable": "DCRat",
            "first_seen_utc": "2026-06-04 09:43:29",
            "last_seen_utc": "2026-06-30 10:43:36",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DCRat,drb-ra,RAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1822295": [
        {
            "ioc_value": "155.103.70.198:13408",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-06-04 09:43:28",
            "last_seen_utc": "2026-06-30 10:43:35",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1822294": [
        {
            "ioc_value": "140.235.16.223:7203",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.dcrat",
            "malware_alias": "DarkCrystal RAT",
            "malware_printable": "DCRat",
            "first_seen_utc": "2026-06-04 09:43:22",
            "last_seen_utc": "2026-06-30 10:43:24",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DCRat,drb-ra,RAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1822223": [
        {
            "ioc_value": "107.150.105.91:8080",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-06-04 06:42:46",
            "last_seen_utc": "2026-06-30 10:46:32",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-666666666",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1822222": [
        {
            "ioc_value": "204.194.49.142:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-06-04 06:42:44",
            "last_seen_utc": "2026-06-30 09:53:54",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-666666666",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1822015": [
        {
            "ioc_value": "20.220.29.224:8443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.havoc",
            "malware_alias": "Havokiz",
            "malware_printable": "Havoc",
            "first_seen_utc": "2026-06-03 19:44:00",
            "last_seen_utc": "2026-06-30 10:44:27",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Havoc",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1822014": [
        {
            "ioc_value": "194.26.192.57:1024",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.dcrat",
            "malware_alias": "DarkCrystal RAT",
            "malware_printable": "DCRat",
            "first_seen_utc": "2026-06-03 19:43:56",
            "last_seen_utc": "2026-06-30 10:44:19",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DCRat,drb-ra,RAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1822013": [
        {
            "ioc_value": "182.23.2.163:47984",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-06-03 19:43:43",
            "last_seen_utc": "2026-06-30 10:43:58",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1822012": [
        {
            "ioc_value": "172.81.61.20:7997",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.dcrat",
            "malware_alias": "DarkCrystal RAT",
            "malware_printable": "DCRat",
            "first_seen_utc": "2026-06-03 19:43:36",
            "last_seen_utc": "2026-06-30 10:43:49",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DCRat,drb-ra,RAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1822011": [
        {
            "ioc_value": "168.144.36.228:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-06-03 19:43:33",
            "last_seen_utc": "2026-06-30 10:43:46",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1822010": [
        {
            "ioc_value": "147.124.210.158:8808",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-06-03 19:43:21",
            "last_seen_utc": "2026-06-30 10:43:28",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1821844": [
        {
            "ioc_value": "47.82.234.12:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-06-03 15:23:52",
            "last_seen_utc": "2026-06-30 10:47:11",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "cobaltstrike",
            "anonymous": "1",
            "reporter": "_ik_"
        }
    ],
    "1821877": [
        {
            "ioc_value": "4.240.85.243:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-06-03 14:36:55",
            "last_seen_utc": "2026-06-30 10:45:31",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": "https://www.shodan.io/host/4.240.85.243#7443",
            "tags": "c2,mythic,shodan",
            "anonymous": "0",
            "reporter": "juroots"
        }
    ],
    "1821870": [
        {
            "ioc_value": "62.192.173.249:9000",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-06-03 14:34:08",
            "last_seen_utc": "2026-06-30 10:45:57",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": "https://www.shodan.io/host/62.192.173.249#9000",
            "tags": "adaptixc2,c2,shodan",
            "anonymous": "0",
            "reporter": "juroots"
        }
    ],
    "1821850": [
        {
            "ioc_value": "114.134.187.38:8443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-06-03 14:31:44",
            "last_seen_utc": "2026-06-30 10:46:35",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": "https://www.shodan.io/host/114.134.187.38#8443",
            "tags": "c2,cobaltstrike,cs-watermark-987654321,shodan",
            "anonymous": "0",
            "reporter": "juroots"
        }
    ],
    "1821807": [
        {
            "ioc_value": "209.200.246.194:11544",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-06-03 11:46:25",
            "last_seen_utc": "2026-06-30 10:46:57",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1821716": [
        {
            "ioc_value": "82.23.246.160:12159",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.dcrat",
            "malware_alias": "DarkCrystal RAT",
            "malware_printable": "DCRat",
            "first_seen_utc": "2026-06-03 09:45:37",
            "last_seen_utc": "2026-06-30 10:46:09",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DCRat,drb-ra,RAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1821715": [
        {
            "ioc_value": "204.194.50.173:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-06-03 09:44:13",
            "last_seen_utc": "2026-06-30 10:44:28",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1821714": [
        {
            "ioc_value": "182.23.2.163:10399",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-06-03 09:43:49",
            "last_seen_utc": "2026-06-30 10:43:55",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1821713": [
        {
            "ioc_value": "156.247.40.190:12159",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.dcrat",
            "malware_alias": "DarkCrystal RAT",
            "malware_printable": "DCRat",
            "first_seen_utc": "2026-06-03 09:43:30",
            "last_seen_utc": "2026-06-30 10:43:36",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DCRat,drb-ra,RAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1821684": [
        {
            "ioc_value": "77.93.155.111:10039",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-06-03 08:01:52",
            "last_seen_utc": "2026-06-30 10:46:05",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "mythic",
            "anonymous": "1",
            "reporter": "_ik_"
        }
    ],
    "1821685": [
        {
            "ioc_value": "124.222.155.113:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-06-03 08:01:51",
            "last_seen_utc": "2026-06-30 10:46:43",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "cobaltstrike",
            "anonymous": "1",
            "reporter": "_ik_"
        }
    ],
    "1821697": [
        {
            "ioc_value": "118.89.203.103:9999",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-06-03 07:57:06",
            "last_seen_utc": "2026-06-30 10:46:39",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-987654321",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1821695": [
        {
            "ioc_value": "118.89.203.103:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-06-03 07:56:52",
            "last_seen_utc": "2026-06-30 10:46:39",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-987654321",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1821525": [
        {
            "ioc_value": "8.163.104.36:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-06-03 05:55:36",
            "last_seen_utc": "2026-06-30 10:47:17",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "",
            "tags": "Agentemis,BEACON,Cobalt Strike,CobaltStrike,cobeacon",
            "anonymous": "0",
            "reporter": "whoamix302"
        }
    ],
    "1821517": [
        {
            "ioc_value": "45.198.224.19:4321",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-06-02 19:45:08",
            "last_seen_utc": "2026-06-30 10:45:37",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1821516": [
        {
            "ioc_value": "195.246.230.99:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-06-02 19:44:03",
            "last_seen_utc": "2026-06-30 10:44:20",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1821514": [
        {
            "ioc_value": "155.103.70.198:13407",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-06-02 19:43:27",
            "last_seen_utc": "2026-06-30 10:43:34",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1821515": [
        {
            "ioc_value": "155.103.71.115:13408",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-06-02 19:43:27",
            "last_seen_utc": "2026-06-30 10:43:35",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1821233": [
        {
            "ioc_value": "172.236.10.250:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.havoc",
            "malware_alias": "Havokiz",
            "malware_printable": "Havoc",
            "first_seen_utc": "2026-06-02 14:06:11",
            "last_seen_utc": "2026-06-30 10:43:47",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": "https://www.shodan.io/host/172.236.10.250#443",
            "tags": "c2,havoc,shodan",
            "anonymous": "0",
            "reporter": "juroots"
        }
    ],
    "1821227": [
        {
            "ioc_value": "198.13.51.245:4321",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-06-02 14:05:08",
            "last_seen_utc": "2026-06-30 10:44:21",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": "https://www.shodan.io/host/198.13.51.245#4321",
            "tags": "adaptixc2,c2,shodan",
            "anonymous": "0",
            "reporter": "juroots"
        }
    ],
    "1821219": [
        {
            "ioc_value": "172.237.125.146:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-06-02 14:04:11",
            "last_seen_utc": "2026-06-30 10:43:47",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": "https://www.shodan.io/host/172.237.125.146#7443",
            "tags": "c2,mythic,shodan",
            "anonymous": "0",
            "reporter": "juroots"
        }
    ],
    "1821220": [
        {
            "ioc_value": "45.76.203.112:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-06-02 14:04:11",
            "last_seen_utc": "2026-06-30 10:45:41",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": "https://www.shodan.io/host/45.76.203.112#7443",
            "tags": "c2,mythic,shodan",
            "anonymous": "0",
            "reporter": "juroots"
        }
    ],
    "1820869": [
        {
            "ioc_value": "113.44.136.127:8087",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-06-02 09:46:15",
            "last_seen_utc": "2026-06-30 10:46:35",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1820868": [
        {
            "ioc_value": "192.159.99.21:5080",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-06-02 09:43:59",
            "last_seen_utc": "2026-06-30 10:44:13",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1820867": [
        {
            "ioc_value": "182.23.2.163:9060",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-06-02 09:43:50",
            "last_seen_utc": "2026-06-30 10:44:00",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1820866": [
        {
            "ioc_value": "15.204.255.172:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-06-02 09:43:26",
            "last_seen_utc": "2026-06-30 10:43:31",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1820682": [
        {
            "ioc_value": "47.77.182.54:2375",
            "ioc_type": "ip:port",
            "threat_type": "payload_delivery",
            "malware": "elf.redtail",
            "malware_alias": null,
            "malware_printable": "RedTail",
            "first_seen_utc": "2026-06-01 20:49:34",
            "last_seen_utc": "2026-06-28 21:16:44",
            "confidence_level": 80,
            "is_compromised": false,
            "reference": "https://twitter.com/NullBlue67",
            "tags": "docker-api,libredtail-http,Redtail,spreader",
            "anonymous": "0",
            "reporter": "nullblue67"
        }
    ],
    "1820729": [
        {
            "ioc_value": "23.235.185.43:8848",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.dcrat",
            "malware_alias": "DarkCrystal RAT",
            "malware_printable": "DCRat",
            "first_seen_utc": "2026-06-01 20:49:15",
            "last_seen_utc": "2026-06-30 10:45:19",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "dcrat",
            "anonymous": "1",
            "reporter": "_ik_"
        }
    ],
    "1820730": [
        {
            "ioc_value": "23.235.185.42:8848",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.dcrat",
            "malware_alias": "DarkCrystal RAT",
            "malware_printable": "DCRat",
            "first_seen_utc": "2026-06-01 20:49:15",
            "last_seen_utc": "2026-06-30 10:45:19",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "dcrat",
            "anonymous": "1",
            "reporter": "_ik_"
        }
    ],
    "1820725": [
        {
            "ioc_value": "45.150.34.117:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.havoc",
            "malware_alias": "Havokiz",
            "malware_printable": "Havoc",
            "first_seen_utc": "2026-06-01 19:45:00",
            "last_seen_utc": "2026-06-30 10:45:36",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Havoc",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1820724": [
        {
            "ioc_value": "182.23.2.163:11166",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-06-01 19:43:44",
            "last_seen_utc": "2026-06-30 10:43:55",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1820723": [
        {
            "ioc_value": "178.16.54.48:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.eye_pyramid",
            "malware_alias": null,
            "malware_printable": "Eye Pyramid",
            "first_seen_utc": "2026-06-01 19:43:43",
            "last_seen_utc": "2026-06-30 10:43:53",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,EyePyramid",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1820722": [
        {
            "ioc_value": "178.16.52.47:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.eye_pyramid",
            "malware_alias": null,
            "malware_printable": "Eye Pyramid",
            "first_seen_utc": "2026-06-01 19:43:42",
            "last_seen_utc": "2026-06-30 10:43:53",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,EyePyramid",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1820615": [
        {
            "ioc_value": "82.156.224.184:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.havoc",
            "malware_alias": "Havokiz",
            "malware_printable": "Havoc",
            "first_seen_utc": "2026-06-01 15:11:43",
            "last_seen_utc": "2026-06-30 10:46:08",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "havoc",
            "anonymous": "1",
            "reporter": "_ik_"
        }
    ],
    "1820574": [
        {
            "ioc_value": "35.75.218.153:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.brute_ratel_c4",
            "malware_alias": "BOLDBADGER,BruteRatel",
            "malware_printable": "Brute Ratel C4",
            "first_seen_utc": "2026-06-01 09:45:05",
            "last_seen_utc": "2026-06-30 10:45:28",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "BruteRatel,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1820573": [
        {
            "ioc_value": "2.58.56.50:2404",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-06-01 09:44:09",
            "last_seen_utc": "2026-06-30 10:44:26",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1820572": [
        {
            "ioc_value": "182.23.2.163:11327",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-06-01 09:43:48",
            "last_seen_utc": "2026-06-30 10:43:56",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1820571": [
        {
            "ioc_value": "176.65.139.144:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.mirai",
            "malware_alias": "Katana",
            "malware_printable": "Mirai",
            "first_seen_utc": "2026-06-01 09:43:44",
            "last_seen_utc": "2026-06-30 10:43:52",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mirai",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1820538": [
        {
            "ioc_value": "43.138.165.203:9001",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-06-01 08:43:25",
            "last_seen_utc": "2026-06-30 10:47:01",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "cobaltstrike",
            "anonymous": "1",
            "reporter": "_ik_"
        }
    ],
    "1820506": [
        {
            "ioc_value": "165.22.225.218:5443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-06-01 06:44:52",
            "last_seen_utc": "2026-06-30 10:46:51",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-987654321",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1820504": [
        {
            "ioc_value": "38.181.42.160:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-06-01 06:44:48",
            "last_seen_utc": "2026-06-30 10:46:59",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-666666666",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1820414": [
        {
            "ioc_value": "82.157.52.180:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-06-01 05:44:49",
            "last_seen_utc": "2026-06-30 10:47:19",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "cobaltstrike",
            "anonymous": "1",
            "reporter": "_ik_"
        }
    ],
    "1820430": [
        {
            "ioc_value": "49.233.215.164:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-06-01 05:44:38",
            "last_seen_utc": "2026-06-30 10:47:13",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "cobaltstrike",
            "anonymous": "1",
            "reporter": "_ik_"
        }
    ],
    "1820432": [
        {
            "ioc_value": "47.116.211.215:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-06-01 05:44:37",
            "last_seen_utc": "2026-06-30 10:47:09",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "cobaltstrike",
            "anonymous": "1",
            "reporter": "_ik_"
        }
    ],
    "1820444": [
        {
            "ioc_value": "47.103.95.85:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-06-01 05:44:35",
            "last_seen_utc": "2026-06-30 10:47:08",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "cobaltstrike",
            "anonymous": "1",
            "reporter": "_ik_"
        }
    ],
    "1820420": [
        {
            "ioc_value": "176.97.124.68:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-05-31 23:46:09",
            "last_seen_utc": "2026-06-30 10:46:52",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1820399": [
        {
            "ioc_value": "176.97.124.68:53",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-05-31 21:46:22",
            "last_seen_utc": "2026-06-30 10:46:52",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1820398": [
        {
            "ioc_value": "154.38.114.115:53",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-05-31 21:46:19",
            "last_seen_utc": "2026-06-30 10:46:48",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1820397": [
        {
            "ioc_value": "ds.metric-take-datadqct.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-05-31 21:45:54",
            "last_seen_utc": "2026-06-30 10:46:24",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1820368": [
        {
            "ioc_value": "182.23.2.163:1477",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-05-31 19:44:04",
            "last_seen_utc": "2026-06-30 10:43:57",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1820367": [
        {
            "ioc_value": "182.23.2.163:1135",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-05-31 19:44:03",
            "last_seen_utc": "2026-06-30 10:43:56",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1820327": [
        {
            "ioc_value": "64.89.160.44:7777",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.dcrat",
            "malware_alias": "DarkCrystal RAT",
            "malware_printable": "DCRat",
            "first_seen_utc": "2026-05-31 15:04:22",
            "last_seen_utc": "2026-06-30 10:45:59",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "dcrat",
            "anonymous": "1",
            "reporter": "_ik_"
        }
    ],
    "1820311": [
        {
            "ioc_value": "107.151.246.172:7890",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-05-31 11:46:12",
            "last_seen_utc": "2026-06-30 10:46:32",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1820291": [
        {
            "ioc_value": "64.176.73.125:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pupy",
            "malware_alias": "Patpoopy",
            "malware_printable": "pupy",
            "first_seen_utc": "2026-05-31 09:45:39",
            "last_seen_utc": "2026-06-30 10:45:58",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PupyRAT,RAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1820290": [
        {
            "ioc_value": "31.57.184.154:2503",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-05-31 09:44:59",
            "last_seen_utc": "2026-06-30 10:45:23",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1820289": [
        {
            "ioc_value": "182.23.2.163:6088",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-05-31 09:43:50",
            "last_seen_utc": "2026-06-30 08:43:59",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1820288": [
        {
            "ioc_value": "172.81.61.226:5202",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.dcrat",
            "malware_alias": "DarkCrystal RAT",
            "malware_printable": "DCRat",
            "first_seen_utc": "2026-05-31 09:43:43",
            "last_seen_utc": "2026-06-30 10:43:49",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DCRat,drb-ra,RAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1820287": [
        {
            "ioc_value": "155.103.71.115:13407",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-05-31 09:43:29",
            "last_seen_utc": "2026-06-30 10:43:35",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1820212": [
        {
            "ioc_value": "82.157.52.180:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-05-31 06:48:29",
            "last_seen_utc": "2026-06-30 10:47:19",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": null,
            "tags": "45090,c2,censys,cobalt strike",
            "anonymous": "0",
            "reporter": "sojubear"
        }
    ],
    "1820214": [
        {
            "ioc_value": "64.89.160.44:1000",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-05-31 06:48:28",
            "last_seen_utc": "2026-06-30 10:45:59",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": null,
            "tags": "205759,asyncrat,c2,censys",
            "anonymous": "0",
            "reporter": "sojubear"
        }
    ],
    "1820144": [
        {
            "ioc_value": "84.32.41.227:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-05-30 19:45:52",
            "last_seen_utc": "2026-06-30 10:46:11",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1820143": [
        {
            "ioc_value": "47.236.24.112:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.havoc",
            "malware_alias": "Havokiz",
            "malware_printable": "Havoc",
            "first_seen_utc": "2026-05-30 19:45:28",
            "last_seen_utc": "2026-06-30 08:45:46",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Havoc",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1820141": [
        {
            "ioc_value": "157.20.182.17:1997",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-05-30 19:43:32",
            "last_seen_utc": "2026-06-29 18:43:34",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1820030": [
        {
            "ioc_value": "154.16.112.232:5432",
            "ioc_type": "ip:port",
            "threat_type": "payload_delivery",
            "malware": "elf.redtail",
            "malware_alias": null,
            "malware_printable": "RedTail",
            "first_seen_utc": "2026-05-30 15:14:06",
            "last_seen_utc": "2026-06-29 09:40:16",
            "confidence_level": 80,
            "is_compromised": false,
            "reference": "https://twitter.com/NullBlue67",
            "tags": "copy-from-program,kill-rivals,postgres,RedTail",
            "anonymous": "0",
            "reporter": "nullblue67"
        }
    ],
    "1820072": [
        {
            "ioc_value": "223.26.59.226:32354",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-05-30 11:47:27",
            "last_seen_utc": "2026-06-30 10:46:58",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1820044": [
        {
            "ioc_value": "46.225.66.210:4321",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-05-30 09:45:35",
            "last_seen_utc": "2026-06-30 10:45:44",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1820043": [
        {
            "ioc_value": "38.54.63.135:4321",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-05-30 09:45:23",
            "last_seen_utc": "2026-06-30 10:45:30",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1820042": [
        {
            "ioc_value": "182.23.2.163:6407",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-05-30 09:43:57",
            "last_seen_utc": "2026-06-29 08:43:53",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1820041": [
        {
            "ioc_value": "157.20.182.18:1973",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-05-30 09:43:35",
            "last_seen_utc": "2026-06-29 08:43:34",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1820040": [
        {
            "ioc_value": "155.103.71.146:776",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-05-30 09:43:34",
            "last_seen_utc": "2026-06-30 10:43:35",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1820039": [
        {
            "ioc_value": "114.132.190.121:4321",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-05-30 09:43:14",
            "last_seen_utc": "2026-06-30 10:43:17",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1819954": [
        {
            "ioc_value": "156.234.211.156:7661",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-05-30 07:04:47",
            "last_seen_utc": "2026-06-30 10:46:49",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": null,
            "tags": "138195,c2,censys,cobalt strike",
            "anonymous": "0",
            "reporter": "sojubear"
        }
    ],
    "1819982": [
        {
            "ioc_value": "40.85.252.198:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.havoc",
            "malware_alias": "Havokiz",
            "malware_printable": "Havoc",
            "first_seen_utc": "2026-05-30 07:04:38",
            "last_seen_utc": "2026-06-30 10:45:32",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "havoc",
            "anonymous": "1",
            "reporter": "_ik_"
        }
    ],
    "1819942": [
        {
            "ioc_value": "209.200.246.82:5663",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-05-29 23:46:36",
            "last_seen_utc": "2026-06-30 10:46:57",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1819907": [
        {
            "ioc_value": "49.233.81.84:4321",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-05-29 19:45:46",
            "last_seen_utc": "2026-06-30 10:45:47",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1819906": [
        {
            "ioc_value": "43.140.219.30:7112",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.chaos",
            "malware_alias": "FakeRyuk,RyukJoke,Yashma",
            "malware_printable": "Chaos",
            "first_seen_utc": "2026-05-29 19:45:33",
            "last_seen_utc": "2026-06-30 10:45:33",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CHAOS,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1819905": [
        {
            "ioc_value": "31.56.209.79:2404",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-05-29 19:45:22",
            "last_seen_utc": "2026-06-29 08:44:59",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1819904": [
        {
            "ioc_value": "27.102.137.139:2404",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-05-29 19:45:20",
            "last_seen_utc": "2026-06-30 10:45:21",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1819903": [
        {
            "ioc_value": "23.235.185.44:8848",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.dcrat",
            "malware_alias": "DarkCrystal RAT",
            "malware_printable": "DCRat",
            "first_seen_utc": "2026-05-29 19:45:19",
            "last_seen_utc": "2026-06-30 10:45:20",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DCRat,drb-ra,RAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1819902": [
        {
            "ioc_value": "209.99.184.51:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-05-29 19:44:29",
            "last_seen_utc": "2026-06-30 08:44:34",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1819901": [
        {
            "ioc_value": "192.162.199.25:4321",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-05-29 19:44:12",
            "last_seen_utc": "2026-06-30 10:44:14",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1819900": [
        {
            "ioc_value": "185.212.129.4:9000",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.evilginx",
            "malware_alias": null,
            "malware_printable": "Evilginx",
            "first_seen_utc": "2026-05-29 19:44:04",
            "last_seen_utc": "2026-06-30 10:44:08",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Evilginx,EvilGoPhish",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1819899": [
        {
            "ioc_value": "182.23.2.163:4452",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-05-29 19:43:57",
            "last_seen_utc": "2026-06-28 18:43:46",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1819898": [
        {
            "ioc_value": "172.86.109.7:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pupy",
            "malware_alias": "Patpoopy",
            "malware_printable": "pupy",
            "first_seen_utc": "2026-05-29 19:43:49",
            "last_seen_utc": "2026-06-30 10:43:49",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PupyRAT,RAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1819895": [
        {
            "ioc_value": "162.248.224.236:7492",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.ransomhub",
            "malware_alias": null,
            "malware_printable": "RansomHub",
            "first_seen_utc": "2026-05-29 19:43:42",
            "last_seen_utc": "2026-06-30 10:43:42",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RansomHub",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1819896": [
        {
            "ioc_value": "162.248.225.165:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.ransomhub",
            "malware_alias": null,
            "malware_printable": "RansomHub",
            "first_seen_utc": "2026-05-29 19:43:42",
            "last_seen_utc": "2026-06-30 10:43:42",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RansomHub",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1819897": [
        {
            "ioc_value": "162.248.225.165:8603",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.ransomhub",
            "malware_alias": null,
            "malware_printable": "RansomHub",
            "first_seen_utc": "2026-05-29 19:43:42",
            "last_seen_utc": "2026-06-30 10:43:42",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RansomHub",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1819894": [
        {
            "ioc_value": "162.248.224.236:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.ransomhub",
            "malware_alias": null,
            "malware_printable": "RansomHub",
            "first_seen_utc": "2026-05-29 19:43:41",
            "last_seen_utc": "2026-06-30 10:43:41",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RansomHub",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1819893": [
        {
            "ioc_value": "157.20.182.17:1444",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-05-29 19:43:36",
            "last_seen_utc": "2026-06-29 08:43:33",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1819892": [
        {
            "ioc_value": "146.59.182.123:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-05-29 19:43:30",
            "last_seen_utc": "2026-06-30 10:43:27",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1819891": [
        {
            "ioc_value": "134.199.170.120:3333",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.evilginx",
            "malware_alias": null,
            "malware_printable": "Evilginx",
            "first_seen_utc": "2026-05-29 19:43:21",
            "last_seen_utc": "2026-06-30 10:43:21",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Evilginx,EvilGoPhish",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1819890": [
        {
            "ioc_value": "13.213.58.233:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-05-29 19:43:18",
            "last_seen_utc": "2026-06-30 10:43:20",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1819889": [
        {
            "ioc_value": "111.229.154.250:4321",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-05-29 19:43:14",
            "last_seen_utc": "2026-06-30 10:43:17",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1819888": [
        {
            "ioc_value": "103.213.251.10:8443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.bianlian",
            "malware_alias": null,
            "malware_printable": "BianLian",
            "first_seen_utc": "2026-05-29 19:43:06",
            "last_seen_utc": "2026-06-30 10:43:09",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "Bianlian,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1819887": [
        {
            "ioc_value": "1.14.172.47:4321",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-05-29 19:43:02",
            "last_seen_utc": "2026-06-30 10:43:02",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1819866": [
        {
            "ioc_value": "124.220.235.4:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-05-29 15:46:36",
            "last_seen_utc": "2026-06-30 10:46:42",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1819842": [
        {
            "ioc_value": "mub.depansm188.top",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-05-29 15:30:50",
            "last_seen_utc": "2026-06-30 11:23:54",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "vidar",
            "anonymous": "0",
            "reporter": "crep1x"
        }
    ],
    "1819843": [
        {
            "ioc_value": "https://mub.depansm188.top/",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-05-29 15:30:50",
            "last_seen_utc": "2026-06-30 11:23:53",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "vidar",
            "anonymous": "0",
            "reporter": "crep1x"
        }
    ],
    "1819788": [
        {
            "ioc_value": "209.200.246.82:7533",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-05-29 11:46:49",
            "last_seen_utc": "2026-06-30 10:46:57",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1819787": [
        {
            "ioc_value": "124.71.141.30:5003",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-05-29 11:46:38",
            "last_seen_utc": "2026-06-30 10:46:44",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1819786": [
        {
            "ioc_value": "118.89.79.131:6528",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-05-29 11:46:33",
            "last_seen_utc": "2026-06-30 10:46:39",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1819785": [
        {
            "ioc_value": "103.242.12.143:18443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-05-29 11:46:24",
            "last_seen_utc": "2026-06-30 10:46:31",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1819763": [
        {
            "ioc_value": "119.29.117.194:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-05-29 09:46:58",
            "last_seen_utc": "2026-06-30 10:46:40",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1819761": [
        {
            "ioc_value": "194.236.215.200:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.danabot",
            "malware_alias": "DanaTools",
            "malware_printable": "DanaBot",
            "first_seen_utc": "2026-05-29 09:44:20",
            "last_seen_utc": "2026-06-30 10:44:19",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DanBot,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1819759": [
        {
            "ioc_value": "192.30.243.28:36812",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-05-29 09:44:16",
            "last_seen_utc": "2026-06-28 18:43:59",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1819760": [
        {
            "ioc_value": "192.30.243.28:8638",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-05-29 09:44:16",
            "last_seen_utc": "2026-06-28 18:43:59",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1819758": [
        {
            "ioc_value": "190.255.90.152:6010",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.dcrat",
            "malware_alias": "DarkCrystal RAT",
            "malware_printable": "DCRat",
            "first_seen_utc": "2026-05-29 09:44:12",
            "last_seen_utc": "2026-06-28 18:43:56",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DCRat,drb-ra,RAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1819757": [
        {
            "ioc_value": "185.212.129.6:9000",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.evilginx",
            "malware_alias": null,
            "malware_printable": "Evilginx",
            "first_seen_utc": "2026-05-29 09:44:06",
            "last_seen_utc": "2026-06-30 10:44:08",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Evilginx,EvilGoPhish",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1819756": [
        {
            "ioc_value": "185.212.129.146:9000",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.evilginx",
            "malware_alias": null,
            "malware_printable": "Evilginx",
            "first_seen_utc": "2026-05-29 09:44:05",
            "last_seen_utc": "2026-06-30 10:44:07",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Evilginx,EvilGoPhish",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1819754": [
        {
            "ioc_value": "172.82.64.235:444",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-05-29 09:43:50",
            "last_seen_utc": "2026-06-28 18:43:39",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1819753": [
        {
            "ioc_value": "168.144.36.228:9000",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pupy",
            "malware_alias": "Patpoopy",
            "malware_printable": "pupy",
            "first_seen_utc": "2026-05-29 09:43:47",
            "last_seen_utc": "2026-06-30 10:43:46",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PupyRAT,RAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1819752": [
        {
            "ioc_value": "158.94.208.29:207",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.dcrat",
            "malware_alias": "DarkCrystal RAT",
            "malware_printable": "DCRat",
            "first_seen_utc": "2026-05-29 09:43:39",
            "last_seen_utc": "2026-06-28 18:43:31",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DCRat,drb-ra,RAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1819751": [
        {
            "ioc_value": "157.254.223.135:2700",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-05-29 09:43:38",
            "last_seen_utc": "2026-06-30 10:43:38",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1819749": [
        {
            "ioc_value": "103.77.246.174:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.mirai",
            "malware_alias": "Katana",
            "malware_printable": "Mirai",
            "first_seen_utc": "2026-05-29 09:43:08",
            "last_seen_utc": "2026-06-30 10:43:10",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mirai",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1819748": [
        {
            "ioc_value": "103.213.251.10:8444",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.bianlian",
            "malware_alias": null,
            "malware_printable": "BianLian",
            "first_seen_utc": "2026-05-29 09:43:07",
            "last_seen_utc": "2026-06-30 10:43:09",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "Bianlian,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1819713": [
        {
            "ioc_value": "198.44.177.179:8081",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-05-29 06:45:14",
            "last_seen_utc": "2026-06-30 10:46:55",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-987654321",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1819710": [
        {
            "ioc_value": "45.116.78.181:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-05-29 06:44:51",
            "last_seen_utc": "2026-06-30 08:47:12",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-987654321",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1819695": [
        {
            "ioc_value": "15.235.9.17:8000",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-05-29 06:26:29",
            "last_seen_utc": "2026-06-29 08:43:29",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "asyncrat",
            "anonymous": "1",
            "reporter": "_ik_"
        }
    ],
    "1819595": [
        {
            "ioc_value": "82.197.69.156:8443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.havoc",
            "malware_alias": "Havokiz",
            "malware_printable": "Havoc",
            "first_seen_utc": "2026-05-28 19:45:25",
            "last_seen_utc": "2026-06-29 08:45:42",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Havoc",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1819594": [
        {
            "ioc_value": "35.158.219.35:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-05-28 19:44:47",
            "last_seen_utc": "2026-06-30 10:45:27",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1819593": [
        {
            "ioc_value": "31.57.184.154:7005",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-05-28 19:44:44",
            "last_seen_utc": "2026-06-30 10:45:24",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1819586": [
        {
            "ioc_value": "13.209.95.4:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-05-28 19:43:13",
            "last_seen_utc": "2026-06-30 10:43:20",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1819407": [
        {
            "ioc_value": "91.230.94.235:4321",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-05-28 09:46:10",
            "last_seen_utc": "2026-06-30 10:46:17",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1819406": [
        {
            "ioc_value": "91.215.85.212:45423",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-05-28 09:46:09",
            "last_seen_utc": "2026-06-30 10:46:16",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1819405": [
        {
            "ioc_value": "85.209.90.132:4321",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-05-28 09:46:05",
            "last_seen_utc": "2026-06-30 10:46:12",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1819404": [
        {
            "ioc_value": "83.171.227.230:4321",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-05-28 09:46:00",
            "last_seen_utc": "2026-06-30 10:46:10",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1819403": [
        {
            "ioc_value": "81.71.20.107:8989",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-05-28 09:45:58",
            "last_seen_utc": "2026-06-30 10:46:08",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1819402": [
        {
            "ioc_value": "43.133.165.151:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-05-28 09:45:23",
            "last_seen_utc": "2026-06-30 10:45:33",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1819401": [
        {
            "ioc_value": "27.102.138.15:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-05-28 09:45:10",
            "last_seen_utc": "2026-06-30 10:45:21",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1819398": [
        {
            "ioc_value": "206.119.171.212:4333",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-05-28 09:44:20",
            "last_seen_utc": "2026-06-30 10:44:29",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1819396": [
        {
            "ioc_value": "202.95.8.97:4321",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-05-28 09:44:19",
            "last_seen_utc": "2026-06-30 10:44:28",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1819397": [
        {
            "ioc_value": "202.95.8.98:4321",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-05-28 09:44:19",
            "last_seen_utc": "2026-06-30 10:44:28",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1819394": [
        {
            "ioc_value": "193.5.65.169:4348",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.ransomhub",
            "malware_alias": null,
            "malware_printable": "RansomHub",
            "first_seen_utc": "2026-05-28 09:44:10",
            "last_seen_utc": "2026-06-30 10:44:18",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RansomHub",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1819395": [
        {
            "ioc_value": "193.5.65.169:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.ransomhub",
            "malware_alias": null,
            "malware_printable": "RansomHub",
            "first_seen_utc": "2026-05-28 09:44:10",
            "last_seen_utc": "2026-06-30 10:44:18",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RansomHub",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1819393": [
        {
            "ioc_value": "172.86.76.218:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pupy",
            "malware_alias": "Patpoopy",
            "malware_printable": "pupy",
            "first_seen_utc": "2026-05-28 09:43:45",
            "last_seen_utc": "2026-06-30 10:43:49",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PupyRAT,RAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1819392": [
        {
            "ioc_value": "172.236.142.17:6933",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-05-28 09:43:44",
            "last_seen_utc": "2026-06-30 10:43:47",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1819391": [
        {
            "ioc_value": "165.154.205.4:53341",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-05-28 09:43:40",
            "last_seen_utc": "2026-06-30 10:43:44",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1819390": [
        {
            "ioc_value": "155.103.71.135:56789",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-05-28 09:43:33",
            "last_seen_utc": "2026-06-30 10:43:35",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1819389": [
        {
            "ioc_value": "146.103.106.59:4321",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-05-28 09:43:27",
            "last_seen_utc": "2026-06-30 08:43:28",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1819388": [
        {
            "ioc_value": "139.59.84.11:2053",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.havoc",
            "malware_alias": "Havokiz",
            "malware_printable": "Havoc",
            "first_seen_utc": "2026-05-28 09:43:23",
            "last_seen_utc": "2026-06-30 08:43:25",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Havoc",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1819387": [
        {
            "ioc_value": "113.31.106.85:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-05-28 09:43:13",
            "last_seen_utc": "2026-06-30 10:43:17",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1819386": [
        {
            "ioc_value": "103.183.75.134:20443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-05-28 09:43:05",
            "last_seen_utc": "2026-06-30 10:43:09",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1819351": [
        {
            "ioc_value": "120.48.66.205:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-05-28 06:56:15",
            "last_seen_utc": "2026-06-30 10:46:41",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-391144938",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1819239": [
        {
            "ioc_value": "138.124.61.65:8088",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-05-28 05:33:17",
            "last_seen_utc": "2026-06-28 18:43:18",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "asyncrat",
            "anonymous": "1",
            "reporter": "_ik_"
        }
    ],
    "1819240": [
        {
            "ioc_value": "46.246.14.2:9999",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.dcrat",
            "malware_alias": "DarkCrystal RAT",
            "malware_printable": "DCRat",
            "first_seen_utc": "2026-05-28 05:33:16",
            "last_seen_utc": "2026-06-30 10:45:45",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "dcrat",
            "anonymous": "1",
            "reporter": "_ik_"
        }
    ],
    "1819269": [
        {
            "ioc_value": "116.213.42.110:2003",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-05-28 05:32:54",
            "last_seen_utc": "2026-06-30 10:46:37",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "cobaltstrike",
            "anonymous": "1",
            "reporter": "_ik_"
        }
    ],
    "1819225": [
        {
            "ioc_value": "91.200.84.198:8515",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-05-27 19:45:55",
            "last_seen_utc": "2026-06-30 10:46:16",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1819224": [
        {
            "ioc_value": "45.32.236.190:2096",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-05-27 19:45:18",
            "last_seen_utc": "2026-06-30 10:45:39",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1819222": [
        {
            "ioc_value": "43.106.14.139:8085",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.havoc",
            "malware_alias": "Havokiz",
            "malware_printable": "Havoc",
            "first_seen_utc": "2026-05-27 19:45:12",
            "last_seen_utc": "2026-06-30 10:45:32",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Havoc",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1819223": [
        {
            "ioc_value": "43.133.149.36:18443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-05-27 19:45:12",
            "last_seen_utc": "2026-06-30 10:45:32",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1819220": [
        {
            "ioc_value": "18.162.155.202:3350",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.deimos_c2",
            "malware_alias": null,
            "malware_printable": "DeimosC2",
            "first_seen_utc": "2026-05-27 19:43:47",
            "last_seen_utc": "2026-06-30 10:43:54",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "Deimos,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1819219": [
        {
            "ioc_value": "157.20.182.17:1973",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-05-27 19:43:30",
            "last_seen_utc": "2026-06-30 10:43:37",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1819217": [
        {
            "ioc_value": "104.225.149.151:54321",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-05-27 19:43:08",
            "last_seen_utc": "2026-06-30 10:43:11",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1819146": [
        {
            "ioc_value": "8.134.70.73:9999",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-05-27 15:46:43",
            "last_seen_utc": "2026-06-30 10:47:16",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1819145": [
        {
            "ioc_value": "47.122.47.221:8081",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-05-27 15:46:36",
            "last_seen_utc": "2026-06-30 10:47:10",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1819067": [
        {
            "ioc_value": "47.118.25.45:8451",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-05-27 11:48:59",
            "last_seen_utc": "2026-06-29 10:46:56",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1819044": [
        {
            "ioc_value": "35.75.179.211:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.brute_ratel_c4",
            "malware_alias": "BOLDBADGER,BruteRatel",
            "malware_printable": "Brute Ratel C4",
            "first_seen_utc": "2026-05-27 09:45:01",
            "last_seen_utc": "2026-06-28 18:44:56",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "BruteRatel,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1819042": [
        {
            "ioc_value": "164.90.206.5:8443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.havoc",
            "malware_alias": "Havokiz",
            "malware_printable": "Havoc",
            "first_seen_utc": "2026-05-27 09:43:38",
            "last_seen_utc": "2026-06-30 10:43:44",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Havoc",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1819041": [
        {
            "ioc_value": "157.254.223.135:2500",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-05-27 09:43:32",
            "last_seen_utc": "2026-06-30 10:43:38",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1818955": [
        {
            "ioc_value": "117.72.159.215:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-05-27 07:09:22",
            "last_seen_utc": "2026-06-30 10:46:37",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": null,
            "tags": "c2,censys,cobalt strike",
            "anonymous": "0",
            "reporter": "sojubear"
        }
    ],
    "1818956": [
        {
            "ioc_value": "8.163.49.50:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-05-27 07:09:22",
            "last_seen_utc": "2026-06-30 10:47:17",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": null,
            "tags": "c2,censys,cobalt strike",
            "anonymous": "0",
            "reporter": "sojubear"
        }
    ],
    "1819006": [
        {
            "ioc_value": "124.70.184.106:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-05-27 06:54:26",
            "last_seen_utc": "2026-06-30 10:46:43",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-666666666",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1818935": [
        {
            "ioc_value": "139.196.223.82:2443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-05-26 22:46:05",
            "last_seen_utc": "2026-06-28 12:46:05",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1818934": [
        {
            "ioc_value": "134.122.134.243:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-05-26 22:46:04",
            "last_seen_utc": "2026-06-29 10:46:32",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1818880": [
        {
            "ioc_value": "5.101.82.8:48214",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-05-26 19:45:20",
            "last_seen_utc": "2026-06-30 10:45:49",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1818879": [
        {
            "ioc_value": "207.180.250.181:20600",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-05-26 19:44:11",
            "last_seen_utc": "2026-06-30 10:44:31",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1818878": [
        {
            "ioc_value": "190.2.150.52:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-05-26 19:43:55",
            "last_seen_utc": "2026-06-30 10:44:12",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1818872": [
        {
            "ioc_value": "155.102.136.60:4506",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.deimos_c2",
            "malware_alias": null,
            "malware_printable": "DeimosC2",
            "first_seen_utc": "2026-05-26 19:43:28",
            "last_seen_utc": "2026-06-30 10:43:34",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "Deimos,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1818804": [
        {
            "ioc_value": "47.122.47.221:18443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-05-26 14:46:42",
            "last_seen_utc": "2026-06-30 10:47:09",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1818731": [
        {
            "ioc_value": "68.64.178.130:8443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-05-26 10:46:53",
            "last_seen_utc": "2026-06-30 10:47:14",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1818730": [
        {
            "ioc_value": "45.227.253.121:35120",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-05-26 10:46:44",
            "last_seen_utc": "2026-06-30 10:47:07",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1818729": [
        {
            "ioc_value": "36.138.84.183:18443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-05-26 10:46:38",
            "last_seen_utc": "2026-06-30 10:46:59",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1818710": [
        {
            "ioc_value": "43.204.108.246:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-05-26 10:01:24",
            "last_seen_utc": "2026-06-30 10:47:05",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "cobaltstrike",
            "anonymous": "1",
            "reporter": "_ik_"
        }
    ],
    "1818711": [
        {
            "ioc_value": "43.204.108.246:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-05-26 10:01:23",
            "last_seen_utc": "2026-06-30 10:47:05",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "cobaltstrike",
            "anonymous": "1",
            "reporter": "_ik_"
        }
    ],
    "1818714": [
        {
            "ioc_value": "198.23.185.82:8888",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-05-26 10:01:20",
            "last_seen_utc": "2026-06-30 10:44:23",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "asyncrat",
            "anonymous": "1",
            "reporter": "_ik_"
        }
    ],
    "1818704": [
        {
            "ioc_value": "91.92.243.189:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.eye_pyramid",
            "malware_alias": null,
            "malware_printable": "Eye Pyramid",
            "first_seen_utc": "2026-05-26 09:45:51",
            "last_seen_utc": "2026-06-28 18:45:41",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,EyePyramid",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1818703": [
        {
            "ioc_value": "64.89.161.156:9999",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.dcrat",
            "malware_alias": "DarkCrystal RAT",
            "malware_printable": "DCRat",
            "first_seen_utc": "2026-05-26 09:45:36",
            "last_seen_utc": "2026-06-30 10:46:00",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DCRat,drb-ra,RAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1818701": [
        {
            "ioc_value": "46.8.226.70:8443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.sliver",
            "malware_alias": null,
            "malware_printable": "Sliver",
            "first_seen_utc": "2026-05-26 09:45:21",
            "last_seen_utc": "2026-06-30 10:45:46",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Sliver",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1818700": [
        {
            "ioc_value": "34.106.231.199:6932",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-05-26 09:44:59",
            "last_seen_utc": "2026-06-30 10:45:26",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1818699": [
        {
            "ioc_value": "23.27.168.162:2850",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.evilginx",
            "malware_alias": null,
            "malware_printable": "Evilginx",
            "first_seen_utc": "2026-05-26 09:44:54",
            "last_seen_utc": "2026-06-30 10:45:20",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Evilginx,EvilGoPhish",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1818698": [
        {
            "ioc_value": "209.99.187.22:4321",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-05-26 09:44:15",
            "last_seen_utc": "2026-06-30 08:44:34",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1818697": [
        {
            "ioc_value": "202.189.6.77:6606",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-05-26 09:44:12",
            "last_seen_utc": "2026-06-30 10:44:28",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1818696": [
        {
            "ioc_value": "193.24.123.160:45631",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-05-26 09:44:02",
            "last_seen_utc": "2026-06-30 10:44:17",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1818695": [
        {
            "ioc_value": "191.93.116.106:8848",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.dcrat",
            "malware_alias": "DarkCrystal RAT",
            "malware_printable": "DCRat",
            "first_seen_utc": "2026-05-26 09:43:57",
            "last_seen_utc": "2026-06-30 10:44:13",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DCRat,drb-ra,RAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1818694": [
        {
            "ioc_value": "153.75.232.207:4000",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.evilginx",
            "malware_alias": null,
            "malware_printable": "Evilginx",
            "first_seen_utc": "2026-05-26 09:43:28",
            "last_seen_utc": "2026-06-30 10:43:32",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Evilginx,EvilGoPhish",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1818480": [
        {
            "ioc_value": "47.108.25.113:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-05-25 22:46:18",
            "last_seen_utc": "2026-06-30 10:47:08",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1818479": [
        {
            "ioc_value": "43.156.42.49:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-05-25 22:46:15",
            "last_seen_utc": "2026-06-30 10:47:04",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1818439": [
        {
            "ioc_value": "5.101.83.143:7312",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-05-25 19:45:14",
            "last_seen_utc": "2026-06-30 10:45:49",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1818438": [
        {
            "ioc_value": "5.101.82.98:42859",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-05-25 19:45:13",
            "last_seen_utc": "2026-06-30 10:45:49",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1818434": [
        {
            "ioc_value": "37.77.150.174:4333",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.eye_pyramid",
            "malware_alias": null,
            "malware_printable": "Eye Pyramid",
            "first_seen_utc": "2026-05-25 19:44:52",
            "last_seen_utc": "2026-06-30 10:45:29",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,EyePyramid",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1818433": [
        {
            "ioc_value": "37.77.150.174:4332",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.eye_pyramid",
            "malware_alias": null,
            "malware_printable": "Eye Pyramid",
            "first_seen_utc": "2026-05-25 19:44:51",
            "last_seen_utc": "2026-06-30 10:45:29",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,EyePyramid",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1818432": [
        {
            "ioc_value": "27.102.137.139:1243",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-05-25 19:44:46",
            "last_seen_utc": "2026-06-30 10:45:21",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1818431": [
        {
            "ioc_value": "202.95.8.92:4321",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-05-25 19:44:05",
            "last_seen_utc": "2026-06-30 10:44:28",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1818427": [
        {
            "ioc_value": "157.20.182.18:1992",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-05-25 19:43:28",
            "last_seen_utc": "2026-06-30 10:43:38",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1818337": [
        {
            "ioc_value": "krolikrojer.lat",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-05-25 14:01:58",
            "last_seen_utc": "2026-06-29 13:27:15",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "clickfix",
            "anonymous": "0",
            "reporter": "whoamix302"
        }
    ],
    "1818298": [
        {
            "ioc_value": "83.142.209.64:35630",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.dcrat",
            "malware_alias": "DarkCrystal RAT",
            "malware_printable": "DCRat",
            "first_seen_utc": "2026-05-25 09:46:05",
            "last_seen_utc": "2026-06-30 10:46:10",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DCRat,drb-ra,RAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1818295": [
        {
            "ioc_value": "157.20.182.18:6666",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-05-25 09:43:37",
            "last_seen_utc": "2026-06-29 18:43:34",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1818253": [
        {
            "ioc_value": "134.175.78.181:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-05-25 06:57:09",
            "last_seen_utc": "2026-06-30 10:46:44",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-666666666",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1818107": [
        {
            "ioc_value": "31.171.131.118:6606",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-05-24 19:45:21",
            "last_seen_utc": "2026-06-30 10:45:23",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1818104": [
        {
            "ioc_value": "157.20.182.18:9992",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-05-24 19:43:36",
            "last_seen_utc": "2026-06-28 18:43:30",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1818053": [
        {
            "ioc_value": "45.154.12.150:53",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-05-24 14:46:49",
            "last_seen_utc": "2026-06-30 10:47:06",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1818052": [
        {
            "ioc_value": "103.210.236.87:53",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-05-24 14:46:17",
            "last_seen_utc": "2026-06-30 10:46:31",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1818050": [
        {
            "ioc_value": "wsus.227api.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-05-24 14:46:12",
            "last_seen_utc": "2026-06-30 10:46:28",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1818051": [
        {
            "ioc_value": "wsus2.227api.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-05-24 14:46:12",
            "last_seen_utc": "2026-06-30 10:46:28",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1818049": [
        {
            "ioc_value": "102.220.160.47:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.mirai",
            "malware_alias": "Katana",
            "malware_printable": "Mirai",
            "first_seen_utc": "2026-05-24 14:43:03",
            "last_seen_utc": "2026-06-30 10:43:05",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mirai",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1818032": [
        {
            "ioc_value": "104.168.0.29:52202",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-05-24 14:10:22",
            "last_seen_utc": "2026-06-30 10:43:11",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "asyncrat",
            "anonymous": "1",
            "reporter": "_ik_"
        }
    ],
    "1818033": [
        {
            "ioc_value": "156.239.238.117:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-05-24 14:10:22",
            "last_seen_utc": "2026-06-30 08:46:54",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "cobaltstrike",
            "anonymous": "1",
            "reporter": "_ik_"
        }
    ],
    "1817883": [
        {
            "ioc_value": "43.138.192.16:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-05-24 11:08:34",
            "last_seen_utc": "2026-06-30 10:47:02",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-987654321",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1817829": [
        {
            "ioc_value": "172.94.18.103:75",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-05-24 11:05:15",
            "last_seen_utc": "2026-06-30 10:43:50",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "asyncrat",
            "anonymous": "1",
            "reporter": "_ik_"
        }
    ],
    "1817873": [
        {
            "ioc_value": "172.94.18.103:73",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-05-24 11:04:56",
            "last_seen_utc": "2026-06-30 10:43:50",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "asyncrat",
            "anonymous": "1",
            "reporter": "_ik_"
        }
    ],
    "1817773": [
        {
            "ioc_value": "sdnssmdf-js.beer",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-05-24 11:04:35",
            "last_seen_utc": "2026-06-29 13:39:11",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "ClickFix,ErrTraffic,Vidar",
            "anonymous": "0",
            "reporter": "varysz"
        }
    ],
    "1817774": [
        {
            "ioc_value": "smtnscerver.beer",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-05-24 11:04:34",
            "last_seen_utc": "2026-06-29 13:32:22",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "ClickFix,ErrTraffic,Vidar",
            "anonymous": "0",
            "reporter": "varysz"
        }
    ],
    "1817785": [
        {
            "ioc_value": "39.100.88.189:9001",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-05-24 11:04:32",
            "last_seen_utc": "2026-06-30 10:47:00",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": null,
            "tags": "37963,c2,censys,cobalt strike",
            "anonymous": "0",
            "reporter": "sojubear"
        }
    ],
    "1817715": [
        {
            "ioc_value": "101.43.30.6:888",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-05-24 11:03:40",
            "last_seen_utc": "2026-06-30 10:46:31",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "cobaltstrike",
            "anonymous": "1",
            "reporter": "_ik_"
        }
    ],
    "1817758": [
        {
            "ioc_value": "https://cyy.turbo88ml.top/",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-05-23 22:00:09",
            "last_seen_utc": "2026-06-30 11:23:32",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "vidar",
            "anonymous": "0",
            "reporter": "crep1x"
        }
    ],
    "1817757": [
        {
            "ioc_value": "cyy.turbo88ml.top",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-05-23 22:00:08",
            "last_seen_utc": "2026-06-30 11:23:32",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "vidar",
            "anonymous": "0",
            "reporter": "crep1x"
        }
    ],
    "1817707": [
        {
            "ioc_value": "18.118.196.244:6666",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-05-23 19:43:58",
            "last_seen_utc": "2026-06-30 08:43:54",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1817705": [
        {
            "ioc_value": "157.254.223.135:6606",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-05-23 19:43:39",
            "last_seen_utc": "2026-06-30 10:43:38",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1817704": [
        {
            "ioc_value": "151.236.20.3:8080",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-05-23 19:43:35",
            "last_seen_utc": "2026-06-30 10:43:32",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1817663": [
        {
            "ioc_value": "101.126.10.34:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-05-23 14:56:56",
            "last_seen_utc": "2026-06-30 10:46:30",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-666666666",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1817454": [
        {
            "ioc_value": "rpc-cloud.beer",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-05-23 14:56:33",
            "last_seen_utc": "2026-06-29 13:38:31",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "ClickFix,ErrTraffic,Vidar",
            "anonymous": "0",
            "reporter": "varysz"
        }
    ],
    "1817460": [
        {
            "ioc_value": "siteamnsserv.beer",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-05-23 14:56:30",
            "last_seen_utc": "2026-06-29 13:39:03",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "ClickFix,ErrTraffic,Vidar",
            "anonymous": "0",
            "reporter": "varysz"
        }
    ],
    "1817462": [
        {
            "ioc_value": "store-image.sbs",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-05-23 14:56:29",
            "last_seen_utc": "2026-06-29 13:32:13",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "ClickFix,ErrTraffic,Vidar",
            "anonymous": "0",
            "reporter": "varysz"
        }
    ],
    "1817468": [
        {
            "ioc_value": "vaer-cdn-3.sbs",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-05-23 14:54:45",
            "last_seen_utc": "2026-06-29 13:32:06",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "ClickFix,ErrTraffic,Vidar",
            "anonymous": "0",
            "reporter": "varysz"
        }
    ],
    "1817469": [
        {
            "ioc_value": "vblbs.beer",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-05-23 14:54:44",
            "last_seen_utc": "2026-06-29 13:32:04",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "ClickFix,ErrTraffic,Vidar",
            "anonymous": "0",
            "reporter": "varysz"
        }
    ],
    "1817470": [
        {
            "ioc_value": "vdsinatest.beer",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-05-23 14:54:44",
            "last_seen_utc": "2026-06-29 13:38:54",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "ClickFix,ErrTraffic,Vidar",
            "anonymous": "0",
            "reporter": "varysz"
        }
    ],
    "1817471": [
        {
            "ioc_value": "visual-ns-portal.beer",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-05-23 14:54:44",
            "last_seen_utc": "2026-06-29 13:31:58",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "ClickFix,ErrTraffic,Vidar",
            "anonymous": "0",
            "reporter": "varysz"
        }
    ],
    "1817474": [
        {
            "ioc_value": "workcdnmass.beer",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-05-23 14:54:42",
            "last_seen_utc": "2026-06-29 13:39:17",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "ClickFix,ErrTraffic,Vidar",
            "anonymous": "0",
            "reporter": "varysz"
        }
    ],
    "1817476": [
        {
            "ioc_value": "lsnsdns.beer",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-05-23 14:54:42",
            "last_seen_utc": "2026-06-29 13:33:09",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "ClickFix,ErrTraffic,Vidar",
            "anonymous": "0",
            "reporter": "varysz"
        }
    ],
    "1817480": [
        {
            "ioc_value": "minecraftserverapigame.xyz",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-05-23 14:54:39",
            "last_seen_utc": "2026-06-29 13:38:33",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "ClickFix,ErrTraffic,Vidar",
            "anonymous": "0",
            "reporter": "varysz"
        }
    ],
    "1817483": [
        {
            "ioc_value": "networksolutionson.sbs",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-05-23 14:54:38",
            "last_seen_utc": "2026-06-29 13:33:04",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "ClickFix,ErrTraffic,Vidar",
            "anonymous": "0",
            "reporter": "varysz"
        }
    ],
    "1817485": [
        {
            "ioc_value": "ntsnsdns.beer",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-05-23 14:54:37",
            "last_seen_utc": "2026-06-29 13:38:45",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "ClickFix,ErrTraffic,Vidar",
            "anonymous": "0",
            "reporter": "varysz"
        }
    ],
    "1817487": [
        {
            "ioc_value": "poygon-notifications.click",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-05-23 14:54:36",
            "last_seen_utc": "2026-06-29 13:32:39",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "ClickFix,ErrTraffic,Vidar",
            "anonymous": "0",
            "reporter": "varysz"
        }
    ],
    "1817488": [
        {
            "ioc_value": "istile-c-cloud.beer",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-05-23 14:54:35",
            "last_seen_utc": "2026-06-29 13:33:20",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "ClickFix,ErrTraffic,Vidar",
            "anonymous": "0",
            "reporter": "varysz"
        }
    ],
    "1817489": [
        {
            "ioc_value": "js-server.beer",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-05-23 14:54:35",
            "last_seen_utc": "2026-06-29 13:39:18",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "ClickFix,ErrTraffic,Vidar",
            "anonymous": "0",
            "reporter": "varysz"
        }
    ],
    "1817491": [
        {
            "ioc_value": "lasthauszver.beer",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-05-23 14:54:34",
            "last_seen_utc": "2026-06-29 13:33:16",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "ClickFix,ErrTraffic,Vidar",
            "anonymous": "0",
            "reporter": "varysz"
        }
    ],
    "1817492": [
        {
            "ioc_value": "image-hoster11.sbs",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-05-23 14:54:34",
            "last_seen_utc": "2026-06-29 13:33:23",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "ClickFix,ErrTraffic,Vidar",
            "anonymous": "0",
            "reporter": "varysz"
        }
    ],
    "1817494": [
        {
            "ioc_value": "img-cdn-cloud.click",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-05-23 14:54:33",
            "last_seen_utc": "2026-06-29 13:33:21",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "ClickFix,ErrTraffic,Vidar",
            "anonymous": "0",
            "reporter": "varysz"
        }
    ],
    "1817497": [
        {
            "ioc_value": "fontawesome-js-ico.beer",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-05-23 14:54:32",
            "last_seen_utc": "2026-06-29 13:33:44",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "ClickFix,ErrTraffic,Vidar",
            "anonymous": "0",
            "reporter": "varysz"
        }
    ],
    "1817498": [
        {
            "ioc_value": "fonts-fontawesome.cfd",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-05-23 14:54:31",
            "last_seen_utc": "2026-06-29 13:33:42",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "ClickFix,ErrTraffic,Vidar",
            "anonymous": "0",
            "reporter": "varysz"
        }
    ],
    "1817500": [
        {
            "ioc_value": "ghdnsserverns.beer",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-05-23 14:54:30",
            "last_seen_utc": "2026-06-29 13:33:32",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "ClickFix,ErrTraffic,Vidar",
            "anonymous": "0",
            "reporter": "varysz"
        }
    ],
    "1817505": [
        {
            "ioc_value": "cdn-server-styles.click",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-05-23 14:54:26",
            "last_seen_utc": "2026-06-29 13:37:54",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "ClickFix,ErrTraffic,Vidar",
            "anonymous": "0",
            "reporter": "varysz"
        }
    ],
    "1817632": [
        {
            "ioc_value": "203.83.10.114:4444",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-05-23 14:54:01",
            "last_seen_utc": "2026-06-30 10:46:56",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "cobaltstrike",
            "anonymous": "1",
            "reporter": "_ik_"
        }
    ],
    "1817655": [
        {
            "ioc_value": "119.29.117.194:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-05-23 14:47:31",
            "last_seen_utc": "2026-06-29 10:46:27",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1817509": [
        {
            "ioc_value": "chekbrow.beer",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-05-23 08:58:45",
            "last_seen_utc": "2026-06-29 13:37:52",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "ClickFix,ErrTraffic,Vidar",
            "anonymous": "0",
            "reporter": "varysz"
        }
    ],
    "1817511": [
        {
            "ioc_value": "cloud-safe.click",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-05-23 08:58:44",
            "last_seen_utc": "2026-06-29 13:39:50",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "ClickFix,ErrTraffic,Vidar",
            "anonymous": "0",
            "reporter": "varysz"
        }
    ],
    "1817512": [
        {
            "ioc_value": "clpcentr.world",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-05-23 08:58:44",
            "last_seen_utc": "2026-06-29 13:38:38",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "ClickFix,ErrTraffic,Vidar",
            "anonymous": "0",
            "reporter": "varysz"
        }
    ],
    "1817513": [
        {
            "ioc_value": "clpuanmeserver.shop",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-05-23 08:58:43",
            "last_seen_utc": "2026-06-29 13:38:35",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "ClickFix,ErrTraffic,Vidar",
            "anonymous": "0",
            "reporter": "varysz"
        }
    ],
    "1817517": [
        {
            "ioc_value": "dev.clpcentr.world",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-05-23 08:58:41",
            "last_seen_utc": "2026-06-29 13:38:36",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "ClickFix,ErrTraffic,Vidar",
            "anonymous": "0",
            "reporter": "varysz"
        }
    ],
    "1817518": [
        {
            "ioc_value": "dreff-nsdns.beer",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-05-23 08:58:40",
            "last_seen_utc": "2026-06-29 13:38:59",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "ClickFix,ErrTraffic,Vidar",
            "anonymous": "0",
            "reporter": "varysz"
        }
    ],
    "1817519": [
        {
            "ioc_value": "bacloudserver.beer",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-05-23 08:58:40",
            "last_seen_utc": "2026-06-29 13:38:14",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "ClickFix,ErrTraffic,Vidar",
            "anonymous": "0",
            "reporter": "varysz"
        }
    ],
    "1817520": [
        {
            "ioc_value": "bbdsnssserver.beer",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-05-23 08:58:40",
            "last_seen_utc": "2026-06-29 13:38:43",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "ClickFix,ErrTraffic,Vidar",
            "anonymous": "0",
            "reporter": "varysz"
        }
    ],
    "1817522": [
        {
            "ioc_value": "bedcdnset.beer",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-05-23 08:58:39",
            "last_seen_utc": "2026-06-29 13:38:12",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "ClickFix,ErrTraffic,Vidar",
            "anonymous": "0",
            "reporter": "varysz"
        }
    ],
    "1817524": [
        {
            "ioc_value": "bigsmart.beer",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-05-23 08:58:38",
            "last_seen_utc": "2026-06-29 13:38:10",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "ClickFix,ErrTraffic,Vidar",
            "anonymous": "0",
            "reporter": "varysz"
        }
    ],
    "1817530": [
        {
            "ioc_value": "2fa-cp.click",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-05-23 08:58:34",
            "last_seen_utc": "2026-06-29 13:38:21",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "ClickFix,ErrTraffic,Vidar",
            "anonymous": "0",
            "reporter": "varysz"
        }
    ],
    "1817537": [
        {
            "ioc_value": "1.117.77.166:3310",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-05-23 08:58:34",
            "last_seen_utc": "2026-06-29 10:46:16",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": null,
            "tags": "45090,c2,censys,cobalt strike",
            "anonymous": "0",
            "reporter": "sojubear"
        }
    ],
    "1817426": [
        {
            "ioc_value": "87.251.76.213:8443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-05-22 19:45:34",
            "last_seen_utc": "2026-06-30 10:46:13",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1817206": [
        {
            "ioc_value": "46.20.109.225:8999",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-05-22 11:36:04",
            "last_seen_utc": "2026-06-30 10:47:07",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "",
            "tags": "Agentemis,BEACON,Cobalt Strike,CobaltStrike,cobeacon",
            "anonymous": "0",
            "reporter": "whoamix302"
        }
    ],
    "1817235": [
        {
            "ioc_value": "31.57.184.154:7006",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-05-22 09:44:40",
            "last_seen_utc": "2026-06-30 10:45:24",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1817233": [
        {
            "ioc_value": "31.171.131.118:7707",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-05-22 09:44:39",
            "last_seen_utc": "2026-06-30 10:45:23",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1817234": [
        {
            "ioc_value": "31.171.131.118:8808",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-05-22 09:44:39",
            "last_seen_utc": "2026-06-30 10:45:23",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1817215": [
        {
            "ioc_value": "154.201.68.191:14125",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-05-22 08:46:18",
            "last_seen_utc": "2026-06-30 10:46:48",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1817132": [
        {
            "ioc_value": "129.204.14.131:44444",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-05-22 08:11:41",
            "last_seen_utc": "2026-06-30 10:46:44",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": null,
            "tags": "45090,c2,censys,cobalt strike",
            "anonymous": "0",
            "reporter": "sojubear"
        }
    ],
    "1817193": [
        {
            "ioc_value": "207.180.250.181:20700",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-05-22 08:11:23",
            "last_seen_utc": "2026-06-30 10:44:31",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "asyncrat",
            "anonymous": "1",
            "reporter": "_ik_"
        }
    ],
    "1817187": [
        {
            "ioc_value": "47.236.110.1:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-05-22 07:55:22",
            "last_seen_utc": "2026-06-30 10:47:10",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-100000",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1817184": [
        {
            "ioc_value": "23.236.64.231:8443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-05-22 07:55:19",
            "last_seen_utc": "2026-06-30 10:46:58",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-987654321",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1817114": [
        {
            "ioc_value": "193.142.146.30:6555",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-05-21 22:46:34",
            "last_seen_utc": "2026-06-28 12:46:14",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1817055": [
        {
            "ioc_value": "42.121.150.29:4506",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.deimos_c2",
            "malware_alias": null,
            "malware_printable": "DeimosC2",
            "first_seen_utc": "2026-05-21 19:45:14",
            "last_seen_utc": "2026-06-30 10:45:32",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "Deimos,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1817054": [
        {
            "ioc_value": "34.61.52.162:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-05-21 19:45:07",
            "last_seen_utc": "2026-06-30 10:45:27",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1817053": [
        {
            "ioc_value": "193.29.13.23:5758",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-05-21 19:44:01",
            "last_seen_utc": "2026-06-30 10:44:17",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1817051": [
        {
            "ioc_value": "157.230.125.65:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-05-21 19:43:30",
            "last_seen_utc": "2026-06-30 10:43:38",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1816875": [
        {
            "ioc_value": "156.225.22.84:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-05-21 07:19:52",
            "last_seen_utc": "2026-06-30 10:46:48",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-987654321",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1816747": [
        {
            "ioc_value": "154.201.68.191:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-05-21 05:01:18",
            "last_seen_utc": "2026-06-30 09:53:51",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "cobaltstrike",
            "anonymous": "1",
            "reporter": "_ik_"
        }
    ],
    "1816738": [
        {
            "ioc_value": "41.216.189.163:43210",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-05-20 19:44:41",
            "last_seen_utc": "2026-06-30 10:45:32",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1816737": [
        {
            "ioc_value": "221.207.101.175:4506",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.deimos_c2",
            "malware_alias": null,
            "malware_printable": "DeimosC2",
            "first_seen_utc": "2026-05-20 19:44:32",
            "last_seen_utc": "2026-06-30 10:45:18",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "Deimos,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1816585": [
        {
            "ioc_value": "51.15.8.6:9998",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.sliver",
            "malware_alias": null,
            "malware_printable": "Sliver",
            "first_seen_utc": "2026-05-20 09:45:05",
            "last_seen_utc": "2026-06-30 10:45:54",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Sliver",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1816583": [
        {
            "ioc_value": "202.1.31.83:4321",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-05-20 09:43:56",
            "last_seen_utc": "2026-06-30 10:44:27",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1816582": [
        {
            "ioc_value": "18.178.185.250:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.brute_ratel_c4",
            "malware_alias": "BOLDBADGER,BruteRatel",
            "malware_printable": "Brute Ratel C4",
            "first_seen_utc": "2026-05-20 09:43:40",
            "last_seen_utc": "2026-06-29 08:43:49",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "BruteRatel,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1816581": [
        {
            "ioc_value": "178.212.13.29:4321",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-05-20 09:43:39",
            "last_seen_utc": "2026-06-30 10:43:54",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1816563": [
        {
            "ioc_value": "1.92.101.103:8088",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-05-20 08:54:33",
            "last_seen_utc": "2026-06-30 10:46:30",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "cobaltstrike",
            "anonymous": "1",
            "reporter": "_ik_"
        }
    ],
    "1816553": [
        {
            "ioc_value": "103.149.93.107:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-05-20 07:37:44",
            "last_seen_utc": "2026-06-30 10:46:31",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-987654321",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1816551": [
        {
            "ioc_value": "45.152.65.240:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-05-20 07:37:42",
            "last_seen_utc": "2026-06-30 10:47:06",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-666666666",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1816481": [
        {
            "ioc_value": "114.134.187.38:8080",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-05-20 05:25:02",
            "last_seen_utc": "2026-06-30 10:46:35",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "cobaltstrike",
            "anonymous": "1",
            "reporter": "_ik_"
        }
    ],
    "1816445": [
        {
            "ioc_value": "43.142.137.169:18443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-05-19 20:46:09",
            "last_seen_utc": "2026-06-30 10:47:04",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1816431": [
        {
            "ioc_value": "91.202.233.214:44123",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-05-19 19:45:18",
            "last_seen_utc": "2026-06-30 10:46:16",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1816427": [
        {
            "ioc_value": "31.57.184.154:2502",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-05-19 19:44:36",
            "last_seen_utc": "2026-06-30 10:45:23",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1816314": [
        {
            "ioc_value": "111.230.36.144:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-05-19 14:00:01",
            "last_seen_utc": "2026-06-30 10:46:34",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "cobaltstrike",
            "anonymous": "1",
            "reporter": "_ik_"
        }
    ],
    "1816296": [
        {
            "ioc_value": "176.120.22.127:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.poshc2",
            "malware_alias": null,
            "malware_printable": "PoshC2",
            "first_seen_utc": "2026-05-19 09:43:37",
            "last_seen_utc": "2026-06-30 08:43:52",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PoshC2",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1816294": [
        {
            "ioc_value": "142.93.165.129:3334",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.evilginx",
            "malware_alias": null,
            "malware_printable": "Evilginx",
            "first_seen_utc": "2026-05-19 09:43:19",
            "last_seen_utc": "2026-06-30 10:43:25",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Evilginx,EvilGoPhish",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1816252": [
        {
            "ioc_value": "45.152.65.240:8080",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-05-19 06:46:32",
            "last_seen_utc": "2026-06-30 10:47:06",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-666666666",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1816248": [
        {
            "ioc_value": "111.230.36.144:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-05-19 06:46:14",
            "last_seen_utc": "2026-06-30 10:46:34",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-987654321",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1816209": [
        {
            "ioc_value": "172.94.18.103:76",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-05-19 05:16:26",
            "last_seen_utc": "2026-06-30 10:43:51",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "asyncrat",
            "anonymous": "1",
            "reporter": "_ik_"
        }
    ],
    "1816173": [
        {
            "ioc_value": "43.143.145.187:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-05-19 05:16:16",
            "last_seen_utc": "2026-06-30 10:47:04",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": null,
            "tags": "45090,c2,censys,cobalt strike",
            "anonymous": "0",
            "reporter": "sojubear"
        }
    ],
    "1816172": [
        {
            "ioc_value": "47.82.234.12:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-05-19 05:16:15",
            "last_seen_utc": "2026-06-30 10:47:12",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": null,
            "tags": "c2,censys,cobalt strike",
            "anonymous": "0",
            "reporter": "sojubear"
        }
    ],
    "1816164": [
        {
            "ioc_value": "119.91.26.245:6666",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-05-19 05:16:06",
            "last_seen_utc": "2026-06-30 10:46:40",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": null,
            "tags": "45090,c2,censys,cobalt strike",
            "anonymous": "0",
            "reporter": "sojubear"
        }
    ],
    "1816110": [
        {
            "ioc_value": "43.144.19.220:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-05-19 05:15:34",
            "last_seen_utc": "2026-06-30 10:47:04",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "cobaltstrike",
            "anonymous": "1",
            "reporter": "_ik_"
        }
    ],
    "1816141": [
        {
            "ioc_value": "1.117.61.9:12306",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-05-18 22:47:21",
            "last_seen_utc": "2026-06-30 10:46:29",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1816102": [
        {
            "ioc_value": "5.101.81.2:51842",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-05-18 19:44:41",
            "last_seen_utc": "2026-06-30 10:45:47",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1816100": [
        {
            "ioc_value": "38.147.189.199:9001",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pupy",
            "malware_alias": "Patpoopy",
            "malware_printable": "pupy",
            "first_seen_utc": "2026-05-18 19:44:31",
            "last_seen_utc": "2026-06-30 10:45:29",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PupyRAT,RAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1816096": [
        {
            "ioc_value": "138.124.90.26:51337",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-05-18 19:43:13",
            "last_seen_utc": "2026-06-30 10:43:23",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1816095": [
        {
            "ioc_value": "130.49.214.92:53522",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-05-18 19:43:11",
            "last_seen_utc": "2026-06-30 10:43:21",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1816094": [
        {
            "ioc_value": "101.99.95.16:2850",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.evilginx",
            "malware_alias": null,
            "malware_printable": "Evilginx",
            "first_seen_utc": "2026-05-18 19:43:02",
            "last_seen_utc": "2026-06-30 10:43:03",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Evilginx,EvilGoPhish",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1816036": [
        {
            "ioc_value": "207.180.250.181:8808",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-05-18 18:05:44",
            "last_seen_utc": "2026-06-30 10:44:31",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "asyncrat",
            "anonymous": "1",
            "reporter": "_ik_"
        }
    ],
    "1815876": [
        {
            "ioc_value": "175.178.36.137:8011",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-05-18 11:28:05",
            "last_seen_utc": "2026-06-30 10:46:52",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "cobaltstrike",
            "anonymous": "1",
            "reporter": "_ik_"
        }
    ],
    "1815946": [
        {
            "ioc_value": "62.234.22.228:51234",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-05-18 10:46:24",
            "last_seen_utc": "2026-06-30 10:47:14",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1815930": [
        {
            "ioc_value": "46.8.226.70:31337",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.sliver",
            "malware_alias": null,
            "malware_printable": "Sliver",
            "first_seen_utc": "2026-05-18 09:44:56",
            "last_seen_utc": "2026-06-30 10:45:46",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Sliver",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1815931": [
        {
            "ioc_value": "46.8.226.70:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.sliver",
            "malware_alias": null,
            "malware_printable": "Sliver",
            "first_seen_utc": "2026-05-18 09:44:56",
            "last_seen_utc": "2026-06-30 10:45:46",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Sliver",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1815927": [
        {
            "ioc_value": "163.181.46.56:4506",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.deimos_c2",
            "malware_alias": null,
            "malware_printable": "DeimosC2",
            "first_seen_utc": "2026-05-18 09:43:30",
            "last_seen_utc": "2026-06-30 10:43:43",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "Deimos,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1815818": [
        {
            "ioc_value": "47.236.91.172:8000",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-05-18 07:33:49",
            "last_seen_utc": "2026-06-30 10:47:11",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "cobaltstrike",
            "anonymous": "1",
            "reporter": "_ik_"
        }
    ],
    "1815757": [
        {
            "ioc_value": "124.220.36.247:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-05-18 07:33:34",
            "last_seen_utc": "2026-06-30 10:46:42",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "cobaltstrike",
            "anonymous": "1",
            "reporter": "_ik_"
        }
    ],
    "1815737": [
        {
            "ioc_value": "81.68.216.220:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-05-18 07:33:28",
            "last_seen_utc": "2026-06-30 10:47:18",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "cobaltstrike",
            "anonymous": "1",
            "reporter": "_ik_"
        }
    ],
    "1815736": [
        {
            "ioc_value": "81.68.216.220:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-05-18 07:33:27",
            "last_seen_utc": "2026-06-30 10:47:18",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "cobaltstrike",
            "anonymous": "1",
            "reporter": "_ik_"
        }
    ],
    "1815832": [
        {
            "ioc_value": "172.86.76.154:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-05-18 07:26:30",
            "last_seen_utc": "2026-06-30 10:46:52",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-987654321",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1815762": [
        {
            "ioc_value": "119.29.112.239:8005",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-05-17 22:45:31",
            "last_seen_utc": "2026-06-30 10:46:40",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1815551": [
        {
            "ioc_value": "207.56.229.234:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-05-17 15:53:07",
            "last_seen_utc": "2026-06-30 10:46:56",
            "confidence_level": 80,
            "is_compromised": false,
            "reference": null,
            "tags": "cobalt-strike,erebus-wraith,unattributed",
            "anonymous": "0",
            "reporter": "Erebu"
        }
    ],
    "1815616": [
        {
            "ioc_value": "angelphonerepair.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-05-17 15:52:22",
            "last_seen_utc": "2026-06-30 06:03:09",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": "",
            "tags": "ClickFix,compromised,etherhiding,Polygon,Vidar,WordPress",
            "anonymous": "0",
            "reporter": "varysz"
        }
    ],
    "1815627": [
        {
            "ioc_value": "istriamaestranza.cl",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-05-17 15:52:11",
            "last_seen_utc": "2026-06-30 06:03:07",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": "",
            "tags": "ClickFix,compromised,etherhiding,Polygon,Vidar,WordPress",
            "anonymous": "0",
            "reporter": "varysz"
        }
    ],
    "1815631": [
        {
            "ioc_value": "thegingamebroadway.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-05-17 15:52:08",
            "last_seen_utc": "2026-06-30 06:03:07",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": "",
            "tags": "ClickFix,compromised,etherhiding,Polygon,Vidar,WordPress",
            "anonymous": "0",
            "reporter": "varysz"
        }
    ],
    "1815461": [
        {
            "ioc_value": "81.71.20.155:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-05-17 06:52:36",
            "last_seen_utc": "2026-06-30 10:47:18",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "cobaltstrike",
            "anonymous": "1",
            "reporter": "_ik_"
        }
    ],
    "1815481": [
        {
            "ioc_value": "47.236.91.172:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-05-17 03:45:47",
            "last_seen_utc": "2026-06-30 10:47:11",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1815397": [
        {
            "ioc_value": "45.155.69.153:43345",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-05-16 19:45:35",
            "last_seen_utc": "2026-06-30 10:45:37",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1815392": [
        {
            "ioc_value": "103.219.153.200:7707",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-05-16 19:43:06",
            "last_seen_utc": "2026-06-30 10:43:09",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1815393": [
        {
            "ioc_value": "103.219.153.200:8808",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-05-16 19:43:06",
            "last_seen_utc": "2026-06-30 10:43:09",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1815391": [
        {
            "ioc_value": "103.219.153.200:6606",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-05-16 19:43:05",
            "last_seen_utc": "2026-06-30 10:43:09",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1815258": [
        {
            "ioc_value": "193.169.194.51:6325",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-05-16 09:43:55",
            "last_seen_utc": "2026-06-30 10:44:16",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1815137": [
        {
            "ioc_value": "95.231.168.143:4483",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.netsupportmanager_rat",
            "malware_alias": "NetSupport",
            "malware_printable": "NetSupportManager RAT",
            "first_seen_utc": "2026-05-15 19:44:50",
            "last_seen_utc": "2026-06-30 10:46:18",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,NetSupport,RAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1815134": [
        {
            "ioc_value": "4.235.114.15:1024",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.dcrat",
            "malware_alias": "DarkCrystal RAT",
            "malware_printable": "DCRat",
            "first_seen_utc": "2026-05-15 19:44:21",
            "last_seen_utc": "2026-06-30 08:45:31",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DCRat,drb-ra,RAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1815133": [
        {
            "ioc_value": "34.69.130.10:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.chaos",
            "malware_alias": "FakeRyuk,RyukJoke,Yashma",
            "malware_printable": "Chaos",
            "first_seen_utc": "2026-05-15 19:44:19",
            "last_seen_utc": "2026-06-30 10:45:27",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CHAOS,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1815127": [
        {
            "ioc_value": "137.184.102.191:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.havoc",
            "malware_alias": "Havokiz",
            "malware_printable": "Havoc",
            "first_seen_utc": "2026-05-15 19:43:12",
            "last_seen_utc": "2026-06-30 10:43:22",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Havoc",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1815073": [
        {
            "ioc_value": "pgo.fatherchrismas.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-05-15 16:00:12",
            "last_seen_utc": "2026-06-30 11:23:11",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "vidar",
            "anonymous": "0",
            "reporter": "crep1x"
        }
    ],
    "1815074": [
        {
            "ioc_value": "https://pgo.fatherchrismas.com/",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-05-15 16:00:12",
            "last_seen_utc": "2026-06-30 11:23:11",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "vidar",
            "anonymous": "0",
            "reporter": "crep1x"
        }
    ],
    "1814914": [
        {
            "ioc_value": "207.56.229.234:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-05-15 13:48:12",
            "last_seen_utc": "2026-06-30 10:46:56",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-666666666",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1814528": [
        {
            "ioc_value": "5.101.81.2:63676",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-05-15 09:44:54",
            "last_seen_utc": "2026-06-30 10:45:48",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1812322": [
        {
            "ioc_value": "1.117.61.9:8443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-05-14 22:45:41",
            "last_seen_utc": "2026-06-30 10:46:29",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1812320": [
        {
            "ioc_value": "ct.feliz.icu",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-05-14 22:45:33",
            "last_seen_utc": "2026-06-30 10:46:22",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1812283": [
        {
            "ioc_value": "95.141.133.7:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-05-14 19:47:27",
            "last_seen_utc": "2026-06-30 10:46:18",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "Covenant,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1812280": [
        {
            "ioc_value": "104.243.248.63:1806",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-05-14 19:43:12",
            "last_seen_utc": "2026-06-29 08:43:11",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1811874": [
        {
            "ioc_value": "8.218.224.15:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-05-14 12:36:52",
            "last_seen_utc": "2026-06-30 10:47:17",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "cobaltstrike",
            "anonymous": "1",
            "reporter": "_ik_"
        }
    ],
    "1812137": [
        {
            "ioc_value": "207.56.226.75:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-05-14 12:33:41",
            "last_seen_utc": "2026-06-30 10:46:56",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "cobaltstrike",
            "anonymous": "1",
            "reporter": "_ik_"
        }
    ],
    "1811554": [
        {
            "ioc_value": "chameleoninserts.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-05-14 12:32:21",
            "last_seen_utc": "2026-06-30 06:03:07",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": "",
            "tags": "ClickFix,compromised,etherhiding,Polygon,Vidar,WordPress",
            "anonymous": "0",
            "reporter": "varysz"
        }
    ],
    "1812148": [
        {
            "ioc_value": "147.78.2.110:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-05-14 12:14:39",
            "last_seen_utc": "2026-06-30 10:46:46",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-987654321",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1812126": [
        {
            "ioc_value": "84.46.251.62:4321",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-05-14 09:51:34",
            "last_seen_utc": "2026-06-30 10:46:11",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1811948": [
        {
            "ioc_value": "5.101.83.144:9521",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-05-13 19:45:08",
            "last_seen_utc": "2026-06-30 10:45:49",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1811945": [
        {
            "ioc_value": "43.230.162.44:14321",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-05-13 19:44:54",
            "last_seen_utc": "2026-06-30 10:45:34",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1811942": [
        {
            "ioc_value": "194.33.48.221:8443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.havoc",
            "malware_alias": "Havokiz",
            "malware_printable": "Havoc",
            "first_seen_utc": "2026-05-13 19:43:53",
            "last_seen_utc": "2026-06-30 10:44:19",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Havoc",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1811939": [
        {
            "ioc_value": "103.197.191.159:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.chaos",
            "malware_alias": "FakeRyuk,RyukJoke,Yashma",
            "malware_printable": "Chaos",
            "first_seen_utc": "2026-05-13 19:43:03",
            "last_seen_utc": "2026-06-28 18:43:07",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CHAOS,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1811762": [
        {
            "ioc_value": "203.202.232.22:3131",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-05-13 09:43:56",
            "last_seen_utc": "2026-06-30 10:44:28",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1811761": [
        {
            "ioc_value": "194.33.48.221:8081",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.havoc",
            "malware_alias": "Havokiz",
            "malware_printable": "Havoc",
            "first_seen_utc": "2026-05-13 09:43:50",
            "last_seen_utc": "2026-06-30 10:44:19",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Havoc",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1811650": [
        {
            "ioc_value": "168.222.97.93:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-05-12 22:45:18",
            "last_seen_utc": "2026-06-30 10:46:51",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1811651": [
        {
            "ioc_value": "168.222.97.93:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-05-12 22:45:18",
            "last_seen_utc": "2026-06-30 10:46:51",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1811649": [
        {
            "ioc_value": "161.248.87.10:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-05-12 22:45:17",
            "last_seen_utc": "2026-06-30 10:46:50",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1811234": [
        {
            "ioc_value": "190.255.90.152:6000",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-05-12 14:50:32",
            "last_seen_utc": "2026-06-28 18:43:56",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": null,
            "tags": "3816,asyncrat,c2,censys",
            "anonymous": "0",
            "reporter": "sojubear"
        }
    ],
    "1811440": [
        {
            "ioc_value": "http://cdntestconnect.com/ed54b97a570943999715.php",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.stealc",
            "malware_alias": null,
            "malware_printable": "Stealc",
            "first_seen_utc": "2026-05-12 14:48:59",
            "last_seen_utc": "2026-06-30 11:17:52",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "c2,first,loader,StealC,stealer",
            "anonymous": "0",
            "reporter": "Bitsight"
        }
    ],
    "1811412": [
        {
            "ioc_value": "117.72.168.103:50011",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-05-12 11:45:38",
            "last_seen_utc": "2026-06-30 10:46:38",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1811400": [
        {
            "ioc_value": "91.215.85.121:6466",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.dcrat",
            "malware_alias": "DarkCrystal RAT",
            "malware_printable": "DCRat",
            "first_seen_utc": "2026-05-12 09:45:17",
            "last_seen_utc": "2026-06-30 10:46:16",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DCRat,drb-ra,RAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1811399": [
        {
            "ioc_value": "85.158.57.247:4321",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-05-12 09:45:14",
            "last_seen_utc": "2026-06-30 10:46:12",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1811398": [
        {
            "ioc_value": "67.180.188.88:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-05-12 09:45:04",
            "last_seen_utc": "2026-06-30 10:46:01",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1811389": [
        {
            "ioc_value": "207.148.2.115:60060",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.sliver",
            "malware_alias": null,
            "malware_printable": "Sliver",
            "first_seen_utc": "2026-05-12 09:43:50",
            "last_seen_utc": "2026-06-30 10:44:30",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Sliver",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1811390": [
        {
            "ioc_value": "207.148.2.115:60061",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.sliver",
            "malware_alias": null,
            "malware_printable": "Sliver",
            "first_seen_utc": "2026-05-12 09:43:50",
            "last_seen_utc": "2026-06-30 10:44:30",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Sliver",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1811387": [
        {
            "ioc_value": "155.103.71.115:14549",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-05-12 09:43:21",
            "last_seen_utc": "2026-06-28 18:43:28",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1811187": [
        {
            "ioc_value": "mpd.pegasus-77.biz.id",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-05-11 23:00:12",
            "last_seen_utc": "2026-06-30 11:22:50",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "vidar",
            "anonymous": "0",
            "reporter": "crep1x"
        }
    ],
    "1811188": [
        {
            "ioc_value": "https://mpd.pegasus-77.biz.id/",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-05-11 23:00:12",
            "last_seen_utc": "2026-06-30 11:22:50",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "vidar",
            "anonymous": "0",
            "reporter": "crep1x"
        }
    ],
    "1811186": [
        {
            "ioc_value": "117.50.184.221:10080",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-05-11 22:45:16",
            "last_seen_utc": "2026-06-30 10:46:37",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1811185": [
        {
            "ioc_value": "112.124.71.123:55555",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-05-11 22:45:14",
            "last_seen_utc": "2026-06-30 10:46:34",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1811129": [
        {
            "ioc_value": "64.199.252.59:3333",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.evilginx",
            "malware_alias": null,
            "malware_printable": "Evilginx",
            "first_seen_utc": "2026-05-11 19:45:07",
            "last_seen_utc": "2026-06-30 10:45:58",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Evilginx,EvilGoPhish",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1811128": [
        {
            "ioc_value": "51.77.54.76:6769",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-05-11 19:45:01",
            "last_seen_utc": "2026-06-30 10:45:54",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1811127": [
        {
            "ioc_value": "46.253.143.52:4321",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-05-11 19:44:51",
            "last_seen_utc": "2026-06-30 10:45:45",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1811126": [
        {
            "ioc_value": "45.77.89.29:4321",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-05-11 19:44:49",
            "last_seen_utc": "2026-06-30 10:45:42",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1811125": [
        {
            "ioc_value": "213.139.77.243:55555",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.eye_pyramid",
            "malware_alias": null,
            "malware_printable": "Eye Pyramid",
            "first_seen_utc": "2026-05-11 19:43:58",
            "last_seen_utc": "2026-06-30 10:44:35",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,EyePyramid",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1811124": [
        {
            "ioc_value": "185.212.128.72:9000",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.evilginx",
            "malware_alias": null,
            "malware_printable": "Evilginx",
            "first_seen_utc": "2026-05-11 19:43:39",
            "last_seen_utc": "2026-06-30 10:44:06",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Evilginx,EvilGoPhish",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1811123": [
        {
            "ioc_value": "185.190.142.66:4321",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-05-11 19:43:38",
            "last_seen_utc": "2026-06-30 10:44:05",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1811118": [
        {
            "ioc_value": "109.73.193.242:10140",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-05-11 19:43:08",
            "last_seen_utc": "2026-06-30 10:43:16",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1810965": [
        {
            "ioc_value": "89.42.134.220:7707",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-05-11 09:45:15",
            "last_seen_utc": "2026-06-30 10:46:15",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1810961": [
        {
            "ioc_value": "44.215.161.149:4005",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.havoc",
            "malware_alias": "Havokiz",
            "malware_printable": "Havoc",
            "first_seen_utc": "2026-05-11 09:44:36",
            "last_seen_utc": "2026-06-30 10:45:34",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Havoc",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1810960": [
        {
            "ioc_value": "43.133.149.36:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-05-11 09:44:35",
            "last_seen_utc": "2026-06-30 10:45:32",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1810959": [
        {
            "ioc_value": "31.57.184.154:7007",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-05-11 09:44:29",
            "last_seen_utc": "2026-06-30 10:45:24",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1810958": [
        {
            "ioc_value": "20.114.142.61:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-05-11 09:43:46",
            "last_seen_utc": "2026-06-30 10:44:27",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1810956": [
        {
            "ioc_value": "193.169.194.19:8264",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-05-11 09:43:41",
            "last_seen_utc": "2026-06-30 10:44:16",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1810955": [
        {
            "ioc_value": "185.242.245.27:44875",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-05-11 09:43:35",
            "last_seen_utc": "2026-06-30 10:44:09",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1810954": [
        {
            "ioc_value": "185.212.128.76:9000",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.evilginx",
            "malware_alias": null,
            "malware_printable": "Evilginx",
            "first_seen_utc": "2026-05-11 09:43:34",
            "last_seen_utc": "2026-06-30 10:44:06",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Evilginx,EvilGoPhish",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1810952": [
        {
            "ioc_value": "172.239.57.52:1234",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-05-11 09:43:26",
            "last_seen_utc": "2026-06-30 10:43:48",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1810953": [
        {
            "ioc_value": "172.245.97.237:2030",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.evilginx",
            "malware_alias": null,
            "malware_printable": "Evilginx",
            "first_seen_utc": "2026-05-11 09:43:26",
            "last_seen_utc": "2026-06-30 10:43:49",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Evilginx,EvilGoPhish",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1810949": [
        {
            "ioc_value": "144.91.78.57:9008",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-05-11 09:43:15",
            "last_seen_utc": "2026-06-30 10:43:27",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1810947": [
        {
            "ioc_value": "130.12.182.209:1525",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-05-11 09:43:09",
            "last_seen_utc": "2026-06-30 10:43:21",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1810462": [
        {
            "ioc_value": "150.158.109.61:9090",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-05-10 23:45:17",
            "last_seen_utc": "2026-06-30 10:46:46",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1810461": [
        {
            "ioc_value": "112.213.106.53:18443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-05-10 23:45:07",
            "last_seen_utc": "2026-06-30 10:46:34",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1810418": [
        {
            "ioc_value": "64.23.231.32:9001",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.sliver",
            "malware_alias": null,
            "malware_printable": "Sliver",
            "first_seen_utc": "2026-05-10 19:44:55",
            "last_seen_utc": "2026-06-30 10:45:59",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Sliver",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1810414": [
        {
            "ioc_value": "31.57.184.154:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-05-10 19:44:31",
            "last_seen_utc": "2026-06-30 10:45:23",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1810413": [
        {
            "ioc_value": "24.134.4.221:4714",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.netsupportmanager_rat",
            "malware_alias": "NetSupport",
            "malware_printable": "NetSupportManager RAT",
            "first_seen_utc": "2026-05-10 19:44:30",
            "last_seen_utc": "2026-06-30 10:45:21",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,NetSupport,RAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1810410": [
        {
            "ioc_value": "195.123.240.236:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.ransomhub",
            "malware_alias": null,
            "malware_printable": "RansomHub",
            "first_seen_utc": "2026-05-10 19:43:45",
            "last_seen_utc": "2026-06-30 10:44:20",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RansomHub",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1810411": [
        {
            "ioc_value": "195.123.240.236:8274",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.ransomhub",
            "malware_alias": null,
            "malware_printable": "RansomHub",
            "first_seen_utc": "2026-05-10 19:43:45",
            "last_seen_utc": "2026-06-30 10:44:20",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RansomHub",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1810408": [
        {
            "ioc_value": "189.34.188.6:5406",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.netsupportmanager_rat",
            "malware_alias": "NetSupport",
            "malware_printable": "NetSupportManager RAT",
            "first_seen_utc": "2026-05-10 19:43:39",
            "last_seen_utc": "2026-06-30 10:44:12",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,NetSupport,RAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1810409": [
        {
            "ioc_value": "189.34.188.6:5407",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.netsupportmanager_rat",
            "malware_alias": "NetSupport",
            "malware_printable": "NetSupportManager RAT",
            "first_seen_utc": "2026-05-10 19:43:39",
            "last_seen_utc": "2026-06-30 10:44:12",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,NetSupport,RAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1809884": [
        {
            "ioc_value": "diversidadecatolica.com.br",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-05-10 18:56:50",
            "last_seen_utc": "2026-06-30 06:03:07",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": "",
            "tags": "ClickFix,compromised,etherhiding,Polygon,Vidar,WordPress",
            "anonymous": "0",
            "reporter": "varysz"
        }
    ],
    "1809914": [
        {
            "ioc_value": "m1-ma.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-05-10 18:56:17",
            "last_seen_utc": "2026-06-30 06:05:30",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": "",
            "tags": "ClickFix,compromised,etherhiding,Polygon,Vidar,WordPress",
            "anonymous": "0",
            "reporter": "varysz"
        }
    ],
    "1809924": [
        {
            "ioc_value": "pastquestion.com.ng",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-05-10 18:56:03",
            "last_seen_utc": "2026-06-30 06:05:32",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": "",
            "tags": "ClickFix,compromised,etherhiding,Polygon,Vidar,WordPress",
            "anonymous": "0",
            "reporter": "varysz"
        }
    ],
    "1809928": [
        {
            "ioc_value": "prediksitaysen88.cloud",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-05-10 18:56:00",
            "last_seen_utc": "2026-06-30 06:03:08",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": "",
            "tags": "ClickFix,compromised,etherhiding,Polygon,Vidar,WordPress",
            "anonymous": "0",
            "reporter": "varysz"
        }
    ],
    "1809935": [
        {
            "ioc_value": "sapienharvest.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-05-10 18:55:52",
            "last_seen_utc": "2026-06-30 06:03:09",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": "",
            "tags": "ClickFix,compromised,etherhiding,Polygon,Vidar,WordPress",
            "anonymous": "0",
            "reporter": "varysz"
        }
    ],
    "1809940": [
        {
            "ioc_value": "staybadparamotor.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-05-10 18:55:48",
            "last_seen_utc": "2026-06-30 06:03:08",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": "",
            "tags": "ClickFix,compromised,etherhiding,Polygon,Vidar,WordPress",
            "anonymous": "0",
            "reporter": "varysz"
        }
    ],
    "1809980": [
        {
            "ioc_value": "129.211.2.123:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-05-10 18:42:12",
            "last_seen_utc": "2026-06-30 10:46:44",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": null,
            "tags": "45090,c2,censys,cobalt strike",
            "anonymous": "0",
            "reporter": "sojubear"
        }
    ],
    "1809984": [
        {
            "ioc_value": "1.92.101.103:8099",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-05-10 18:42:09",
            "last_seen_utc": "2026-06-30 10:46:30",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": null,
            "tags": "55990,c2,censys,cobalt strike",
            "anonymous": "0",
            "reporter": "sojubear"
        }
    ],
    "1810170": [
        {
            "ioc_value": "57.158.27.132:8080",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.sliver",
            "malware_alias": null,
            "malware_printable": "Sliver",
            "first_seen_utc": "2026-05-10 09:44:56",
            "last_seen_utc": "2026-06-30 10:45:56",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Sliver",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1810169": [
        {
            "ioc_value": "43.133.149.36:18080",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-05-10 09:44:39",
            "last_seen_utc": "2026-06-30 10:45:32",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1810164": [
        {
            "ioc_value": "179.43.134.189:9968",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-05-10 09:43:33",
            "last_seen_utc": "2026-06-30 10:43:54",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1809754": [
        {
            "ioc_value": "213.130.25.141:44333",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.netsupportmanager_rat",
            "malware_alias": "NetSupport",
            "malware_printable": "NetSupportManager RAT",
            "first_seen_utc": "2026-05-09 19:43:46",
            "last_seen_utc": "2026-06-30 10:44:35",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,NetSupport,RAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1809750": [
        {
            "ioc_value": "168.144.89.48:8443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-05-09 19:43:24",
            "last_seen_utc": "2026-06-30 10:43:46",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1809749": [
        {
            "ioc_value": "167.99.151.149:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-05-09 19:43:23",
            "last_seen_utc": "2026-06-30 10:43:45",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1809219": [
        {
            "ioc_value": "139.196.50.117:9930",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-05-08 23:44:52",
            "last_seen_utc": "2026-06-30 10:46:45",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1809052": [
        {
            "ioc_value": "83.142.209.60:8795",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-05-08 19:44:36",
            "last_seen_utc": "2026-06-30 10:46:10",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1809046": [
        {
            "ioc_value": "64.90.19.46:5432",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-05-08 19:44:32",
            "last_seen_utc": "2026-06-30 10:46:01",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1809043": [
        {
            "ioc_value": "5.101.86.105:4509",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-05-08 19:44:25",
            "last_seen_utc": "2026-06-30 10:45:50",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1809039": [
        {
            "ioc_value": "209.38.100.109:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-05-08 19:43:41",
            "last_seen_utc": "2026-06-30 10:44:32",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1809038": [
        {
            "ioc_value": "193.42.24.165:4848",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-05-08 19:43:36",
            "last_seen_utc": "2026-06-30 10:44:18",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1809037": [
        {
            "ioc_value": "193.169.194.24:2509",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-05-08 19:43:35",
            "last_seen_utc": "2026-06-30 10:44:16",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1809034": [
        {
            "ioc_value": "185.212.128.15:9000",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.evilginx",
            "malware_alias": null,
            "malware_printable": "Evilginx",
            "first_seen_utc": "2026-05-08 19:43:29",
            "last_seen_utc": "2026-06-30 10:44:06",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Evilginx,EvilGoPhish",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1809035": [
        {
            "ioc_value": "185.212.128.24:9000",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.evilginx",
            "malware_alias": null,
            "malware_printable": "Evilginx",
            "first_seen_utc": "2026-05-08 19:43:29",
            "last_seen_utc": "2026-06-30 10:44:06",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Evilginx,EvilGoPhish",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1809033": [
        {
            "ioc_value": "180.97.214.70:4506",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.deimos_c2",
            "malware_alias": null,
            "malware_printable": "DeimosC2",
            "first_seen_utc": "2026-05-08 19:43:28",
            "last_seen_utc": "2026-06-30 10:43:55",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "Deimos,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1809029": [
        {
            "ioc_value": "160.25.82.142:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-05-08 19:43:19",
            "last_seen_utc": "2026-06-30 10:43:40",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1809027": [
        {
            "ioc_value": "146.185.239.61:9702",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-05-08 19:43:15",
            "last_seen_utc": "2026-06-30 10:43:27",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1808742": [
        {
            "ioc_value": "47.83.254.175:1102",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-05-08 10:44:29",
            "last_seen_utc": "2026-06-30 10:47:12",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1808741": [
        {
            "ioc_value": "1364170351-kld29tgkc1.ap-guangzhou.tencentscf.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-05-08 10:43:48",
            "last_seen_utc": "2026-06-30 10:46:20",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1808661": [
        {
            "ioc_value": "5.101.86.95:4034",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-05-08 08:43:53",
            "last_seen_utc": "2026-06-30 10:45:51",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1808659": [
        {
            "ioc_value": "5.101.86.41:3305",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-05-08 08:43:51",
            "last_seen_utc": "2026-06-30 10:45:50",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1808655": [
        {
            "ioc_value": "5.101.83.117:8374",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-05-08 08:43:49",
            "last_seen_utc": "2026-06-30 10:45:49",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1808654": [
        {
            "ioc_value": "5.101.82.226:3581",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-05-08 08:43:48",
            "last_seen_utc": "2026-06-30 10:45:48",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1808653": [
        {
            "ioc_value": "5.101.81.23:4315",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-05-08 08:43:47",
            "last_seen_utc": "2026-06-30 10:45:48",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1808650": [
        {
            "ioc_value": "45.56.91.55:2005",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-05-08 08:43:45",
            "last_seen_utc": "2026-06-30 10:45:40",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "Covenant,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1808643": [
        {
            "ioc_value": "209.38.110.161:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-05-08 08:43:21",
            "last_seen_utc": "2026-06-30 10:44:32",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1808639": [
        {
            "ioc_value": "185.212.129.114:9000",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.evilginx",
            "malware_alias": null,
            "malware_printable": "Evilginx",
            "first_seen_utc": "2026-05-08 08:43:15",
            "last_seen_utc": "2026-06-30 10:44:07",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Evilginx,EvilGoPhish",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1808637": [
        {
            "ioc_value": "178.104.186.90:4321",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-05-08 08:43:13",
            "last_seen_utc": "2026-06-30 10:43:52",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1808633": [
        {
            "ioc_value": "146.185.239.55:6448",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-05-08 08:43:08",
            "last_seen_utc": "2026-06-30 10:43:27",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1808628": [
        {
            "ioc_value": "113.31.118.180:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-05-08 08:43:05",
            "last_seen_utc": "2026-06-30 10:43:17",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1808623": [
        {
            "ioc_value": "104.243.248.63:1802",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-05-08 08:43:04",
            "last_seen_utc": "2026-06-30 08:43:13",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1808622": [
        {
            "ioc_value": "103.83.87.81:4141",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-05-08 08:43:03",
            "last_seen_utc": "2026-06-29 18:43:09",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1808600": [
        {
            "ioc_value": "45.202.249.88:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-05-08 07:49:28",
            "last_seen_utc": "2026-06-30 10:47:06",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-987654321",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1808598": [
        {
            "ioc_value": "45.202.249.88:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-05-08 07:49:24",
            "last_seen_utc": "2026-06-30 10:47:06",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-987654321",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1808286": [
        {
            "ioc_value": "101.33.225.32:8011",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-05-07 20:44:32",
            "last_seen_utc": "2026-06-30 10:46:30",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1808255": [
        {
            "ioc_value": "168.144.36.228:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pupy",
            "malware_alias": "Patpoopy",
            "malware_printable": "pupy",
            "first_seen_utc": "2026-05-07 18:43:18",
            "last_seen_utc": "2026-06-30 10:43:46",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PupyRAT,RAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1808253": [
        {
            "ioc_value": "146.185.233.41:5382",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-05-07 18:43:11",
            "last_seen_utc": "2026-06-30 10:43:27",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1808252": [
        {
            "ioc_value": "138.197.21.32:3333",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.evilginx",
            "malware_alias": null,
            "malware_printable": "Evilginx",
            "first_seen_utc": "2026-05-07 18:43:09",
            "last_seen_utc": "2026-06-30 10:43:23",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Evilginx,EvilGoPhish",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1808142": [
        {
            "ioc_value": "83.147.38.94:2030",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.evilginx",
            "malware_alias": null,
            "malware_printable": "Evilginx",
            "first_seen_utc": "2026-05-07 10:44:18",
            "last_seen_utc": "2026-06-30 10:46:10",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Evilginx,EvilGoPhish",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1807868": [
        {
            "ioc_value": "27.102.137.139:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-05-06 20:53:22",
            "last_seen_utc": "2026-06-30 10:45:21",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "",
            "tags": "Remcos,RemcosRAT,Remvio,Socmer",
            "anonymous": "0",
            "reporter": "whoamix302"
        }
    ],
    "1807906": [
        {
            "ioc_value": "45.207.192.190:30078",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-05-06 20:45:39",
            "last_seen_utc": "2026-06-30 10:47:06",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1807905": [
        {
            "ioc_value": "207.56.226.75:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-05-06 20:45:29",
            "last_seen_utc": "2026-06-30 10:46:56",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1807904": [
        {
            "ioc_value": "117.72.168.103:16337",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-05-06 20:45:09",
            "last_seen_utc": "2026-06-30 10:46:38",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1807903": [
        {
            "ioc_value": "static.slbc7890.shop",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-05-06 20:44:56",
            "last_seen_utc": "2026-06-29 10:46:14",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1807846": [
        {
            "ioc_value": "5.101.86.102:2501",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-05-06 18:44:01",
            "last_seen_utc": "2026-06-30 10:45:50",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1807847": [
        {
            "ioc_value": "5.101.86.107:4934",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-05-06 18:44:01",
            "last_seen_utc": "2026-06-30 10:45:50",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1807842": [
        {
            "ioc_value": "154.18.238.18:8848",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.dcrat",
            "malware_alias": "DarkCrystal RAT",
            "malware_printable": "DCRat",
            "first_seen_utc": "2026-05-06 18:43:14",
            "last_seen_utc": "2026-06-30 10:43:32",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DCRat,drb-ra,RAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1807792": [
        {
            "ioc_value": "39.101.78.48:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-05-06 16:44:44",
            "last_seen_utc": "2026-06-30 10:47:00",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1807791": [
        {
            "ioc_value": "124.223.90.150:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-05-06 16:44:32",
            "last_seen_utc": "2026-06-30 10:46:43",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1807788": [
        {
            "ioc_value": "1.15.100.187:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-05-06 16:44:22",
            "last_seen_utc": "2026-06-30 08:46:32",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1807783": [
        {
            "ioc_value": "1325813086-kvn4jlpgeu.ap-shanghai.tencentscf.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-05-06 16:44:13",
            "last_seen_utc": "2026-06-30 08:46:22",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1807785": [
        {
            "ioc_value": "4176rbz8vepn6.cfc-execute.bj.baidubce.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-05-06 16:44:13",
            "last_seen_utc": "2026-06-30 10:46:21",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1807540": [
        {
            "ioc_value": "5.101.86.41:2428",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-05-06 08:44:09",
            "last_seen_utc": "2026-06-30 10:45:50",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1807541": [
        {
            "ioc_value": "5.101.86.41:6448",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-05-06 08:44:09",
            "last_seen_utc": "2026-06-30 10:45:50",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1807538": [
        {
            "ioc_value": "31.57.184.154:7707",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-05-06 08:43:54",
            "last_seen_utc": "2026-06-30 10:45:24",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1807206": [
        {
            "ioc_value": "5.101.86.98:4126",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-05-05 18:49:30",
            "last_seen_utc": "2026-06-30 10:45:52",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1807204": [
        {
            "ioc_value": "5.101.82.228:9362",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-05-05 18:49:12",
            "last_seen_utc": "2026-06-30 10:45:48",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1807205": [
        {
            "ioc_value": "5.101.82.229:3039",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-05-05 18:49:12",
            "last_seen_utc": "2026-06-30 10:45:48",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1806953": [
        {
            "ioc_value": "5.101.82.99:6031",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-05-05 10:47:42",
            "last_seen_utc": "2026-06-30 10:45:49",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1806901": [
        {
            "ioc_value": "172.245.156.179:18443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-05-05 08:44:56",
            "last_seen_utc": "2026-06-30 10:46:51",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1806229": [
        {
            "ioc_value": "8.130.80.145:18443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-05-04 20:45:07",
            "last_seen_utc": "2026-06-30 10:47:15",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1806228": [
        {
            "ioc_value": "154.219.115.123:61443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-05-04 20:44:43",
            "last_seen_utc": "2026-06-30 10:46:48",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1806227": [
        {
            "ioc_value": "119.29.198.193:8555",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-05-04 20:44:36",
            "last_seen_utc": "2026-06-30 10:46:40",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1806112": [
        {
            "ioc_value": "5.101.86.101:1398",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-05-04 18:44:06",
            "last_seen_utc": "2026-06-30 10:45:50",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1805766": [
        {
            "ioc_value": "82.165.79.60:31337",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.sliver",
            "malware_alias": null,
            "malware_printable": "Sliver",
            "first_seen_utc": "2026-05-04 08:44:13",
            "last_seen_utc": "2026-06-30 10:46:09",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Sliver",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1805765": [
        {
            "ioc_value": "82.165.79.60:1337",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.sliver",
            "malware_alias": null,
            "malware_printable": "Sliver",
            "first_seen_utc": "2026-05-04 08:44:12",
            "last_seen_utc": "2026-06-30 10:46:09",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Sliver",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1805757": [
        {
            "ioc_value": "163.181.45.55:4506",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.deimos_c2",
            "malware_alias": null,
            "malware_printable": "DeimosC2",
            "first_seen_utc": "2026-05-04 08:43:16",
            "last_seen_utc": "2026-06-30 10:43:43",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "Deimos,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1805268": [
        {
            "ioc_value": "151.245.90.45:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-05-03 12:44:29",
            "last_seen_utc": "2026-06-30 10:46:47",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1805267": [
        {
            "ioc_value": "ap.johamp.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-05-03 12:44:08",
            "last_seen_utc": "2026-06-30 10:46:21",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1805202": [
        {
            "ioc_value": "46.151.182.148:25608",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-05-03 08:43:54",
            "last_seen_utc": "2026-06-29 08:45:22",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1804968": [
        {
            "ioc_value": "203.160.54.22:8443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-05-02 20:44:31",
            "last_seen_utc": "2026-06-30 10:46:56",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1804965": [
        {
            "ioc_value": "h67as5d5x.m6p3wca1.cc",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-05-02 20:44:06",
            "last_seen_utc": "2026-06-30 10:46:24",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1804928": [
        {
            "ioc_value": "38.147.173.24:8562",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-05-02 18:43:44",
            "last_seen_utc": "2026-06-30 10:45:29",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1804853": [
        {
            "ioc_value": "47.101.172.178:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-05-02 14:44:30",
            "last_seen_utc": "2026-06-30 10:47:07",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1804732": [
        {
            "ioc_value": "8.160.216.91:4506",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.deimos_c2",
            "malware_alias": null,
            "malware_printable": "DeimosC2",
            "first_seen_utc": "2026-05-02 08:43:53",
            "last_seen_utc": "2026-06-30 10:46:06",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "Deimos,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1804728": [
        {
            "ioc_value": "31.57.184.161:7707",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-05-02 08:43:40",
            "last_seen_utc": "2026-06-30 10:45:24",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1804729": [
        {
            "ioc_value": "31.57.184.161:8808",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-05-02 08:43:40",
            "last_seen_utc": "2026-06-30 10:45:24",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1804727": [
        {
            "ioc_value": "31.57.184.161:6606",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-05-02 08:43:39",
            "last_seen_utc": "2026-06-30 10:45:24",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1804719": [
        {
            "ioc_value": "124.95.172.200:4506",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.deimos_c2",
            "malware_alias": null,
            "malware_printable": "DeimosC2",
            "first_seen_utc": "2026-05-02 08:43:06",
            "last_seen_utc": "2026-06-30 10:43:19",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "Deimos,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1804607": [
        {
            "ioc_value": "vinabeautyspa.nyc",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.iclickfix",
            "malware_alias": null,
            "malware_printable": "IClickFix",
            "first_seen_utc": "2026-05-02 06:32:30",
            "last_seen_utc": "2026-06-30 06:05:31",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": "",
            "tags": "ClickFix,compromised,etherhiding,Polygon,Vidar",
            "anonymous": "0",
            "reporter": "varysz"
        }
    ],
    "1804586": [
        {
            "ioc_value": "topjobsnigerian.com.ng",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.iclickfix",
            "malware_alias": null,
            "malware_printable": "IClickFix",
            "first_seen_utc": "2026-05-02 06:32:28",
            "last_seen_utc": "2026-06-30 06:03:06",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": "",
            "tags": "ClickFix,compromised,etherhiding,Polygon,Vidar",
            "anonymous": "0",
            "reporter": "varysz"
        }
    ],
    "1804570": [
        {
            "ioc_value": "thegoldenliving.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.iclickfix",
            "malware_alias": null,
            "malware_printable": "IClickFix",
            "first_seen_utc": "2026-05-02 06:32:27",
            "last_seen_utc": "2026-06-30 06:03:07",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": "",
            "tags": "ClickFix,compromised,etherhiding,Polygon,Vidar",
            "anonymous": "0",
            "reporter": "varysz"
        }
    ],
    "1804551": [
        {
            "ioc_value": "sunyan.me",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.iclickfix",
            "malware_alias": null,
            "malware_printable": "IClickFix",
            "first_seen_utc": "2026-05-02 06:32:25",
            "last_seen_utc": "2026-06-30 06:03:08",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": "",
            "tags": "ClickFix,compromised,etherhiding,Polygon,Vidar",
            "anonymous": "0",
            "reporter": "varysz"
        }
    ],
    "1804482": [
        {
            "ioc_value": "pretribun.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.iclickfix",
            "malware_alias": null,
            "malware_printable": "IClickFix",
            "first_seen_utc": "2026-05-02 06:32:18",
            "last_seen_utc": "2026-06-30 06:05:30",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": "",
            "tags": "ClickFix,compromised,etherhiding,Polygon,Vidar",
            "anonymous": "0",
            "reporter": "varysz"
        }
    ],
    "1804468": [
        {
            "ioc_value": "phnomtamaozoologicalpark.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.iclickfix",
            "malware_alias": null,
            "malware_printable": "IClickFix",
            "first_seen_utc": "2026-05-02 06:32:17",
            "last_seen_utc": "2026-06-30 06:03:07",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": "",
            "tags": "ClickFix,compromised,etherhiding,Polygon,Vidar",
            "anonymous": "0",
            "reporter": "varysz"
        }
    ],
    "1804470": [
        {
            "ioc_value": "pio-ulski.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.iclickfix",
            "malware_alias": null,
            "malware_printable": "IClickFix",
            "first_seen_utc": "2026-05-02 06:32:17",
            "last_seen_utc": "2026-06-30 06:03:08",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": "",
            "tags": "ClickFix,compromised,etherhiding,Polygon,Vidar",
            "anonymous": "0",
            "reporter": "varysz"
        }
    ],
    "1804455": [
        {
            "ioc_value": "onlydiscovery.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.iclickfix",
            "malware_alias": null,
            "malware_printable": "IClickFix",
            "first_seen_utc": "2026-05-02 06:32:16",
            "last_seen_utc": "2026-06-30 06:03:09",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": "",
            "tags": "ClickFix,compromised,etherhiding,Polygon,Vidar",
            "anonymous": "0",
            "reporter": "varysz"
        }
    ],
    "1804447": [
        {
            "ioc_value": "nycefmonline.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.iclickfix",
            "malware_alias": null,
            "malware_printable": "IClickFix",
            "first_seen_utc": "2026-05-02 06:32:15",
            "last_seen_utc": "2026-06-30 06:05:32",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": "",
            "tags": "ClickFix,compromised,etherhiding,Polygon,Vidar",
            "anonymous": "0",
            "reporter": "varysz"
        }
    ],
    "1804427": [
        {
            "ioc_value": "murdockfuneralhome.net",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.iclickfix",
            "malware_alias": null,
            "malware_printable": "IClickFix",
            "first_seen_utc": "2026-05-02 06:32:14",
            "last_seen_utc": "2026-06-30 06:03:07",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": "",
            "tags": "ClickFix,compromised,etherhiding,Polygon,Vidar",
            "anonymous": "0",
            "reporter": "varysz"
        }
    ],
    "1804436": [
        {
            "ioc_value": "nefis.be",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.iclickfix",
            "malware_alias": null,
            "malware_printable": "IClickFix",
            "first_seen_utc": "2026-05-02 06:32:14",
            "last_seen_utc": "2026-06-30 06:03:07",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": "",
            "tags": "ClickFix,compromised,etherhiding,Polygon,Vidar",
            "anonymous": "0",
            "reporter": "varysz"
        }
    ],
    "1804417": [
        {
            "ioc_value": "mobilepricesbot.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.iclickfix",
            "malware_alias": null,
            "malware_printable": "IClickFix",
            "first_seen_utc": "2026-05-02 06:32:13",
            "last_seen_utc": "2026-06-30 06:05:32",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": "",
            "tags": "ClickFix,compromised,etherhiding,Polygon,Vidar",
            "anonymous": "0",
            "reporter": "varysz"
        }
    ],
    "1804426": [
        {
            "ioc_value": "muneramusica.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.iclickfix",
            "malware_alias": null,
            "malware_printable": "IClickFix",
            "first_seen_utc": "2026-05-02 06:32:13",
            "last_seen_utc": "2026-06-28 14:01:28",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": "",
            "tags": "ClickFix,compromised,etherhiding,Polygon,Vidar",
            "anonymous": "0",
            "reporter": "varysz"
        }
    ],
    "1804387": [
        {
            "ioc_value": "lightcenterlove.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.iclickfix",
            "malware_alias": null,
            "malware_printable": "IClickFix",
            "first_seen_utc": "2026-05-02 06:32:10",
            "last_seen_utc": "2026-06-30 06:03:06",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": "",
            "tags": "ClickFix,compromised,etherhiding,Polygon,Vidar",
            "anonymous": "0",
            "reporter": "varysz"
        }
    ],
    "1804389": [
        {
            "ioc_value": "livelaughlovedo.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.iclickfix",
            "malware_alias": null,
            "malware_printable": "IClickFix",
            "first_seen_utc": "2026-05-02 06:32:10",
            "last_seen_utc": "2026-06-30 06:05:32",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": "",
            "tags": "ClickFix,compromised,etherhiding,Polygon,Vidar",
            "anonymous": "0",
            "reporter": "varysz"
        }
    ],
    "1804375": [
        {
            "ioc_value": "kcherbs.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.iclickfix",
            "malware_alias": null,
            "malware_printable": "IClickFix",
            "first_seen_utc": "2026-05-02 06:32:09",
            "last_seen_utc": "2026-06-30 06:03:07",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": "",
            "tags": "ClickFix,compromised,etherhiding,Polygon,Vidar",
            "anonymous": "0",
            "reporter": "varysz"
        }
    ],
    "1804362": [
        {
            "ioc_value": "jes-edu.in",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.iclickfix",
            "malware_alias": null,
            "malware_printable": "IClickFix",
            "first_seen_utc": "2026-05-02 06:32:08",
            "last_seen_utc": "2026-06-30 06:05:31",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": "",
            "tags": "ClickFix,compromised,etherhiding,Polygon,Vidar",
            "anonymous": "0",
            "reporter": "varysz"
        }
    ],
    "1804332": [
        {
            "ioc_value": "healgram.gr",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.iclickfix",
            "malware_alias": null,
            "malware_printable": "IClickFix",
            "first_seen_utc": "2026-05-02 06:32:05",
            "last_seen_utc": "2026-06-30 06:05:31",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": "",
            "tags": "ClickFix,compromised,etherhiding,Polygon,Vidar",
            "anonymous": "0",
            "reporter": "varysz"
        }
    ],
    "1804281": [
        {
            "ioc_value": "entwined.co.ke",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.iclickfix",
            "malware_alias": null,
            "malware_printable": "IClickFix",
            "first_seen_utc": "2026-05-02 06:31:59",
            "last_seen_utc": "2026-06-30 06:03:07",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": "",
            "tags": "ClickFix,compromised,etherhiding,Polygon,Vidar",
            "anonymous": "0",
            "reporter": "varysz"
        }
    ],
    "1804268": [
        {
            "ioc_value": "dr-habitat.fr",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.iclickfix",
            "malware_alias": null,
            "malware_printable": "IClickFix",
            "first_seen_utc": "2026-05-02 06:31:58",
            "last_seen_utc": "2026-06-30 06:03:08",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": "",
            "tags": "ClickFix,compromised,etherhiding,Polygon,Vidar",
            "anonymous": "0",
            "reporter": "varysz"
        }
    ],
    "1804250": [
        {
            "ioc_value": "councilapprovaldesign.com.au",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.iclickfix",
            "malware_alias": null,
            "malware_printable": "IClickFix",
            "first_seen_utc": "2026-05-02 06:31:56",
            "last_seen_utc": "2026-06-30 06:03:08",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": "",
            "tags": "ClickFix,compromised,etherhiding,Polygon,Vidar",
            "anonymous": "0",
            "reporter": "varysz"
        }
    ],
    "1804233": [
        {
            "ioc_value": "clarksoutpost.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.iclickfix",
            "malware_alias": null,
            "malware_printable": "IClickFix",
            "first_seen_utc": "2026-05-02 06:31:55",
            "last_seen_utc": "2026-06-30 06:03:08",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": "",
            "tags": "ClickFix,compromised,etherhiding,Polygon,Vidar",
            "anonymous": "0",
            "reporter": "varysz"
        }
    ],
    "1804220": [
        {
            "ioc_value": "cbdmassage378.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.iclickfix",
            "malware_alias": null,
            "malware_printable": "IClickFix",
            "first_seen_utc": "2026-05-02 06:31:53",
            "last_seen_utc": "2026-06-30 06:03:07",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": "",
            "tags": "ClickFix,compromised,etherhiding,Polygon,Vidar",
            "anonymous": "0",
            "reporter": "varysz"
        }
    ],
    "1804205": [
        {
            "ioc_value": "bluegrassrooter.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.iclickfix",
            "malware_alias": null,
            "malware_printable": "IClickFix",
            "first_seen_utc": "2026-05-02 06:31:52",
            "last_seen_utc": "2026-06-30 06:03:08",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": "",
            "tags": "ClickFix,compromised,etherhiding,Polygon,Vidar",
            "anonymous": "0",
            "reporter": "varysz"
        }
    ],
    "1804185": [
        {
            "ioc_value": "babytoyecia.com.br",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.iclickfix",
            "malware_alias": null,
            "malware_printable": "IClickFix",
            "first_seen_utc": "2026-05-02 06:31:50",
            "last_seen_utc": "2026-06-30 06:03:08",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": "",
            "tags": "ClickFix,compromised,etherhiding,Polygon,Vidar",
            "anonymous": "0",
            "reporter": "varysz"
        }
    ],
    "1803956": [
        {
            "ioc_value": "https://arsimonopa.com/live/",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.latrodectus",
            "malware_alias": "BLACKWIDOW,IceNova,Latrodectus,Lotus",
            "malware_printable": "Latrodectus",
            "first_seen_utc": "2026-05-02 05:24:17",
            "last_seen_utc": "2026-06-30 11:21:51",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "c2,Latrodectus",
            "anonymous": "0",
            "reporter": "Bitsight"
        }
    ],
    "1803960": [
        {
            "ioc_value": "https://lemonimonakio.com/live/",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.latrodectus",
            "malware_alias": "BLACKWIDOW,IceNova,Latrodectus,Lotus",
            "malware_printable": "Latrodectus",
            "first_seen_utc": "2026-05-02 05:24:15",
            "last_seen_utc": "2026-06-30 11:12:48",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "c2,Latrodectus",
            "anonymous": "0",
            "reporter": "Bitsight"
        }
    ],
    "1803896": [
        {
            "ioc_value": "89.114.115.200:8080",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.chaos",
            "malware_alias": "FakeRyuk,RyukJoke,Yashma",
            "malware_printable": "Chaos",
            "first_seen_utc": "2026-05-01 18:43:58",
            "last_seen_utc": "2026-06-30 10:46:14",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CHAOS,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1803894": [
        {
            "ioc_value": "59.152.212.164:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.bianlian",
            "malware_alias": null,
            "malware_printable": "BianLian",
            "first_seen_utc": "2026-05-01 18:43:53",
            "last_seen_utc": "2026-06-30 10:45:56",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "Bianlian,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1803887": [
        {
            "ioc_value": "5.101.82.190:5691",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-05-01 18:43:50",
            "last_seen_utc": "2026-06-30 10:45:48",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1803881": [
        {
            "ioc_value": "45.10.164.177:45123",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-05-01 18:43:45",
            "last_seen_utc": "2026-06-30 10:45:34",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1803880": [
        {
            "ioc_value": "39.101.82.73:4506",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.deimos_c2",
            "malware_alias": null,
            "malware_printable": "DeimosC2",
            "first_seen_utc": "2026-05-01 18:43:44",
            "last_seen_utc": "2026-06-30 10:45:31",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "Deimos,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1803874": [
        {
            "ioc_value": "31.57.184.154:6606",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-05-01 18:43:41",
            "last_seen_utc": "2026-06-30 10:45:23",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1803866": [
        {
            "ioc_value": "195.88.191.41:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.ransomhub",
            "malware_alias": null,
            "malware_printable": "RansomHub",
            "first_seen_utc": "2026-05-01 18:43:24",
            "last_seen_utc": "2026-06-30 10:44:21",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RansomHub",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1803867": [
        {
            "ioc_value": "195.88.191.41:7666",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.ransomhub",
            "malware_alias": null,
            "malware_printable": "RansomHub",
            "first_seen_utc": "2026-05-01 18:43:24",
            "last_seen_utc": "2026-06-30 10:44:21",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RansomHub",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1803858": [
        {
            "ioc_value": "185.212.128.80:9000",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.evilginx",
            "malware_alias": null,
            "malware_printable": "Evilginx",
            "first_seen_utc": "2026-05-01 18:43:19",
            "last_seen_utc": "2026-06-30 10:44:07",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Evilginx,EvilGoPhish",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1803859": [
        {
            "ioc_value": "185.212.128.85:9000",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.evilginx",
            "malware_alias": null,
            "malware_printable": "Evilginx",
            "first_seen_utc": "2026-05-01 18:43:19",
            "last_seen_utc": "2026-06-30 10:44:07",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Evilginx,EvilGoPhish",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1803856": [
        {
            "ioc_value": "173.211.106.231:21320",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-05-01 18:43:16",
            "last_seen_utc": "2026-06-29 18:43:45",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1803843": [
        {
            "ioc_value": "107.175.113.106:55",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pupy",
            "malware_alias": "Patpoopy",
            "malware_printable": "pupy",
            "first_seen_utc": "2026-05-01 18:43:04",
            "last_seen_utc": "2026-06-30 10:43:15",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PupyRAT,RAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1803840": [
        {
            "ioc_value": "103.110.65.166:52223",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.sliver",
            "malware_alias": null,
            "malware_printable": "Sliver",
            "first_seen_utc": "2026-05-01 18:43:02",
            "last_seen_utc": "2026-06-30 10:43:08",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Sliver",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1803693": [
        {
            "ioc_value": "8.222.192.153:8000",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-05-01 14:44:50",
            "last_seen_utc": "2026-06-30 10:46:07",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1803689": [
        {
            "ioc_value": "47.236.91.172:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-05-01 14:44:44",
            "last_seen_utc": "2026-06-30 10:47:11",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1803685": [
        {
            "ioc_value": "secure-server.sbs",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-05-01 14:44:09",
            "last_seen_utc": "2026-06-30 10:46:27",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1803670": [
        {
            "ioc_value": "frr.ambil-disini.web.id",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-05-01 14:30:24",
            "last_seen_utc": "2026-06-30 11:22:28",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "vidar",
            "anonymous": "0",
            "reporter": "crep1x"
        }
    ],
    "1803671": [
        {
            "ioc_value": "https://frr.ambil-disini.web.id/",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-05-01 14:30:24",
            "last_seen_utc": "2026-06-30 11:22:28",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "vidar",
            "anonymous": "0",
            "reporter": "crep1x"
        }
    ],
    "1803514": [
        {
            "ioc_value": "72.56.246.58:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.chaos",
            "malware_alias": "FakeRyuk,RyukJoke,Yashma",
            "malware_printable": "Chaos",
            "first_seen_utc": "2026-05-01 08:43:49",
            "last_seen_utc": "2026-06-30 10:46:04",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CHAOS,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1803512": [
        {
            "ioc_value": "62.60.226.63:6856",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-05-01 08:43:48",
            "last_seen_utc": "2026-06-30 10:45:57",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1803513": [
        {
            "ioc_value": "64.89.163.114:6606",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-05-01 08:43:48",
            "last_seen_utc": "2026-06-30 10:46:00",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1803506": [
        {
            "ioc_value": "5.101.86.57:1984",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-05-01 08:43:46",
            "last_seen_utc": "2026-06-30 10:45:51",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1803507": [
        {
            "ioc_value": "5.101.86.60:6798",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-05-01 08:43:46",
            "last_seen_utc": "2026-06-30 10:45:51",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1803508": [
        {
            "ioc_value": "5.101.86.76:1338",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-05-01 08:43:46",
            "last_seen_utc": "2026-06-30 10:45:51",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1803509": [
        {
            "ioc_value": "5.101.86.76:9323",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-05-01 08:43:46",
            "last_seen_utc": "2026-06-30 10:45:51",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1803510": [
        {
            "ioc_value": "5.101.86.76:9521",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-05-01 08:43:46",
            "last_seen_utc": "2026-06-30 10:45:51",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1803511": [
        {
            "ioc_value": "5.101.86.78:9323",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-05-01 08:43:46",
            "last_seen_utc": "2026-06-30 10:45:51",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1803499": [
        {
            "ioc_value": "46.151.182.71:22",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-05-01 08:43:44",
            "last_seen_utc": "2026-06-30 10:45:44",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1803500": [
        {
            "ioc_value": "47.103.106.26:2333",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-05-01 08:43:44",
            "last_seen_utc": "2026-06-30 10:45:46",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1803501": [
        {
            "ioc_value": "47.83.254.175:6321",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-05-01 08:43:44",
            "last_seen_utc": "2026-06-30 10:45:47",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1803493": [
        {
            "ioc_value": "4.236.165.30:4321",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-05-01 08:43:40",
            "last_seen_utc": "2026-06-30 10:45:31",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1803490": [
        {
            "ioc_value": "3.19.238.211:31337",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.sliver",
            "malware_alias": null,
            "malware_printable": "Sliver",
            "first_seen_utc": "2026-05-01 08:43:37",
            "last_seen_utc": "2026-06-30 10:45:22",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Sliver",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1803483": [
        {
            "ioc_value": "194.116.236.110:6161",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-05-01 08:43:21",
            "last_seen_utc": "2026-06-29 08:44:09",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1803478": [
        {
            "ioc_value": "190.2.150.52:853",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-05-01 08:43:20",
            "last_seen_utc": "2026-06-30 10:44:12",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1803473": [
        {
            "ioc_value": "178.128.252.142:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-05-01 08:43:16",
            "last_seen_utc": "2026-06-30 10:43:53",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1803470": [
        {
            "ioc_value": "169.40.135.35:6158",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-05-01 08:43:14",
            "last_seen_utc": "2026-06-30 10:43:46",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1803465": [
        {
            "ioc_value": "158.94.209.227:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.eye_pyramid",
            "malware_alias": null,
            "malware_printable": "Eye Pyramid",
            "first_seen_utc": "2026-05-01 08:43:12",
            "last_seen_utc": "2026-06-28 18:43:31",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,EyePyramid",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1803460": [
        {
            "ioc_value": "155.103.70.100:50030",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-05-01 08:43:11",
            "last_seen_utc": "2026-06-30 10:43:34",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1803461": [
        {
            "ioc_value": "155.103.70.100:50033",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-05-01 08:43:11",
            "last_seen_utc": "2026-06-30 10:43:34",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1803462": [
        {
            "ioc_value": "155.103.70.68:2323",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-05-01 08:43:11",
            "last_seen_utc": "2026-06-28 18:43:27",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1803458": [
        {
            "ioc_value": "151.243.109.213:6325",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-05-01 08:43:10",
            "last_seen_utc": "2026-06-30 10:43:32",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1803452": [
        {
            "ioc_value": "136.0.41.76:8443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.evilginx",
            "malware_alias": null,
            "malware_printable": "Evilginx",
            "first_seen_utc": "2026-05-01 08:43:07",
            "last_seen_utc": "2026-06-30 10:43:22",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Evilginx,EvilGoPhish",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1803448": [
        {
            "ioc_value": "111.229.144.163:60000",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-05-01 08:43:05",
            "last_seen_utc": "2026-06-30 10:43:16",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1803387": [
        {
            "ioc_value": "203.160.54.22:8080",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-05-01 07:08:49",
            "last_seen_utc": "2026-06-30 10:46:55",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-987654321",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1803286": [
        {
            "ioc_value": "94.176.3.228:48765",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-05-01 02:43:32",
            "last_seen_utc": "2026-06-30 10:46:17",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1803291": [
        {
            "ioc_value": "98.97.125.70:8883",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.danabot",
            "malware_alias": "DanaTools",
            "malware_printable": "DanaBot",
            "first_seen_utc": "2026-05-01 02:43:32",
            "last_seen_utc": "2026-06-30 10:46:20",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DanBot,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1803279": [
        {
            "ioc_value": "91.202.233.153:43555",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-05-01 02:43:31",
            "last_seen_utc": "2026-06-30 10:46:16",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1803280": [
        {
            "ioc_value": "91.215.85.151:47653",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-05-01 02:43:31",
            "last_seen_utc": "2026-06-30 10:46:16",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1803275": [
        {
            "ioc_value": "85.121.5.202:5689",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-05-01 02:43:30",
            "last_seen_utc": "2026-06-30 10:46:11",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1803276": [
        {
            "ioc_value": "85.155.186.2:3821",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-05-01 02:43:30",
            "last_seen_utc": "2026-06-30 10:46:11",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1803269": [
        {
            "ioc_value": "83.97.20.133:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.bianlian",
            "malware_alias": null,
            "malware_printable": "BianLian",
            "first_seen_utc": "2026-05-01 02:43:29",
            "last_seen_utc": "2026-06-30 10:46:10",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "Bianlian,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1803262": [
        {
            "ioc_value": "79.135.160.20:9999",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-05-01 02:43:28",
            "last_seen_utc": "2026-06-30 10:46:06",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1803257": [
        {
            "ioc_value": "66.163.115.78:8808",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-05-01 02:43:27",
            "last_seen_utc": "2026-06-30 10:46:01",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1803260": [
        {
            "ioc_value": "72.56.246.58:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.chaos",
            "malware_alias": "FakeRyuk,RyukJoke,Yashma",
            "malware_printable": "Chaos",
            "first_seen_utc": "2026-05-01 02:43:27",
            "last_seen_utc": "2026-06-30 10:46:04",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CHAOS,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1803261": [
        {
            "ioc_value": "72.56.246.58:8080",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.chaos",
            "malware_alias": "FakeRyuk,RyukJoke,Yashma",
            "malware_printable": "Chaos",
            "first_seen_utc": "2026-05-01 02:43:27",
            "last_seen_utc": "2026-06-30 10:46:05",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CHAOS,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1803251": [
        {
            "ioc_value": "52.198.162.251:16000",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.havoc",
            "malware_alias": "Havokiz",
            "malware_printable": "Havoc",
            "first_seen_utc": "2026-05-01 02:43:26",
            "last_seen_utc": "2026-06-30 10:45:54",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Havoc",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1803254": [
        {
            "ioc_value": "62.81.188.1:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.danabot",
            "malware_alias": "DanaTools",
            "malware_printable": "DanaBot",
            "first_seen_utc": "2026-05-01 02:43:26",
            "last_seen_utc": "2026-06-30 10:45:58",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DanBot,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1803255": [
        {
            "ioc_value": "66.163.115.78:6606",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-05-01 02:43:26",
            "last_seen_utc": "2026-06-30 10:46:01",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1803256": [
        {
            "ioc_value": "66.163.115.78:7707",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-05-01 02:43:26",
            "last_seen_utc": "2026-06-30 10:46:01",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1803245": [
        {
            "ioc_value": "45.95.232.195:54655",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-05-01 02:43:25",
            "last_seen_utc": "2026-06-30 10:45:43",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1803246": [
        {
            "ioc_value": "46.101.77.223:3333",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.evilginx",
            "malware_alias": null,
            "malware_printable": "Evilginx",
            "first_seen_utc": "2026-05-01 02:43:25",
            "last_seen_utc": "2026-06-30 10:45:44",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Evilginx,EvilGoPhish",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1803240": [
        {
            "ioc_value": "45.56.91.55:2003",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-05-01 02:43:24",
            "last_seen_utc": "2026-06-30 10:45:39",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "Covenant,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1803244": [
        {
            "ioc_value": "45.81.243.52:4321",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-05-01 02:43:24",
            "last_seen_utc": "2026-06-30 10:45:43",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1803235": [
        {
            "ioc_value": "45.125.67.171:8443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-05-01 02:43:23",
            "last_seen_utc": "2026-06-30 10:45:34",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1803238": [
        {
            "ioc_value": "45.155.69.106:42211",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-05-01 02:43:23",
            "last_seen_utc": "2026-06-30 10:45:37",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1803231": [
        {
            "ioc_value": "43.134.133.177:8445",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.bianlian",
            "malware_alias": null,
            "malware_printable": "BianLian",
            "first_seen_utc": "2026-05-01 02:43:22",
            "last_seen_utc": "2026-06-30 10:45:33",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "Bianlian,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1803232": [
        {
            "ioc_value": "43.142.77.170:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.chaos",
            "malware_alias": "FakeRyuk,RyukJoke,Yashma",
            "malware_printable": "Chaos",
            "first_seen_utc": "2026-05-01 02:43:22",
            "last_seen_utc": "2026-06-30 10:45:33",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CHAOS,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1803233": [
        {
            "ioc_value": "43.142.77.170:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.chaos",
            "malware_alias": "FakeRyuk,RyukJoke,Yashma",
            "malware_printable": "Chaos",
            "first_seen_utc": "2026-05-01 02:43:22",
            "last_seen_utc": "2026-06-30 10:45:33",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CHAOS,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1803234": [
        {
            "ioc_value": "43.160.225.40:39001",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-05-01 02:43:22",
            "last_seen_utc": "2026-06-30 10:45:33",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1803225": [
        {
            "ioc_value": "37.72.140.15:5555",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-05-01 02:43:21",
            "last_seen_utc": "2026-06-30 10:45:28",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1803228": [
        {
            "ioc_value": "38.54.119.24:4321",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-05-01 02:43:21",
            "last_seen_utc": "2026-06-30 10:45:30",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1803218": [
        {
            "ioc_value": "222.255.100.119:8080",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.chaos",
            "malware_alias": "FakeRyuk,RyukJoke,Yashma",
            "malware_printable": "Chaos",
            "first_seen_utc": "2026-05-01 02:43:20",
            "last_seen_utc": "2026-06-30 10:45:19",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CHAOS,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1803219": [
        {
            "ioc_value": "23.227.203.6:42235",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-05-01 02:43:20",
            "last_seen_utc": "2026-06-30 10:45:19",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1803222": [
        {
            "ioc_value": "31.57.184.154:8808",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-05-01 02:43:20",
            "last_seen_utc": "2026-06-30 10:45:24",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1803211": [
        {
            "ioc_value": "216.107.208.250:10444",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.bianlian",
            "malware_alias": null,
            "malware_printable": "BianLian",
            "first_seen_utc": "2026-05-01 02:43:19",
            "last_seen_utc": "2026-06-30 10:44:37",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "Bianlian,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1803215": [
        {
            "ioc_value": "219.142.15.101:4353",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.danabot",
            "malware_alias": "DanaTools",
            "malware_printable": "DanaBot",
            "first_seen_utc": "2026-05-01 02:43:19",
            "last_seen_utc": "2026-06-30 10:45:18",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DanBot,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1803216": [
        {
            "ioc_value": "220.231.47.163:4353",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.danabot",
            "malware_alias": "DanaTools",
            "malware_printable": "DanaBot",
            "first_seen_utc": "2026-05-01 02:43:19",
            "last_seen_utc": "2026-06-30 10:45:18",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DanBot,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1803217": [
        {
            "ioc_value": "221.130.42.19:4353",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.danabot",
            "malware_alias": "DanaTools",
            "malware_printable": "DanaBot",
            "first_seen_utc": "2026-05-01 02:43:19",
            "last_seen_utc": "2026-06-30 10:45:18",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DanBot,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1803204": [
        {
            "ioc_value": "207.107.147.42:4438",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.bianlian",
            "malware_alias": null,
            "malware_printable": "BianLian",
            "first_seen_utc": "2026-05-01 02:43:18",
            "last_seen_utc": "2026-06-30 10:44:30",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "Bianlian,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1803205": [
        {
            "ioc_value": "208.249.244.20:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.bianlian",
            "malware_alias": null,
            "malware_printable": "BianLian",
            "first_seen_utc": "2026-05-01 02:43:18",
            "last_seen_utc": "2026-06-30 10:44:31",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "Bianlian,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1803206": [
        {
            "ioc_value": "209.151.145.164:8443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.deimos_c2",
            "malware_alias": null,
            "malware_printable": "DeimosC2",
            "first_seen_utc": "2026-05-01 02:43:18",
            "last_seen_utc": "2026-06-30 10:44:32",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "Deimos,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1803202": [
        {
            "ioc_value": "202.95.17.188:4321",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-05-01 02:43:17",
            "last_seen_utc": "2026-06-30 10:44:28",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1803203": [
        {
            "ioc_value": "206.189.40.107:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.havoc",
            "malware_alias": "Havokiz",
            "malware_printable": "Havoc",
            "first_seen_utc": "2026-05-01 02:43:17",
            "last_seen_utc": "2026-06-30 10:44:30",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Havoc",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1803192": [
        {
            "ioc_value": "193.23.137.40:3334",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.evilginx",
            "malware_alias": null,
            "malware_printable": "Evilginx",
            "first_seen_utc": "2026-05-01 02:43:15",
            "last_seen_utc": "2026-06-30 10:44:17",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Evilginx,EvilGoPhish",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1803180": [
        {
            "ioc_value": "185.242.3.83:9909",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-05-01 02:43:14",
            "last_seen_utc": "2026-06-30 10:44:09",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1803181": [
        {
            "ioc_value": "185.247.224.40:4321",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-05-01 02:43:14",
            "last_seen_utc": "2026-06-30 10:44:09",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1803173": [
        {
            "ioc_value": "185.212.128.81:9000",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.evilginx",
            "malware_alias": null,
            "malware_printable": "Evilginx",
            "first_seen_utc": "2026-05-01 02:43:13",
            "last_seen_utc": "2026-06-30 10:44:07",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Evilginx,EvilGoPhish",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1803174": [
        {
            "ioc_value": "185.212.129.23:9000",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.evilginx",
            "malware_alias": null,
            "malware_printable": "Evilginx",
            "first_seen_utc": "2026-05-01 02:43:13",
            "last_seen_utc": "2026-06-30 10:44:07",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Evilginx,EvilGoPhish",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1803176": [
        {
            "ioc_value": "185.212.129.29:9000",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.evilginx",
            "malware_alias": null,
            "malware_printable": "Evilginx",
            "first_seen_utc": "2026-05-01 02:43:13",
            "last_seen_utc": "2026-06-30 10:44:08",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Evilginx,EvilGoPhish",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1803177": [
        {
            "ioc_value": "185.212.129.30:9000",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.evilginx",
            "malware_alias": null,
            "malware_printable": "Evilginx",
            "first_seen_utc": "2026-05-01 02:43:13",
            "last_seen_utc": "2026-06-30 10:44:08",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Evilginx,EvilGoPhish",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1803178": [
        {
            "ioc_value": "185.213.20.250:4321",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-05-01 02:43:13",
            "last_seen_utc": "2026-06-30 10:44:08",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1803179": [
        {
            "ioc_value": "185.242.245.120:42534",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-05-01 02:43:13",
            "last_seen_utc": "2026-06-30 10:44:09",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1803166": [
        {
            "ioc_value": "180.184.29.135:8080",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-05-01 02:43:12",
            "last_seen_utc": "2026-06-30 10:43:55",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1803167": [
        {
            "ioc_value": "182.255.45.114:4848",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-05-01 02:43:12",
            "last_seen_utc": "2026-06-30 10:44:00",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1803168": [
        {
            "ioc_value": "185.122.171.4:44355",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-05-01 02:43:12",
            "last_seen_utc": "2026-06-30 10:44:03",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1803171": [
        {
            "ioc_value": "185.212.128.25:9000",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.evilginx",
            "malware_alias": null,
            "malware_printable": "Evilginx",
            "first_seen_utc": "2026-05-01 02:43:12",
            "last_seen_utc": "2026-06-30 10:44:06",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Evilginx,EvilGoPhish",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1803172": [
        {
            "ioc_value": "185.212.128.48:9000",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.evilginx",
            "malware_alias": null,
            "malware_printable": "Evilginx",
            "first_seen_utc": "2026-05-01 02:43:12",
            "last_seen_utc": "2026-06-30 10:44:06",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Evilginx,EvilGoPhish",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1803162": [
        {
            "ioc_value": "178.16.52.22:8396",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-05-01 02:43:11",
            "last_seen_utc": "2026-06-30 10:43:53",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1803158": [
        {
            "ioc_value": "173.211.106.231:21321",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-05-01 02:43:10",
            "last_seen_utc": "2026-06-29 18:43:45",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1803159": [
        {
            "ioc_value": "173.242.59.199:8888",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.evilginx",
            "malware_alias": null,
            "malware_printable": "Evilginx",
            "first_seen_utc": "2026-05-01 02:43:10",
            "last_seen_utc": "2026-06-30 10:43:51",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Evilginx,EvilGoPhish",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1803152": [
        {
            "ioc_value": "172.111.162.252:3030",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-05-01 02:43:09",
            "last_seen_utc": "2026-06-30 10:43:47",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1803153": [
        {
            "ioc_value": "172.9.165.216:8096",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.chaos",
            "malware_alias": "FakeRyuk,RyukJoke,Yashma",
            "malware_printable": "Chaos",
            "first_seen_utc": "2026-05-01 02:43:09",
            "last_seen_utc": "2026-06-30 10:43:50",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CHAOS,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1803145": [
        {
            "ioc_value": "161.248.179.92:1111",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-05-01 02:43:08",
            "last_seen_utc": "2026-06-30 10:43:40",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1803146": [
        {
            "ioc_value": "161.248.179.92:9999",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-05-01 02:43:08",
            "last_seen_utc": "2026-06-30 10:43:40",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1803147": [
        {
            "ioc_value": "162.14.124.25:4321",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-05-01 02:43:08",
            "last_seen_utc": "2026-06-30 10:43:41",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1803134": [
        {
            "ioc_value": "149.104.28.204:3656",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-05-01 02:43:07",
            "last_seen_utc": "2026-06-30 10:43:30",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1803127": [
        {
            "ioc_value": "142.93.88.220:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.havoc",
            "malware_alias": "Havokiz",
            "malware_printable": "Havoc",
            "first_seen_utc": "2026-05-01 02:43:06",
            "last_seen_utc": "2026-06-30 10:43:26",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Havoc",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1803124": [
        {
            "ioc_value": "138.124.113.131:4211",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-05-01 02:43:05",
            "last_seen_utc": "2026-06-30 10:43:23",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1803126": [
        {
            "ioc_value": "139.64.164.72:63337",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.chaos",
            "malware_alias": "FakeRyuk,RyukJoke,Yashma",
            "malware_printable": "Chaos",
            "first_seen_utc": "2026-05-01 02:43:05",
            "last_seen_utc": "2026-06-30 10:43:24",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CHAOS,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1803114": [
        {
            "ioc_value": "115.42.60.122:5440",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.dcrat",
            "malware_alias": "DarkCrystal RAT",
            "malware_printable": "DCRat",
            "first_seen_utc": "2026-05-01 02:43:04",
            "last_seen_utc": "2026-06-30 10:43:18",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DCRat,drb-ra,RAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1803115": [
        {
            "ioc_value": "117.72.101.55:9520",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.chaos",
            "malware_alias": "FakeRyuk,RyukJoke,Yashma",
            "malware_printable": "Chaos",
            "first_seen_utc": "2026-05-01 02:43:04",
            "last_seen_utc": "2026-06-30 10:43:18",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CHAOS,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1803119": [
        {
            "ioc_value": "130.94.23.39:4321",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-05-01 02:43:04",
            "last_seen_utc": "2026-06-30 10:43:21",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1803109": [
        {
            "ioc_value": "103.75.190.47:54630",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.dcrat",
            "malware_alias": "DarkCrystal RAT",
            "malware_printable": "DCRat",
            "first_seen_utc": "2026-05-01 02:43:03",
            "last_seen_utc": "2026-06-30 10:43:10",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DCRat,drb-ra,RAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1803110": [
        {
            "ioc_value": "104.234.174.93:57712",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-05-01 02:43:03",
            "last_seen_utc": "2026-06-30 10:43:11",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1803111": [
        {
            "ioc_value": "106.55.71.62:8989",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-05-01 02:43:03",
            "last_seen_utc": "2026-06-30 10:43:12",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1803113": [
        {
            "ioc_value": "115.190.247.97:4321",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-05-01 02:43:03",
            "last_seen_utc": "2026-06-30 10:43:17",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1802897": [
        {
            "ioc_value": "82.156.219.31:8443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-04-30 18:43:45",
            "last_seen_utc": "2026-06-30 10:47:18",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1802894": [
        {
            "ioc_value": "193.53.127.220:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-04-30 18:43:30",
            "last_seen_utc": "2026-06-30 10:46:55",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1802892": [
        {
            "ioc_value": "www.microsslcheck.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-04-30 18:43:10",
            "last_seen_utc": "2026-06-30 10:46:28",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1802724": [
        {
            "ioc_value": "101.43.29.69:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-04-30 12:55:24",
            "last_seen_utc": "2026-06-30 10:46:31",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-666666666",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1802288": [
        {
            "ioc_value": "dokunmatikekrandegisimi.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-04-30 05:46:36",
            "last_seen_utc": "2026-06-30 06:05:32",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": "",
            "tags": "ClickFix,compromised,etherhiding,Polygon,Vidar,WordPress",
            "anonymous": "0",
            "reporter": "varysz"
        }
    ],
    "1802141": [
        {
            "ioc_value": "82.156.62.131:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-04-29 14:43:42",
            "last_seen_utc": "2026-06-30 10:47:19",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1802138": [
        {
            "ioc_value": "156.245.147.98:9010",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-04-29 14:43:24",
            "last_seen_utc": "2026-06-30 10:46:50",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1801960": [
        {
            "ioc_value": "156.245.147.101:9010",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-04-29 07:49:06",
            "last_seen_utc": "2026-06-30 10:46:49",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "Agentemis,BEACON,Cobalt Strike,CobaltStrike,cobeacon",
            "anonymous": "0",
            "reporter": "whoamix302"
        }
    ],
    "1800975": [
        {
            "ioc_value": "45.43.59.179:53",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-04-27 11:02:18",
            "last_seen_utc": "2026-06-30 10:47:07",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1800972": [
        {
            "ioc_value": "ns1.twnic.top",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-04-27 10:46:10",
            "last_seen_utc": "2026-06-30 10:46:26",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1800970": [
        {
            "ioc_value": "cc.twnic.top",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-04-27 10:43:32",
            "last_seen_utc": "2026-06-30 10:46:22",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1800899": [
        {
            "ioc_value": "147.78.2.110:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-04-27 08:23:19",
            "last_seen_utc": "2026-06-30 10:46:46",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-987654321",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1800528": [
        {
            "ioc_value": "http://pillow.riverbridge.site",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-04-26 19:14:08",
            "last_seen_utc": "2026-06-30 11:22:07",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "ipocalur,Vidar",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1800509": [
        {
            "ioc_value": "pillow.riverbridge.site",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-04-26 18:19:19",
            "last_seen_utc": "2026-06-30 11:22:07",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://bazaar.abuse.ch/sample/2199baf11d50dd10555f8aec122178e03b62570fc0d4614a8e928978dc547154/",
            "tags": "ipocalur,Vidar",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1800411": [
        {
            "ioc_value": "http://91.92.242.236/oPvjr94jfe/index.php",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.amadey",
            "malware_alias": null,
            "malware_printable": "Amadey",
            "first_seen_utc": "2026-04-26 18:11:00",
            "last_seen_utc": "2026-06-30 11:23:34",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "54e64e,amadey,c2",
            "anonymous": "0",
            "reporter": "Bitsight"
        }
    ],
    "1800301": [
        {
            "ioc_value": "156.245.147.98:53",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-04-26 08:48:33",
            "last_seen_utc": "2026-06-30 10:46:50",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1800299": [
        {
            "ioc_value": "dd.googleos-js.vip",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-04-26 08:43:33",
            "last_seen_utc": "2026-06-30 10:46:22",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1800298": [
        {
            "ioc_value": "d2.googleos-js.vip",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-04-26 08:43:30",
            "last_seen_utc": "2026-06-30 10:46:22",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1797248": [
        {
            "ioc_value": "psy.flise-mesteren.dk",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-04-24 15:18:06",
            "last_seen_utc": "2026-06-30 11:21:44",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "r88vry,Vidar",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1797247": [
        {
            "ioc_value": "https://psy.flise-mesteren.dk/",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-04-24 15:18:01",
            "last_seen_utc": "2026-06-30 11:21:44",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "r88vry,Vidar",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1796426": [
        {
            "ioc_value": "http://196.251.107.248/kont2rt/index.php",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.amadey",
            "malware_alias": null,
            "malware_printable": "Amadey",
            "first_seen_utc": "2026-04-23 04:45:34",
            "last_seen_utc": "2026-06-30 11:25:06",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "Amadey",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1796313": [
        {
            "ioc_value": "192.210.174.149:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-04-22 20:53:22",
            "last_seen_utc": "2026-06-30 10:46:55",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1796097": [
        {
            "ioc_value": "47.94.162.43:2222",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-04-22 14:30:19",
            "last_seen_utc": "2026-06-30 10:47:12",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "Agentemis,BEACON,Cobalt Strike,CobaltStrike,cobeacon",
            "anonymous": "0",
            "reporter": "whoamix302"
        }
    ],
    "1796068": [
        {
            "ioc_value": "wrath.bottlevacuum.shop",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-04-22 11:17:13",
            "last_seen_utc": "2026-06-30 11:21:55",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "opiusra,Vidar",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1796067": [
        {
            "ioc_value": "http://wrath.bottlevacuum.shop",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-04-22 11:17:09",
            "last_seen_utc": "2026-06-30 11:21:55",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "opiusra,Vidar",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1796009": [
        {
            "ioc_value": "82.156.62.131:5555",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-04-22 10:36:10",
            "last_seen_utc": "2026-06-30 10:47:19",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "Agentemis,BEACON,Cobalt Strike,CobaltStrike,cobeacon",
            "anonymous": "0",
            "reporter": "whoamix302"
        }
    ],
    "1794638": [
        {
            "ioc_value": "http://213.5.130.87",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-04-19 18:25:29",
            "last_seen_utc": "2026-06-30 06:01:33",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "c2,REMPROXY",
            "anonymous": "0",
            "reporter": "BlackLotusLabs"
        }
    ],
    "1793918": [
        {
            "ioc_value": "121.4.92.72:1111",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-04-18 02:46:54",
            "last_seen_utc": "2026-06-30 10:46:41",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1793803": [
        {
            "ioc_value": "https://keypharmacy.uk/",
            "ioc_type": "url",
            "threat_type": "payload_delivery",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-04-17 22:15:08",
            "last_seen_utc": "2026-06-30 07:31:04",
            "confidence_level": 75,
            "is_compromised": true,
            "reference": null,
            "tags": "ClickFix,compromised,EtherHiding,Polygon,Vidar,WordPress",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1793799": [
        {
            "ioc_value": "https://unspanel.rs/",
            "ioc_type": "url",
            "threat_type": "payload_delivery",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-04-17 22:15:06",
            "last_seen_utc": "2026-06-30 08:31:02",
            "confidence_level": 75,
            "is_compromised": true,
            "reference": null,
            "tags": "ClickFix,compromised,EtherHiding,Polygon,Vidar,WordPress",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1793739": [
        {
            "ioc_value": "43.230.200.254:53",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-04-17 20:50:11",
            "last_seen_utc": "2026-06-30 10:47:05",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1793738": [
        {
            "ioc_value": "ns2.jane2010.filegear-sg.me",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-04-17 20:44:37",
            "last_seen_utc": "2026-06-30 10:46:26",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1793737": [
        {
            "ioc_value": "ns1.jane2010.filegear-sg.me",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-04-17 20:44:14",
            "last_seen_utc": "2026-06-30 10:46:25",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1793645": [
        {
            "ioc_value": "http://213.5.130.147",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-04-17 18:15:06",
            "last_seen_utc": "2026-06-30 06:01:34",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "c2,REMPROXY",
            "anonymous": "0",
            "reporter": "BlackLotusLabs"
        }
    ],
    "1793617": [
        {
            "ioc_value": "ask.shurimaster.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-04-17 17:13:27",
            "last_seen_utc": "2026-06-30 11:21:00",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "a10fsw,Vidar",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1793616": [
        {
            "ioc_value": "https://ask.shurimaster.com/",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-04-17 17:13:25",
            "last_seen_utc": "2026-06-30 11:21:00",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "a10fsw,Vidar",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1792850": [
        {
            "ioc_value": "pir.rapidphonebuyer.co.uk",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-04-16 16:13:58",
            "last_seen_utc": "2026-06-30 11:18:41",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "d0b0p,Vidar",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1792849": [
        {
            "ioc_value": "https://pir.rapidphonebuyer.co.uk/",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-04-16 16:13:56",
            "last_seen_utc": "2026-06-30 11:18:41",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "d0b0p,Vidar",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1792719": [
        {
            "ioc_value": "gusto.brothbridge.space",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-04-16 11:16:20",
            "last_seen_utc": "2026-06-30 11:21:23",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "odiznrio,Vidar",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1792718": [
        {
            "ioc_value": "http://gusto.brothbridge.space",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-04-16 11:16:17",
            "last_seen_utc": "2026-06-30 11:21:23",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "odiznrio,Vidar",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1792707": [
        {
            "ioc_value": "43.167.177.224:7778",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-04-16 10:56:58",
            "last_seen_utc": "2026-06-30 10:47:05",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1792532": [
        {
            "ioc_value": "bxx2rghe05kng.cfc-execute.bj.baidubce.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-04-16 02:43:39",
            "last_seen_utc": "2026-06-30 10:46:22",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1791747": [
        {
            "ioc_value": "http://107.189.24.190:80",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-04-15 11:43:19",
            "last_seen_utc": "2026-06-30 11:15:58",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "gr00n1,Vidar",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1791738": [
        {
            "ioc_value": "139.224.23.63:8866",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-04-15 11:39:45",
            "last_seen_utc": "2026-06-30 10:46:45",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "Agentemis,BEACON,Cobalt Strike,CobaltStrike,cobeacon",
            "anonymous": "0",
            "reporter": "whoamix302"
        }
    ],
    "1791688": [
        {
            "ioc_value": "venom.summertunnel.shop",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-04-15 08:15:17",
            "last_seen_utc": "2026-06-30 11:21:11",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "ozpifus,Vidar",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1791687": [
        {
            "ioc_value": "http://venom.summertunnel.shop",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-04-15 08:15:13",
            "last_seen_utc": "2026-06-30 11:21:11",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "ozpifus,Vidar",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1791265": [
        {
            "ioc_value": "https://cakramakmurabadi.com/",
            "ioc_type": "url",
            "threat_type": "payload_delivery",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-04-15 01:15:17",
            "last_seen_utc": "2026-06-30 07:31:03",
            "confidence_level": 75,
            "is_compromised": true,
            "reference": null,
            "tags": "ClickFix,compromised,EtherHiding,Polygon,Vidar,WordPress",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1791228": [
        {
            "ioc_value": "https://opportunitiesforeveryone.net/",
            "ioc_type": "url",
            "threat_type": "payload_delivery",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-04-15 01:15:04",
            "last_seen_utc": "2026-06-29 17:01:03",
            "confidence_level": 75,
            "is_compromised": true,
            "reference": null,
            "tags": "ClickFix,compromised,EtherHiding,Polygon,Vidar,WordPress",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1790859": [
        {
            "ioc_value": "lts.cloudvaly.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-04-14 16:03:14",
            "last_seen_utc": "2026-06-30 11:13:03",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "ho0r1,Vidar",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1790857": [
        {
            "ioc_value": "https://lts.cloudvaly.com/",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-04-14 16:03:10",
            "last_seen_utc": "2026-06-30 11:13:03",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "ho0r1,Vidar",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1790171": [
        {
            "ioc_value": "dzodu.sparklingideas.space",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-04-14 14:11:23",
            "last_seen_utc": "2026-06-30 11:20:28",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "odzdkzo,Vidar",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1790170": [
        {
            "ioc_value": "http://dzodu.sparklingideas.space",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-04-14 14:11:18",
            "last_seen_utc": "2026-06-30 11:20:28",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "odzdkzo,Vidar",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1790169": [
        {
            "ioc_value": "http://kdije.weirdthings.site",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-04-14 14:10:11",
            "last_seen_utc": "2026-06-30 11:17:36",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "okfueh,Vidar",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1787396": [
        {
            "ioc_value": "https://gustoantico.ch/",
            "ioc_type": "url",
            "threat_type": "payload_delivery",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-04-14 11:34:45",
            "last_seen_utc": "2026-06-29 15:31:03",
            "confidence_level": 75,
            "is_compromised": true,
            "reference": null,
            "tags": "ClickFix,compromised,EtherHiding,Polygon,Vidar,WordPress",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1787027": [
        {
            "ioc_value": "https://cannabis-dna.com/",
            "ioc_type": "url",
            "threat_type": "payload_delivery",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-04-14 11:32:51",
            "last_seen_utc": "2026-06-30 11:15:03",
            "confidence_level": 75,
            "is_compromised": true,
            "reference": null,
            "tags": "ClickFix,compromised,EtherHiding,Polygon,Vidar,WordPress",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1786636": [
        {
            "ioc_value": "https://thekiss.gr/",
            "ioc_type": "url",
            "threat_type": "payload_delivery",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-04-14 09:47:57",
            "last_seen_utc": "2026-06-30 07:31:04",
            "confidence_level": 75,
            "is_compromised": true,
            "reference": null,
            "tags": "ClickFix,compromised,EtherHiding,Polygon,Vidar,WordPress",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1786385": [
        {
            "ioc_value": "https://swanriverschool.org/",
            "ioc_type": "url",
            "threat_type": "payload_delivery",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-04-14 09:46:43",
            "last_seen_utc": "2026-06-30 07:31:04",
            "confidence_level": 75,
            "is_compromised": true,
            "reference": null,
            "tags": "ClickFix,compromised,EtherHiding,Polygon,Vidar,WordPress",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1786292": [
        {
            "ioc_value": "https://dainikkishoreganj.com/",
            "ioc_type": "url",
            "threat_type": "payload_delivery",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-04-14 09:46:16",
            "last_seen_utc": "2026-06-30 07:31:03",
            "confidence_level": 75,
            "is_compromised": true,
            "reference": null,
            "tags": "ClickFix,compromised,EtherHiding,Polygon,Vidar,WordPress",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1786290": [
        {
            "ioc_value": "https://tools4teens.net/",
            "ioc_type": "url",
            "threat_type": "payload_delivery",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-04-14 09:46:15",
            "last_seen_utc": "2026-06-30 07:31:03",
            "confidence_level": 75,
            "is_compromised": true,
            "reference": null,
            "tags": "ClickFix,compromised,EtherHiding,Polygon,Vidar,WordPress",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1785832": [
        {
            "ioc_value": "https://knowmat.com/",
            "ioc_type": "url",
            "threat_type": "payload_delivery",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-04-14 09:43:49",
            "last_seen_utc": "2026-06-30 07:31:03",
            "confidence_level": 75,
            "is_compromised": true,
            "reference": null,
            "tags": "ClickFix,compromised,EtherHiding,Polygon,Vidar,WordPress",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1785740": [
        {
            "ioc_value": "https://lisanslab.com/",
            "ioc_type": "url",
            "threat_type": "payload_delivery",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-04-14 09:43:22",
            "last_seen_utc": "2026-06-30 07:31:03",
            "confidence_level": 75,
            "is_compromised": true,
            "reference": null,
            "tags": "ClickFix,compromised,EtherHiding,Polygon,Vidar,WordPress",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1785064": [
        {
            "ioc_value": "pre.hifive.net.au",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-04-13 07:47:21",
            "last_seen_utc": "2026-06-30 11:20:07",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "Vidar",
            "anonymous": "0",
            "reporter": "crep1x"
        }
    ],
    "1785065": [
        {
            "ioc_value": "pre.sequareeus.online",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-04-13 07:47:21",
            "last_seen_utc": "2026-06-29 13:37:38",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "Vidar",
            "anonymous": "0",
            "reporter": "crep1x"
        }
    ],
    "1785069": [
        {
            "ioc_value": "fuz.supportify360.io",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-04-13 07:47:21",
            "last_seen_utc": "2026-06-29 13:37:45",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "Vidar",
            "anonymous": "0",
            "reporter": "crep1x"
        }
    ],
    "1785049": [
        {
            "ioc_value": "https://pre.hifive.net.au/",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-04-13 07:46:34",
            "last_seen_utc": "2026-06-30 11:20:07",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "Vidar",
            "anonymous": "0",
            "reporter": "crep1x"
        }
    ],
    "1784558": [
        {
            "ioc_value": "47.104.248.7:8884",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-04-12 06:34:43",
            "last_seen_utc": "2026-06-30 10:47:08",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "Agentemis,BEACON,C2,Cobalt Strike,CobaltStrike,cobeacon",
            "anonymous": "0",
            "reporter": "whoamix302"
        }
    ],
    "1783757": [
        {
            "ioc_value": "etokrol.lol",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "js.iclickfix",
            "malware_alias": null,
            "malware_printable": "IClickFix",
            "first_seen_utc": "2026-04-11 07:06:51",
            "last_seen_utc": "2026-06-29 13:37:49",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "clickfix",
            "anonymous": "1",
            "reporter": "m_govcert_ch"
        }
    ],
    "1783849": [
        {
            "ioc_value": "https://cdn.mensualgeneratr.com/",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.smokeloader",
            "malware_alias": "Dofoil,Sharik,Smoke,Smoke Loader",
            "malware_printable": "SmokeLoader",
            "first_seen_utc": "2026-04-11 07:06:31",
            "last_seen_utc": "2026-06-30 10:02:52",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "c2,SmokeLoader",
            "anonymous": "0",
            "reporter": "Bitsight"
        }
    ],
    "1784155": [
        {
            "ioc_value": "101.35.214.58:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-04-11 06:36:58",
            "last_seen_utc": "2026-06-30 10:46:30",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-305419896",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1783801": [
        {
            "ioc_value": "ldt.hifive.net.au",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-04-10 12:09:04",
            "last_seen_utc": "2026-06-29 13:37:41",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "Vidar",
            "anonymous": "0",
            "reporter": "crep1x"
        }
    ],
    "1783375": [
        {
            "ioc_value": "39.102.125.11:4435",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-04-09 14:48:47",
            "last_seen_utc": "2026-06-30 10:47:00",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1782183": [
        {
            "ioc_value": "gy4q.supportly.au",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-04-07 07:46:06",
            "last_seen_utc": "2026-06-29 13:37:29",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "Vidar",
            "anonymous": "0",
            "reporter": "crep1x"
        }
    ],
    "1782182": [
        {
            "ioc_value": "dzdi.serendipityhub.space",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-04-07 07:46:05",
            "last_seen_utc": "2026-06-30 11:19:56",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "Vidar",
            "anonymous": "0",
            "reporter": "crep1x"
        }
    ],
    "1782152": [
        {
            "ioc_value": "http://dzdi.serendipityhub.space/",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-04-07 07:43:55",
            "last_seen_utc": "2026-06-30 11:19:56",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "Vidar",
            "anonymous": "0",
            "reporter": "crep1x"
        }
    ],
    "1781907": [
        {
            "ioc_value": "43.139.108.161:8192",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-04-06 18:49:49",
            "last_seen_utc": "2026-06-30 10:47:03",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "Agentemis,BEACON,C2,Cobalt Strike,CobaltStrike,cobeacon",
            "anonymous": "0",
            "reporter": "whoamix302"
        }
    ],
    "1781225": [
        {
            "ioc_value": "111.230.217.36:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-04-04 20:44:05",
            "last_seen_utc": "2026-06-30 10:46:34",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1781224": [
        {
            "ioc_value": "109.244.130.113:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-04-04 20:44:01",
            "last_seen_utc": "2026-06-30 10:46:33",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1780720": [
        {
            "ioc_value": "hor.kaitorinihon.jp",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-04-03 16:13:22",
            "last_seen_utc": "2026-06-30 11:19:03",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "Vidar",
            "anonymous": "0",
            "reporter": "crep1x"
        }
    ],
    "1780716": [
        {
            "ioc_value": "https://hor.kaitorinihon.jp/",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-04-03 16:12:59",
            "last_seen_utc": "2026-06-30 11:19:03",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "Vidar",
            "anonymous": "0",
            "reporter": "crep1x"
        }
    ],
    "1780037": [
        {
            "ioc_value": "164.92.67.70:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.havoc",
            "malware_alias": "Havokiz",
            "malware_printable": "Havoc",
            "first_seen_utc": "2026-04-01 10:45:34",
            "last_seen_utc": "2026-06-30 10:43:44",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": "https://www.shodan.io/host/164.92.67.70#443",
            "tags": "c2,havoc,shodan",
            "anonymous": "0",
            "reporter": "juroots"
        }
    ],
    "1777986": [
        {
            "ioc_value": "47.122.47.221:8880",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-03-28 14:56:18",
            "last_seen_utc": "2026-06-30 10:47:10",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1777607": [
        {
            "ioc_value": "pn2.skfilmsint.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-03-27 21:24:29",
            "last_seen_utc": "2026-06-30 11:17:48",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "Vidar",
            "anonymous": "0",
            "reporter": "crep1x"
        }
    ],
    "1777609": [
        {
            "ioc_value": "gre.syslicense.net",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-03-27 21:24:29",
            "last_seen_utc": "2026-06-30 11:17:15",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "Vidar",
            "anonymous": "0",
            "reporter": "crep1x"
        }
    ],
    "1777611": [
        {
            "ioc_value": "fefeo.iknowthat.space",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-03-27 21:24:29",
            "last_seen_utc": "2026-06-30 11:18:08",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "Vidar",
            "anonymous": "0",
            "reporter": "crep1x"
        }
    ],
    "1777601": [
        {
            "ioc_value": "https://pn2.skfilmsint.com/",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-03-27 21:24:17",
            "last_seen_utc": "2026-06-30 11:17:48",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "Vidar",
            "anonymous": "0",
            "reporter": "crep1x"
        }
    ],
    "1777603": [
        {
            "ioc_value": "https://gre.syslicense.net/",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-03-27 21:24:17",
            "last_seen_utc": "2026-06-30 11:17:15",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "Vidar",
            "anonymous": "0",
            "reporter": "crep1x"
        }
    ],
    "1777605": [
        {
            "ioc_value": "http://fefeo.iknowthat.space/",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-03-27 21:24:17",
            "last_seen_utc": "2026-06-30 11:18:08",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "Vidar",
            "anonymous": "0",
            "reporter": "crep1x"
        }
    ],
    "1777296": [
        {
            "ioc_value": "185.242.3.83:2202",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-03-27 12:01:30",
            "last_seen_utc": "2026-06-30 10:44:09",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/185.242.3.83",
            "tags": "AS60223,AsyncRAT,C2,censys,NETIFACE-AS,RAT",
            "anonymous": "0",
            "reporter": "DonPasci"
        }
    ],
    "1777088": [
        {
            "ioc_value": "94.154.35.153:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-03-27 07:06:39",
            "last_seen_utc": "2026-06-29 13:38:28",
            "confidence_level": 90,
            "is_compromised": false,
            "reference": "https://clickfix.carsonww.com/domains/mayaktours.com",
            "tags": "C2,ClearFake,ClickFix,ErrTraffic",
            "anonymous": "0",
            "reporter": "Lenny_3BO"
        }
    ],
    "1777089": [
        {
            "ioc_value": "178.16.52.101:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-03-27 07:06:39",
            "last_seen_utc": "2026-06-29 13:39:39",
            "confidence_level": 90,
            "is_compromised": false,
            "reference": "https://clickfix.carsonww.com/domains/attentiongetters.com",
            "tags": "C2,ClearFake,ClickFix,ErrTraffic,macOS",
            "anonymous": "0",
            "reporter": "Lenny_3BO"
        }
    ],
    "1777014": [
        {
            "ioc_value": "49.234.199.152:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-03-27 00:00:31",
            "last_seen_utc": "2026-06-30 10:47:13",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/49.234.199.152",
            "tags": "AS45090,C2,censys,CobaltStrike,cs-watermark-987654321,TENCENT-NET-AP",
            "anonymous": "0",
            "reporter": "DonPasci"
        }
    ],
    "1776672": [
        {
            "ioc_value": "158.94.209.95:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.gcleaner",
            "malware_alias": null,
            "malware_printable": "GCleaner",
            "first_seen_utc": "2026-03-26 14:59:36",
            "last_seen_utc": "2026-06-30 11:24:12",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "GCleaner,loader",
            "anonymous": "0",
            "reporter": "Bitsight"
        }
    ],
    "1774903": [
        {
            "ioc_value": "37.72.172.58:7707",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-03-24 12:01:13",
            "last_seen_utc": "2026-06-30 10:45:28",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/37.72.172.58",
            "tags": "AS29802,AsyncRAT,C2,censys,HVC-AS,RAT",
            "anonymous": "0",
            "reporter": "DonPasci"
        }
    ],
    "1774898": [
        {
            "ioc_value": "47.92.208.27:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-03-24 12:00:35",
            "last_seen_utc": "2026-06-30 10:47:12",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/47.92.208.27",
            "tags": "ALIBABA-CN-NET,AS37963,C2,censys,CobaltStrike,cs-watermark-666666666",
            "anonymous": "0",
            "reporter": "DonPasci"
        }
    ],
    "1774595": [
        {
            "ioc_value": "154.83.12.132:53",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-03-23 21:06:09",
            "last_seen_utc": "2026-06-30 10:46:48",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1774355": [
        {
            "ioc_value": "kdije.weirdthings.site",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-03-23 13:42:00",
            "last_seen_utc": "2026-06-30 11:17:37",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "Vidar",
            "anonymous": "0",
            "reporter": "crep1x"
        }
    ],
    "1774216": [
        {
            "ioc_value": "msi.swadeshcomputer.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-03-23 08:02:27",
            "last_seen_utc": "2026-06-30 11:16:41",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "Vidar",
            "anonymous": "0",
            "reporter": "crep1x"
        }
    ],
    "1774200": [
        {
            "ioc_value": "https://msi.swadeshcomputer.com/",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-03-23 08:01:55",
            "last_seen_utc": "2026-06-30 11:16:41",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "Vidar",
            "anonymous": "0",
            "reporter": "crep1x"
        }
    ],
    "1774089": [
        {
            "ioc_value": "195.250.25.176:58101",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-03-23 04:01:29",
            "last_seen_utc": "2026-06-30 10:44:21",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/195.250.25.176",
            "tags": "AdaptixC2,AS36454,C2,censys,WHG-DAL",
            "anonymous": "0",
            "reporter": "DonPasci"
        }
    ],
    "1773536": [
        {
            "ioc_value": "156.239.252.191:448",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-03-22 18:02:20",
            "last_seen_utc": "2026-06-30 10:46:49",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "BEACON,C2,CobaltStrike,Shodan",
            "anonymous": "0",
            "reporter": "whoamix302"
        }
    ],
    "1773754": [
        {
            "ioc_value": "138.226.236.52:13212",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-03-22 12:01:29",
            "last_seen_utc": "2026-06-30 10:43:23",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/138.226.236.52",
            "tags": "AdaptixC2,AS205775,C2,censys,NEONCORENETWORKS",
            "anonymous": "0",
            "reporter": "DonPasci"
        }
    ],
    "1772653": [
        {
            "ioc_value": "5.101.86.72:3305",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-03-20 16:00:44",
            "last_seen_utc": "2026-06-30 10:45:51",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/5.101.86.72",
            "tags": "AS-GLOBALTELEHOST,AS62563,C2,censys,RAT,Remcos",
            "anonymous": "0",
            "reporter": "DonPasci"
        }
    ],
    "1772652": [
        {
            "ioc_value": "101.35.95.103:4444",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-03-20 16:00:21",
            "last_seen_utc": "2026-06-30 10:46:30",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/101.35.95.103",
            "tags": "AS45090,C2,censys,CobaltStrike,cs-watermark-0,TENCENT-NET-AP",
            "anonymous": "0",
            "reporter": "DonPasci"
        }
    ],
    "1772372": [
        {
            "ioc_value": "pr2.codetohaven.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-03-20 13:59:59",
            "last_seen_utc": "2026-06-30 11:16:30",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "Vidar",
            "anonymous": "0",
            "reporter": "crep1x"
        }
    ],
    "1772370": [
        {
            "ioc_value": "https://pr2.codetohaven.com/",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-03-20 13:59:49",
            "last_seen_utc": "2026-06-30 11:16:30",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "Vidar",
            "anonymous": "0",
            "reporter": "crep1x"
        }
    ],
    "1771988": [
        {
            "ioc_value": "https://rpc-cloud.beer/api/css.js",
            "ioc_type": "url",
            "threat_type": "payload_delivery",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-03-20 10:32:12",
            "last_seen_utc": "2026-06-29 16:02:00",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "ClickFix,ErrTraffic",
            "anonymous": "0",
            "reporter": "HuntYethHounds"
        }
    ],
    "1771875": [
        {
            "ioc_value": "182.255.44.96:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-03-20 06:42:00",
            "last_seen_utc": "2026-06-30 10:46:53",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-987654321",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1771791": [
        {
            "ioc_value": "8.136.13.87:7001",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-03-20 00:02:12",
            "last_seen_utc": "2026-06-30 10:46:06",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/8.136.13.87",
            "tags": "AdaptixC2,ALIBABA-CN-NET,AS37963,C2,censys",
            "anonymous": "0",
            "reporter": "DonPasci"
        }
    ],
    "1771714": [
        {
            "ioc_value": "45.136.13.247:43211",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-03-19 20:02:51",
            "last_seen_utc": "2026-06-30 10:45:35",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/45.136.13.247",
            "tags": "AdaptixC2,AS139659,C2,censys,LUCID-AS-AP",
            "anonymous": "0",
            "reporter": "DonPasci"
        }
    ],
    "1771456": [
        {
            "ioc_value": "dhzuadd.hellothere.sbs",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-03-19 13:11:25",
            "last_seen_utc": "2026-06-30 11:17:04",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drkfiz,Vidar",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1771455": [
        {
            "ioc_value": "https://dhzuadd.hellothere.sbs",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-03-19 13:11:20",
            "last_seen_utc": "2026-06-30 11:17:03",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drkfiz,Vidar",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1769955": [
        {
            "ioc_value": "43.138.39.212:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-03-18 04:00:18",
            "last_seen_utc": "2026-06-30 10:47:03",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/43.138.39.212",
            "tags": "AS45090,C2,censys,CobaltStrike,TENCENT-NET-AP",
            "anonymous": "0",
            "reporter": "DonPasci"
        }
    ],
    "1769012": [
        {
            "ioc_value": "88.218.60.191:4321",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-03-17 04:01:23",
            "last_seen_utc": "2026-06-30 10:46:13",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/88.218.60.191",
            "tags": "AdaptixC2,AS48282,C2,censys,VDSINA-AS",
            "anonymous": "0",
            "reporter": "DonPasci"
        }
    ],
    "1768984": [
        {
            "ioc_value": "156.245.144.203:8880",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-03-17 02:48:23",
            "last_seen_utc": "2026-06-30 10:46:49",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1768644": [
        {
            "ioc_value": "35.179.229.71:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.havoc",
            "malware_alias": "Havokiz",
            "malware_printable": "Havoc",
            "first_seen_utc": "2026-03-16 20:01:10",
            "last_seen_utc": "2026-06-30 10:45:27",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/35.179.229.71",
            "tags": "AMAZON-02,AS16509,C2,censys,Havoc",
            "anonymous": "0",
            "reporter": "DonPasci"
        }
    ],
    "1767951": [
        {
            "ioc_value": "http://82.38.71.155/",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.smokeloader",
            "malware_alias": "Dofoil,Sharik,Smoke,Smoke Loader",
            "malware_printable": "SmokeLoader",
            "first_seen_utc": "2026-03-16 10:41:19",
            "last_seen_utc": "2026-06-29 17:43:56",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "c2,SmokeLoader",
            "anonymous": "0",
            "reporter": "Bitsight"
        }
    ],
    "1767077": [
        {
            "ioc_value": "185.242.3.83:5505",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-03-15 16:00:41",
            "last_seen_utc": "2026-06-30 10:44:09",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/185.242.3.83",
            "tags": "AS60223,AsyncRAT,C2,censys,NETIFACE-AS,RAT",
            "anonymous": "0",
            "reporter": "DonPasci"
        }
    ],
    "1767015": [
        {
            "ioc_value": "156.245.144.203:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-03-15 14:49:59",
            "last_seen_utc": "2026-06-30 10:46:49",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1767016": [
        {
            "ioc_value": "156.245.144.203:4443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-03-15 14:49:59",
            "last_seen_utc": "2026-06-30 10:46:49",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1766813": [
        {
            "ioc_value": "119.29.117.194:801",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-03-15 06:51:25",
            "last_seen_utc": "2026-06-29 10:46:27",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-987654321",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1766764": [
        {
            "ioc_value": "202.191.67.71:50003",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-03-15 04:01:14",
            "last_seen_utc": "2026-06-30 10:44:28",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/202.191.67.71",
            "tags": "AdaptixC2,AS131262,C2,censys,KELNET-AS-AP",
            "anonymous": "0",
            "reporter": "DonPasci"
        }
    ],
    "1766342": [
        {
            "ioc_value": "sil-api-js.click",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-03-14 17:20:42",
            "last_seen_utc": "2026-06-29 13:32:31",
            "confidence_level": 85,
            "is_compromised": false,
            "reference": "https://www.sekoia.io/en/blog/clearfake-a-newcomer-to-the-fake-updates-threats-landscape/",
            "tags": "clearfake,clickfix,errtraffic",
            "anonymous": "0",
            "reporter": "Lenny_3BO"
        }
    ],
    "1766343": [
        {
            "ioc_value": "cdn-2faclov.sbs",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-03-14 17:20:41",
            "last_seen_utc": "2026-06-29 13:39:08",
            "confidence_level": 85,
            "is_compromised": false,
            "reference": "https://www.sekoia.io/en/blog/clearfake-a-newcomer-to-the-fake-updates-threats-landscape/",
            "tags": "clearfake,clickfix,errtraffic",
            "anonymous": "0",
            "reporter": "Lenny_3BO"
        }
    ],
    "1766344": [
        {
            "ioc_value": "winecdn.sbs",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-03-14 17:20:41",
            "last_seen_utc": "2026-06-29 13:31:51",
            "confidence_level": 85,
            "is_compromised": false,
            "reference": "https://www.sekoia.io/en/blog/clearfake-a-newcomer-to-the-fake-updates-threats-landscape/",
            "tags": "clearfake,clickfix,errtraffic",
            "anonymous": "0",
            "reporter": "Lenny_3BO"
        }
    ],
    "1765787": [
        {
            "ioc_value": "5.101.82.60:2509",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-03-14 08:00:55",
            "last_seen_utc": "2026-06-30 10:45:48",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/5.101.82.60",
            "tags": "AS-GLOBALTELEHOST,AS63023,C2,censys,RAT,Remcos",
            "anonymous": "0",
            "reporter": "DonPasci"
        }
    ],
    "1765444": [
        {
            "ioc_value": "pan.paihost.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-03-13 15:06:16",
            "last_seen_utc": "2026-06-30 11:15:47",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "Vidar",
            "anonymous": "0",
            "reporter": "crep1x"
        }
    ],
    "1765442": [
        {
            "ioc_value": "https://pan.paihost.com/",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-03-13 15:05:58",
            "last_seen_utc": "2026-06-30 11:15:47",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "Vidar",
            "anonymous": "0",
            "reporter": "crep1x"
        }
    ],
    "1764276": [
        {
            "ioc_value": "46.151.182.205:6606",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-03-13 04:01:11",
            "last_seen_utc": "2026-06-30 10:45:44",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/46.151.182.205",
            "tags": "AS205759,AsyncRAT,C2,censys,GHOSTYNETWORKS,RAT",
            "anonymous": "0",
            "reporter": "DonPasci"
        }
    ],
    "1763543": [
        {
            "ioc_value": "159.138.31.252:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-03-11 16:01:48",
            "last_seen_utc": "2026-06-30 10:43:39",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/159.138.31.252",
            "tags": "AS136907,C2,censys,HWCLOUDS-AS-AP,Mythic",
            "anonymous": "0",
            "reporter": "DonPasci"
        }
    ],
    "1763170": [
        {
            "ioc_value": "60.247.206.23:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-03-11 07:03:38",
            "last_seen_utc": "2026-06-30 10:47:13",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-391144938",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1762854": [
        {
            "ioc_value": "85.206.168.238:2404",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-03-10 16:00:58",
            "last_seen_utc": "2026-06-30 10:46:12",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/85.206.168.238",
            "tags": "AS61272,C2,censys,IST-AS,RAT,Remcos",
            "anonymous": "0",
            "reporter": "DonPasci"
        }
    ],
    "1762492": [
        {
            "ioc_value": "107.172.3.15:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-03-10 00:01:13",
            "last_seen_utc": "2026-06-30 10:43:13",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/107.172.3.15",
            "tags": "AS-COLOCROSSING,AS36352,C2,censys,Mythic",
            "anonymous": "0",
            "reporter": "DonPasci"
        }
    ],
    "1762153": [
        {
            "ioc_value": "ooe.myserver.com.bd",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-03-09 09:29:37",
            "last_seen_utc": "2026-06-30 11:15:37",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "Vidar",
            "anonymous": "0",
            "reporter": "crep1x"
        }
    ],
    "1762131": [
        {
            "ioc_value": "https://ooe.myserver.com.bd/",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-03-09 09:29:17",
            "last_seen_utc": "2026-06-30 11:15:36",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "Vidar",
            "anonymous": "0",
            "reporter": "crep1x"
        }
    ],
    "1759331": [
        {
            "ioc_value": "194.36.178.53:4321",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-03-06 00:01:40",
            "last_seen_utc": "2026-06-30 10:44:19",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/194.36.178.53",
            "tags": "AdaptixC2,AS200740,C2,censys,FIRST-SERVER-EU-AS",
            "anonymous": "0",
            "reporter": "DonPasci"
        }
    ],
    "1758456": [
        {
            "ioc_value": "http://213.5.130.197",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-03-05 06:17:58",
            "last_seen_utc": "2026-06-30 06:01:35",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "c2,REMPROXY",
            "anonymous": "0",
            "reporter": "BlackLotusLabs"
        }
    ],
    "1758457": [
        {
            "ioc_value": "http://213.5.130.154",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-03-05 06:17:57",
            "last_seen_utc": "2026-06-30 06:01:34",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "c2,REMPROXY",
            "anonymous": "0",
            "reporter": "BlackLotusLabs"
        }
    ],
    "1758458": [
        {
            "ioc_value": "http://213.5.130.200",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-03-05 06:17:56",
            "last_seen_utc": "2026-06-30 06:01:35",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "c2,REMPROXY",
            "anonymous": "0",
            "reporter": "BlackLotusLabs"
        }
    ],
    "1758459": [
        {
            "ioc_value": "http://213.5.130.131",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-03-05 06:17:55",
            "last_seen_utc": "2026-06-30 06:01:35",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "c2,REMPROXY",
            "anonymous": "0",
            "reporter": "BlackLotusLabs"
        }
    ],
    "1758460": [
        {
            "ioc_value": "http://213.5.130.179",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-03-05 06:17:54",
            "last_seen_utc": "2026-06-30 06:01:33",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "c2,REMPROXY",
            "anonymous": "0",
            "reporter": "BlackLotusLabs"
        }
    ],
    "1758461": [
        {
            "ioc_value": "http://213.5.130.189",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-03-05 06:17:54",
            "last_seen_utc": "2026-06-30 06:01:34",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "c2,REMPROXY",
            "anonymous": "0",
            "reporter": "BlackLotusLabs"
        }
    ],
    "1758006": [
        {
            "ioc_value": "70.153.18.45:10002",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-03-04 04:01:12",
            "last_seen_utc": "2026-06-30 10:46:04",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/70.153.18.45",
            "tags": "AS8075,censys,EvilGoPhish,MICROSOFT-CORP-MSN-AS-BLOCK,panel,Phishing",
            "anonymous": "0",
            "reporter": "DonPasci"
        }
    ],
    "1756664": [
        {
            "ioc_value": "ctl.it-bd.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-03-02 09:31:49",
            "last_seen_utc": "2026-06-30 11:15:04",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "Vidar",
            "anonymous": "0",
            "reporter": "crep1x"
        }
    ],
    "1756622": [
        {
            "ioc_value": "https://ctl.it-bd.com/",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-03-02 09:30:33",
            "last_seen_utc": "2026-06-30 11:15:04",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "Vidar",
            "anonymous": "0",
            "reporter": "crep1x"
        }
    ],
    "1756333": [
        {
            "ioc_value": "171.22.181.114:38990",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.pink",
            "malware_alias": null,
            "malware_printable": "Pink",
            "first_seen_utc": "2026-03-01 14:27:15",
            "last_seen_utc": "2026-06-30 10:55:42",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "Pink",
            "anonymous": "0",
            "reporter": "Bitsight"
        }
    ],
    "1755728": [
        {
            "ioc_value": "188.227.14.105:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-02-28 11:00:05",
            "last_seen_utc": "2026-06-30 10:46:55",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/188.227.14.105",
            "tags": "AS35000,C2,censys",
            "anonymous": "0",
            "reporter": "dyingbreeds_"
        }
    ],
    "1754813": [
        {
            "ioc_value": "47.120.20.86:8888",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-02-25 20:02:24",
            "last_seen_utc": "2026-06-30 10:47:09",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/47.120.20.86",
            "tags": "ALIBABA-CN-NET,AS37963,C2,censys,CobaltStrike,cs-watermark-987654321",
            "anonymous": "0",
            "reporter": "DonPasci"
        }
    ],
    "1754671": [
        {
            "ioc_value": "115.190.250.28:5521",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-02-25 19:01:08",
            "last_seen_utc": "2026-06-30 10:46:36",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/115.190.250.28",
            "tags": "AS137718,C2,censys",
            "anonymous": "0",
            "reporter": "dyingbreeds_"
        }
    ],
    "1754439": [
        {
            "ioc_value": "185.72.8.121:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.ransomhub",
            "malware_alias": null,
            "malware_printable": "RansomHub",
            "first_seen_utc": "2026-02-25 09:05:20",
            "last_seen_utc": "2026-06-30 10:44:10",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RansomHub",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1754438": [
        {
            "ioc_value": "185.72.8.121:1032",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.ransomhub",
            "malware_alias": null,
            "malware_printable": "RansomHub",
            "first_seen_utc": "2026-02-25 09:05:18",
            "last_seen_utc": "2026-06-30 10:44:10",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RansomHub",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1753925": [
        {
            "ioc_value": "113.45.185.225:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-02-24 04:01:15",
            "last_seen_utc": "2026-06-30 10:46:35",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/113.45.185.225",
            "tags": "AS55990,C2,censys,CobaltStrike,cs-watermark-987654321,HWCSNET",
            "anonymous": "0",
            "reporter": "DonPasci"
        }
    ],
    "1753846": [
        {
            "ioc_value": "64.89.161.183:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-02-23 23:00:07",
            "last_seen_utc": "2026-06-30 10:47:14",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/64.89.161.183",
            "tags": "AS205759,C2,censys,GHOSTYNETWORKS",
            "anonymous": "0",
            "reporter": "dyingbreeds_"
        }
    ],
    "1753479": [
        {
            "ioc_value": "glo.gadgetwalabd.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-02-23 10:07:22",
            "last_seen_utc": "2026-06-30 11:14:30",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "Vidar",
            "anonymous": "0",
            "reporter": "crep1x"
        }
    ],
    "1753432": [
        {
            "ioc_value": "https://glo.gadgetwalabd.com/",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-02-23 10:06:47",
            "last_seen_utc": "2026-06-30 11:14:30",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "Vidar",
            "anonymous": "0",
            "reporter": "crep1x"
        }
    ],
    "1751483": [
        {
            "ioc_value": "45.116.104.104:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-02-21 08:01:40",
            "last_seen_utc": "2026-06-30 10:45:34",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/45.116.104.104",
            "tags": "AS215481,C2,censys,FLEXYNODE-AS,Mythic",
            "anonymous": "0",
            "reporter": "DonPasci"
        }
    ],
    "1751453": [
        {
            "ioc_value": "47.104.159.246:18443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-02-21 03:00:07",
            "last_seen_utc": "2026-06-30 10:47:08",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/47.104.159.246",
            "tags": "AS37963,C2,censys",
            "anonymous": "0",
            "reporter": "dyingbreeds_"
        }
    ],
    "1751104": [
        {
            "ioc_value": "107.172.217.220:12096",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-02-20 11:00:06",
            "last_seen_utc": "2026-06-30 10:46:32",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/107.172.217.220",
            "tags": "AS36352,C2,censys",
            "anonymous": "0",
            "reporter": "dyingbreeds_"
        }
    ],
    "1751083": [
        {
            "ioc_value": "185.180.198.3:2025",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.ransomhub",
            "malware_alias": null,
            "malware_printable": "RansomHub",
            "first_seen_utc": "2026-02-20 08:47:26",
            "last_seen_utc": "2026-06-30 10:44:04",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RansomHub",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1751084": [
        {
            "ioc_value": "185.180.198.3:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.ransomhub",
            "malware_alias": null,
            "malware_printable": "RansomHub",
            "first_seen_utc": "2026-02-20 08:47:26",
            "last_seen_utc": "2026-06-30 10:44:05",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RansomHub",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1751080": [
        {
            "ioc_value": "163.181.208.79:4506",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.deimos_c2",
            "malware_alias": null,
            "malware_printable": "DeimosC2",
            "first_seen_utc": "2026-02-20 08:46:17",
            "last_seen_utc": "2026-06-30 10:43:43",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "Deimos,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1751056": [
        {
            "ioc_value": "81.68.89.216:8088",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-02-20 07:09:34",
            "last_seen_utc": "2026-06-30 10:47:18",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-987654321",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1749217": [
        {
            "ioc_value": "111.228.4.54:4455",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-02-16 09:05:30",
            "last_seen_utc": "2026-06-30 10:46:33",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": "https://www.shodan.io/host/111.228.4.54#4455",
            "tags": "c2,cobaltstrike,cs-watermark-987654321,shodan",
            "anonymous": "0",
            "reporter": "juroots"
        }
    ],
    "1748314": [
        {
            "ioc_value": "27.221.15.199:4506",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.deimos_c2",
            "malware_alias": null,
            "malware_printable": "DeimosC2",
            "first_seen_utc": "2026-02-14 18:46:07",
            "last_seen_utc": "2026-06-30 10:45:22",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "Deimos,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1747540": [
        {
            "ioc_value": "gor.emiraride.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-02-13 14:01:35",
            "last_seen_utc": "2026-06-30 11:14:08",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "Vidar",
            "anonymous": "0",
            "reporter": "crep1x"
        }
    ],
    "1747538": [
        {
            "ioc_value": "https://gor.emiraride.com/",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-02-13 14:01:02",
            "last_seen_utc": "2026-06-30 11:14:08",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "Vidar",
            "anonymous": "0",
            "reporter": "crep1x"
        }
    ],
    "1747121": [
        {
            "ioc_value": "117.72.191.140:8028",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-02-13 06:59:13",
            "last_seen_utc": "2026-06-30 10:46:38",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": "https://www.shodan.io/host/117.72.191.140#8028",
            "tags": "c2,cobaltstrike,cs-watermark-391144938,shodan",
            "anonymous": "0",
            "reporter": "juroots"
        }
    ],
    "1746911": [
        {
            "ioc_value": "175.192.75.105:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.netsupportmanager_rat",
            "malware_alias": "NetSupport",
            "malware_printable": "NetSupportManager RAT",
            "first_seen_utc": "2026-02-12 16:01:27",
            "last_seen_utc": "2026-06-30 10:43:52",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/175.192.75.105",
            "tags": "AS4766,C2,censys,KIXS-AS-KR,Netsupport,RAT",
            "anonymous": "0",
            "reporter": "DonPasci"
        }
    ],
    "1743719": [
        {
            "ioc_value": "opa.dokantrack.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-02-09 11:14:08",
            "last_seen_utc": "2026-06-30 11:13:46",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "Vidar",
            "anonymous": "0",
            "reporter": "crep1x"
        }
    ],
    "1743622": [
        {
            "ioc_value": "https://opa.dokantrack.com/",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-02-09 11:13:23",
            "last_seen_utc": "2026-06-30 11:13:46",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "Vidar",
            "anonymous": "0",
            "reporter": "crep1x"
        }
    ],
    "1743594": [
        {
            "ioc_value": "15.204.14.143:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.havoc",
            "malware_alias": "Havokiz",
            "malware_printable": "Havoc",
            "first_seen_utc": "2026-02-09 11:00:33",
            "last_seen_utc": "2026-06-30 10:43:31",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/15.204.14.143",
            "tags": "AS16276,C2,censys,OVH",
            "anonymous": "0",
            "reporter": "dyingbreeds_"
        }
    ],
    "1743398": [
        {
            "ioc_value": "192.3.233.166:59850",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-02-08 16:00:16",
            "last_seen_utc": "2026-06-30 10:46:55",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/192.3.233.166",
            "tags": "AS-COLOCROSSING,AS36352,C2,censys,CobaltStrike,cs-watermark-666666666",
            "anonymous": "0",
            "reporter": "DonPasci"
        }
    ],
    "1743395": [
        {
            "ioc_value": "1.15.25.148:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-02-08 15:42:41",
            "last_seen_utc": "2026-06-30 11:21:39",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1743391": [
        {
            "ioc_value": "106.52.208.143:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-02-08 15:42:40",
            "last_seen_utc": "2026-06-30 11:21:38",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1743392": [
        {
            "ioc_value": "106.13.137.229:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-02-08 15:42:40",
            "last_seen_utc": "2026-06-30 11:21:38",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1743393": [
        {
            "ioc_value": "101.43.2.116:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-02-08 15:42:40",
            "last_seen_utc": "2026-06-30 11:21:39",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1743394": [
        {
            "ioc_value": "101.133.148.66:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-02-08 15:42:40",
            "last_seen_utc": "2026-06-30 11:21:39",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1743388": [
        {
            "ioc_value": "115.190.178.249:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-02-08 15:42:39",
            "last_seen_utc": "2026-06-30 11:21:37",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1743389": [
        {
            "ioc_value": "114.132.150.96:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-02-08 15:42:39",
            "last_seen_utc": "2026-06-30 11:21:37",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1743390": [
        {
            "ioc_value": "110.40.176.194:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-02-08 15:42:39",
            "last_seen_utc": "2026-06-30 11:21:38",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1743386": [
        {
            "ioc_value": "120.48.50.33:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-02-08 15:42:37",
            "last_seen_utc": "2026-06-30 11:21:35",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1743387": [
        {
            "ioc_value": "117.72.214.50:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-02-08 15:42:37",
            "last_seen_utc": "2026-06-30 11:21:36",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1743381": [
        {
            "ioc_value": "124.223.199.39:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-02-08 15:42:36",
            "last_seen_utc": "2026-06-30 11:21:34",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1743382": [
        {
            "ioc_value": "124.221.32.87:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-02-08 15:42:36",
            "last_seen_utc": "2026-06-30 11:21:35",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1743383": [
        {
            "ioc_value": "124.220.48.168:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-02-08 15:42:36",
            "last_seen_utc": "2026-06-30 11:21:35",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1743384": [
        {
            "ioc_value": "124.220.164.98:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-02-08 15:42:36",
            "last_seen_utc": "2026-06-30 11:21:35",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1743385": [
        {
            "ioc_value": "121.41.167.80:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-02-08 15:42:36",
            "last_seen_utc": "2026-06-30 11:21:35",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1743378": [
        {
            "ioc_value": "152.136.139.105:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-02-08 15:42:35",
            "last_seen_utc": "2026-06-30 11:21:34",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1743379": [
        {
            "ioc_value": "129.204.103.151:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-02-08 15:42:35",
            "last_seen_utc": "2026-06-30 11:21:34",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1743380": [
        {
            "ioc_value": "124.223.47.219:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-02-08 15:42:35",
            "last_seen_utc": "2026-06-30 11:21:34",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1743374": [
        {
            "ioc_value": "172.245.215.43:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-02-08 15:42:34",
            "last_seen_utc": "2026-06-30 11:21:32",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1743375": [
        {
            "ioc_value": "165.154.125.212:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-02-08 15:42:34",
            "last_seen_utc": "2026-06-30 11:21:33",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1743376": [
        {
            "ioc_value": "156.233.233.134:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-02-08 15:42:34",
            "last_seen_utc": "2026-06-30 11:21:33",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1743377": [
        {
            "ioc_value": "154.201.91.224:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-02-08 15:42:34",
            "last_seen_utc": "2026-06-30 11:21:33",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1743370": [
        {
            "ioc_value": "38.190.224.63:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-02-08 15:42:33",
            "last_seen_utc": "2026-06-30 11:21:31",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1743371": [
        {
            "ioc_value": "222.255.214.236:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-02-08 15:42:33",
            "last_seen_utc": "2026-06-30 11:21:31",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1743372": [
        {
            "ioc_value": "192.252.187.60:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-02-08 15:42:33",
            "last_seen_utc": "2026-06-30 11:21:32",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1743373": [
        {
            "ioc_value": "178.16.52.194:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-02-08 15:42:33",
            "last_seen_utc": "2026-06-30 11:21:32",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1743365": [
        {
            "ioc_value": "43.139.146.100:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-02-08 15:42:32",
            "last_seen_utc": "2026-06-30 11:21:30",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1743366": [
        {
            "ioc_value": "43.133.41.106:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-02-08 15:42:32",
            "last_seen_utc": "2026-06-30 11:21:31",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1743367": [
        {
            "ioc_value": "42.192.49.72:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-02-08 15:42:32",
            "last_seen_utc": "2026-06-30 11:21:31",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1743368": [
        {
            "ioc_value": "39.107.85.83:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-02-08 15:42:32",
            "last_seen_utc": "2026-06-30 11:21:31",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1743369": [
        {
            "ioc_value": "39.106.144.162:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-02-08 15:42:32",
            "last_seen_utc": "2026-06-30 11:21:31",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1743363": [
        {
            "ioc_value": "47.100.168.4:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-02-08 15:42:31",
            "last_seen_utc": "2026-06-30 11:21:30",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1743364": [
        {
            "ioc_value": "43.139.169.60:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-02-08 15:42:31",
            "last_seen_utc": "2026-06-30 11:21:30",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1743362": [
        {
            "ioc_value": "47.111.146.110:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-02-08 15:42:30",
            "last_seen_utc": "2026-06-30 11:21:29",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1743358": [
        {
            "ioc_value": "47.243.175.24:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-02-08 15:42:29",
            "last_seen_utc": "2026-06-30 11:21:27",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1743359": [
        {
            "ioc_value": "47.239.188.48:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-02-08 15:42:29",
            "last_seen_utc": "2026-06-30 11:21:27",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1743360": [
        {
            "ioc_value": "47.122.30.177:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-02-08 15:42:29",
            "last_seen_utc": "2026-06-30 11:21:28",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1743361": [
        {
            "ioc_value": "47.122.1.243:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-02-08 15:42:29",
            "last_seen_utc": "2026-06-30 11:21:28",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1743356": [
        {
            "ioc_value": "61.166.154.109:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-02-08 15:42:28",
            "last_seen_utc": "2026-06-30 11:21:26",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1743357": [
        {
            "ioc_value": "49.235.177.231:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-02-08 15:42:28",
            "last_seen_utc": "2026-06-30 11:21:27",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1743353": [
        {
            "ioc_value": "81.70.255.195:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-02-08 15:42:27",
            "last_seen_utc": "2026-06-30 11:21:25",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1743354": [
        {
            "ioc_value": "81.69.98.230:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-02-08 15:42:27",
            "last_seen_utc": "2026-06-30 11:21:26",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1743355": [
        {
            "ioc_value": "8.210.78.137:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-02-08 15:42:27",
            "last_seen_utc": "2026-06-30 11:21:26",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1743351": [
        {
            "ioc_value": "83.229.126.65:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-02-08 15:42:26",
            "last_seen_utc": "2026-06-30 11:21:25",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1743352": [
        {
            "ioc_value": "81.71.159.99:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-02-08 15:42:26",
            "last_seen_utc": "2026-06-30 11:21:25",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1743349": [
        {
            "ioc_value": "83.229.123.61:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-02-08 15:42:15",
            "last_seen_utc": "2026-06-30 11:21:13",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1743350": [
        {
            "ioc_value": "83.229.126.183:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-02-08 15:42:15",
            "last_seen_utc": "2026-06-30 11:21:13",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1743348": [
        {
            "ioc_value": "8.153.205.30:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-02-08 15:42:14",
            "last_seen_utc": "2026-06-30 11:21:26",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1743347": [
        {
            "ioc_value": "8.137.149.67:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-02-08 15:42:13",
            "last_seen_utc": "2026-06-30 11:21:12",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1743344": [
        {
            "ioc_value": "47.93.28.103:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-02-08 15:42:12",
            "last_seen_utc": "2026-06-30 11:21:27",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1743345": [
        {
            "ioc_value": "60.205.139.210:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-02-08 15:42:12",
            "last_seen_utc": "2026-06-30 11:21:11",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1743346": [
        {
            "ioc_value": "lcowpowerlite.italynorth.cloudapp.azure.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-02-08 15:42:12",
            "last_seen_utc": "2026-06-30 11:21:11",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1743340": [
        {
            "ioc_value": "47.109.198.8:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-02-08 15:42:11",
            "last_seen_utc": "2026-06-30 11:21:09",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1743341": [
        {
            "ioc_value": "47.120.70.161:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-02-08 15:42:11",
            "last_seen_utc": "2026-06-30 11:21:28",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1743342": [
        {
            "ioc_value": "47.121.137.8:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-02-08 15:42:11",
            "last_seen_utc": "2026-06-30 11:21:28",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1743343": [
        {
            "ioc_value": "47.121.29.60:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-02-08 15:42:11",
            "last_seen_utc": "2026-06-30 11:21:10",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1743336": [
        {
            "ioc_value": "45.115.236.152:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-02-08 15:42:10",
            "last_seen_utc": "2026-06-30 11:21:30",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1743338": [
        {
            "ioc_value": "47.107.136.106:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-02-08 15:42:10",
            "last_seen_utc": "2026-06-30 11:21:29",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1743339": [
        {
            "ioc_value": "47.109.145.121:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-02-08 15:42:10",
            "last_seen_utc": "2026-06-30 11:21:29",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1743333": [
        {
            "ioc_value": "192.140.176.79:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-02-08 15:42:09",
            "last_seen_utc": "2026-06-30 11:21:08",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1743334": [
        {
            "ioc_value": "36.140.162.173:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-02-08 15:42:09",
            "last_seen_utc": "2026-06-30 11:21:08",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1743335": [
        {
            "ioc_value": "39.105.165.37:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-02-08 15:42:09",
            "last_seen_utc": "2026-06-30 11:21:31",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1743330": [
        {
            "ioc_value": "152.32.251.78:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-02-08 15:42:08",
            "last_seen_utc": "2026-06-30 11:21:33",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1743331": [
        {
            "ioc_value": "154.201.74.112:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-02-08 15:42:08",
            "last_seen_utc": "2026-06-30 11:21:33",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1743332": [
        {
            "ioc_value": "179.43.186.214:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-02-08 15:42:08",
            "last_seen_utc": "2026-06-30 11:21:07",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1743326": [
        {
            "ioc_value": "139.196.41.201:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-02-08 15:42:07",
            "last_seen_utc": "2026-06-30 11:21:06",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1743327": [
        {
            "ioc_value": "139.224.16.185:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-02-08 15:42:07",
            "last_seen_utc": "2026-06-30 11:21:06",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1743328": [
        {
            "ioc_value": "14.103.175.50:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-02-08 15:42:07",
            "last_seen_utc": "2026-06-30 11:21:06",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1743329": [
        {
            "ioc_value": "150.187.25.242:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-02-08 15:42:07",
            "last_seen_utc": "2026-06-30 11:21:06",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1743322": [
        {
            "ioc_value": "120.48.168.57:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-02-08 15:42:06",
            "last_seen_utc": "2026-06-30 11:21:05",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1743323": [
        {
            "ioc_value": "121.40.18.128:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-02-08 15:42:06",
            "last_seen_utc": "2026-06-30 11:21:35",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1743324": [
        {
            "ioc_value": "122.51.93.94:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-02-08 15:42:06",
            "last_seen_utc": "2026-06-30 11:21:06",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1743325": [
        {
            "ioc_value": "134.122.140.185:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-02-08 15:42:06",
            "last_seen_utc": "2026-06-30 11:21:34",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1743320": [
        {
            "ioc_value": "117.72.102.110:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-02-08 15:42:05",
            "last_seen_utc": "2026-06-30 11:21:37",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1743321": [
        {
            "ioc_value": "117.72.242.9:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-02-08 15:42:05",
            "last_seen_utc": "2026-06-30 11:21:05",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1743318": [
        {
            "ioc_value": "113.44.67.52:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-02-08 15:42:04",
            "last_seen_utc": "2026-06-30 11:21:04",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1743319": [
        {
            "ioc_value": "115.190.161.178:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-02-08 15:42:04",
            "last_seen_utc": "2026-06-30 11:21:04",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1743314": [
        {
            "ioc_value": "106.38.201.95:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-02-08 15:42:03",
            "last_seen_utc": "2026-06-30 11:21:03",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1743315": [
        {
            "ioc_value": "106.75.162.108:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-02-08 15:42:03",
            "last_seen_utc": "2026-06-30 11:21:03",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1743316": [
        {
            "ioc_value": "106.75.215.96:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-02-08 15:42:03",
            "last_seen_utc": "2026-06-30 11:21:38",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1743317": [
        {
            "ioc_value": "106.75.224.31:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-02-08 15:42:03",
            "last_seen_utc": "2026-06-30 11:21:38",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1743312": [
        {
            "ioc_value": "106.12.219.245:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-02-08 15:42:02",
            "last_seen_utc": "2026-06-30 11:21:02",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1743313": [
        {
            "ioc_value": "106.13.29.104:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-02-08 15:42:02",
            "last_seen_utc": "2026-06-30 11:21:02",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1743267": [
        {
            "ioc_value": "15.204.14.143:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.havoc",
            "malware_alias": "Havokiz",
            "malware_printable": "Havoc",
            "first_seen_utc": "2026-02-08 11:00:25",
            "last_seen_utc": "2026-06-30 10:43:31",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/15.204.14.143",
            "tags": "AS16276,C2,censys,OVH",
            "anonymous": "0",
            "reporter": "dyingbreeds_"
        }
    ],
    "1743209": [
        {
            "ioc_value": "15.204.95.228:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.havoc",
            "malware_alias": "Havokiz",
            "malware_printable": "Havoc",
            "first_seen_utc": "2026-02-08 04:00:55",
            "last_seen_utc": "2026-06-30 10:43:31",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/15.204.95.228",
            "tags": "AS16276,C2,censys,Havoc,OVH",
            "anonymous": "0",
            "reporter": "DonPasci"
        }
    ],
    "1742595": [
        {
            "ioc_value": "174.138.86.141:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-02-07 03:00:18",
            "last_seen_utc": "2026-06-30 10:43:51",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/174.138.86.141",
            "tags": "AS14061,C2,censys,Mythic",
            "anonymous": "0",
            "reporter": "dyingbreeds_"
        }
    ],
    "1741587": [
        {
            "ioc_value": "57.158.27.132:31337",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.sliver",
            "malware_alias": null,
            "malware_printable": "Sliver",
            "first_seen_utc": "2026-02-05 13:01:59",
            "last_seen_utc": "2026-06-30 10:45:56",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": "https://www.shodan.io/host/57.158.27.132#31337",
            "tags": "c2,shodan,sliver",
            "anonymous": "0",
            "reporter": "juroots"
        }
    ],
    "1741476": [
        {
            "ioc_value": "94.74.0.253:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-02-05 11:00:23",
            "last_seen_utc": "2026-06-30 10:46:18",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/94.74.0.253",
            "tags": "AS39636,ASN-AEMNET,C2,censys,Mythic",
            "anonymous": "0",
            "reporter": "dyingbreeds_"
        }
    ],
    "1741375": [
        {
            "ioc_value": "37.72.172.58:6066",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-02-05 06:34:37",
            "last_seen_utc": "2026-06-30 10:45:28",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "",
            "tags": "AS29802,asyncrat,c2,fofa,RAT",
            "anonymous": "0",
            "reporter": "oxygen28"
        }
    ],
    "1741132": [
        {
            "ioc_value": "172.174.234.34:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-02-04 11:00:54",
            "last_seen_utc": "2026-06-30 10:43:47",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/172.174.234.34",
            "tags": "AS8075,C2,censys,Mythic",
            "anonymous": "0",
            "reporter": "dyingbreeds_"
        }
    ],
    "1740953": [
        {
            "ioc_value": "188.166.244.201:4321",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-02-04 00:02:27",
            "last_seen_utc": "2026-06-30 10:44:11",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/188.166.244.201",
            "tags": "AdaptixC2,AS14061,C2,censys,DIGITALOCEAN-ASN",
            "anonymous": "0",
            "reporter": "DonPasci"
        }
    ],
    "1739255": [
        {
            "ioc_value": "98.85.71.175:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-01-31 00:05:33",
            "last_seen_utc": "2026-06-30 10:46:20",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/98.85.71.175",
            "tags": "AMAZON-AES,AS14618,C2,censys,Mythic",
            "anonymous": "0",
            "reporter": "DonPasci"
        }
    ],
    "1739209": [
        {
            "ioc_value": "47.115.193.52:4506",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.deimos_c2",
            "malware_alias": null,
            "malware_printable": "DeimosC2",
            "first_seen_utc": "2026-01-30 18:54:11",
            "last_seen_utc": "2026-06-30 10:45:46",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "Deimos,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1739169": [
        {
            "ioc_value": "167.99.208.145:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-01-30 16:05:29",
            "last_seen_utc": "2026-06-30 10:43:45",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/167.99.208.145",
            "tags": "AS14061,C2,censys,DIGITALOCEAN-ASN,Mythic",
            "anonymous": "0",
            "reporter": "DonPasci"
        }
    ],
    "1739163": [
        {
            "ioc_value": "107.150.105.91:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-01-30 16:04:48",
            "last_seen_utc": "2026-06-30 11:21:03",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/107.150.105.91",
            "tags": "AS135377,C2,censys,CobaltStrike,cs-watermark-666666666,UCLOUD-HK-AS-AP",
            "anonymous": "0",
            "reporter": "DonPasci"
        }
    ],
    "1739009": [
        {
            "ioc_value": "111.92.243.40:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-01-30 08:04:49",
            "last_seen_utc": "2026-06-30 11:21:04",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/111.92.243.40",
            "tags": "AS401696,C2,censys,CobaltStrike,COGNETCLOUD,cs-watermark-666666666",
            "anonymous": "0",
            "reporter": "DonPasci"
        }
    ],
    "1738921": [
        {
            "ioc_value": "45.82.85.50:13063",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.ransomhub",
            "malware_alias": null,
            "malware_printable": "RansomHub",
            "first_seen_utc": "2026-01-30 02:55:25",
            "last_seen_utc": "2026-06-30 10:45:43",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RansomHub",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1738909": [
        {
            "ioc_value": "68.64.178.201:54321",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-01-30 00:06:02",
            "last_seen_utc": "2026-06-30 10:46:03",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/68.64.178.201",
            "tags": "AdaptixC2,AS139659,C2,censys,LUCID-AS-AP",
            "anonymous": "0",
            "reporter": "DonPasci"
        }
    ],
    "1738481": [
        {
            "ioc_value": "39.101.78.48:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-01-28 11:00:07",
            "last_seen_utc": "2026-06-30 10:47:00",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/39.101.78.48",
            "tags": "AS37963,C2,censys",
            "anonymous": "0",
            "reporter": "dyingbreeds_"
        }
    ],
    "1737790": [
        {
            "ioc_value": "47.120.46.230:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-01-26 23:00:09",
            "last_seen_utc": "2026-06-30 11:21:10",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/47.120.46.230",
            "tags": "AS37963,C2,censys",
            "anonymous": "0",
            "reporter": "dyingbreeds_"
        }
    ],
    "1737664": [
        {
            "ioc_value": "https://fluraresto.me/live/",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.latrodectus",
            "malware_alias": "BLACKWIDOW,IceNova,Latrodectus,Lotus",
            "malware_printable": "Latrodectus",
            "first_seen_utc": "2026-01-26 13:57:13",
            "last_seen_utc": "2026-06-30 11:06:59",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "c2,Latrodectus",
            "anonymous": "0",
            "reporter": "Bitsight"
        }
    ],
    "1737665": [
        {
            "ioc_value": "https://mastralakkot.live/live/",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.latrodectus",
            "malware_alias": "BLACKWIDOW,IceNova,Latrodectus,Lotus",
            "malware_printable": "Latrodectus",
            "first_seen_utc": "2026-01-26 13:57:13",
            "last_seen_utc": "2026-06-30 11:16:01",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "c2,Latrodectus",
            "anonymous": "0",
            "reporter": "Bitsight"
        }
    ],
    "1737569": [
        {
            "ioc_value": "27.223.85.234:58001",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-01-26 08:05:39",
            "last_seen_utc": "2026-06-30 10:45:22",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/27.223.85.234",
            "tags": "AdaptixC2,AS4837,C2,censys,CHINA169-BACKBONE",
            "anonymous": "0",
            "reporter": "DonPasci"
        }
    ],
    "1737455": [
        {
            "ioc_value": "167.179.76.179:53",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-01-25 22:49:35",
            "last_seen_utc": "2026-06-30 10:46:51",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1737454": [
        {
            "ioc_value": "ns1.ns-apache.jo3.org",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-01-25 22:48:35",
            "last_seen_utc": "2026-06-30 10:46:26",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1736696": [
        {
            "ioc_value": "80.87.206.64:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.rhysida",
            "malware_alias": null,
            "malware_printable": "Rhysida",
            "first_seen_utc": "2026-01-24 18:47:55",
            "last_seen_utc": "2026-06-30 10:46:08",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Rhysida",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1736697": [
        {
            "ioc_value": "80.87.206.64:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.rhysida",
            "malware_alias": null,
            "malware_printable": "Rhysida",
            "first_seen_utc": "2026-01-24 18:47:55",
            "last_seen_utc": "2026-06-30 10:46:08",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Rhysida",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1736055": [
        {
            "ioc_value": "lat.sodstreams.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-01-23 09:14:44",
            "last_seen_utc": "2026-06-30 11:13:35",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "Vidar",
            "anonymous": "0",
            "reporter": "crep1x"
        }
    ],
    "1736049": [
        {
            "ioc_value": "https://lat.sodstreams.com/",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-01-23 09:14:26",
            "last_seen_utc": "2026-06-30 11:13:34",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "Vidar",
            "anonymous": "0",
            "reporter": "crep1x"
        }
    ],
    "1736034": [
        {
            "ioc_value": "158.158.8.193:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.bianlian",
            "malware_alias": null,
            "malware_printable": "BianLian",
            "first_seen_utc": "2026-01-23 08:45:57",
            "last_seen_utc": "2026-06-30 10:43:39",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "Bianlian,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1736014": [
        {
            "ioc_value": "47.120.32.72:8075",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-01-23 08:04:06",
            "last_seen_utc": "2026-06-30 10:47:09",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/47.120.32.72",
            "tags": "ALIBABA-CN-NET,AS37963,C2,censys,CobaltStrike,cs-watermark-666666666",
            "anonymous": "0",
            "reporter": "DonPasci"
        }
    ],
    "1735522": [
        {
            "ioc_value": "176.31.71.168:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pupy",
            "malware_alias": "Patpoopy",
            "malware_printable": "pupy",
            "first_seen_utc": "2026-01-22 12:04:28",
            "last_seen_utc": "2026-06-30 10:43:52",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/176.31.71.168",
            "tags": "AS16276,C2,censys,OVH,Pupy,RAT",
            "anonymous": "0",
            "reporter": "DonPasci"
        }
    ],
    "1735342": [
        {
            "ioc_value": "54.145.56.188:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-01-21 20:04:36",
            "last_seen_utc": "2026-06-30 10:45:55",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/54.145.56.188",
            "tags": "AMAZON-AES,AS14618,C2,censys,Mythic",
            "anonymous": "0",
            "reporter": "DonPasci"
        }
    ],
    "1735337": [
        {
            "ioc_value": "121.4.92.72:5000",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-01-21 20:03:53",
            "last_seen_utc": "2026-06-30 10:46:41",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/121.4.92.72",
            "tags": "AS45090,C2,censys,CobaltStrike,cs-watermark-987654321,TENCENT-NET-AP",
            "anonymous": "0",
            "reporter": "DonPasci"
        }
    ],
    "1734893": [
        {
            "ioc_value": "136.24.173.249:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-01-20 16:04:24",
            "last_seen_utc": "2026-06-30 10:43:22",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/136.24.173.249",
            "tags": "AS19165,C2,censys,Mythic,WEBPASS",
            "anonymous": "0",
            "reporter": "DonPasci"
        }
    ],
    "1734081": [
        {
            "ioc_value": "103.79.79.105:8444",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pupy",
            "malware_alias": "Patpoopy",
            "malware_printable": "pupy",
            "first_seen_utc": "2026-01-18 00:03:59",
            "last_seen_utc": "2026-06-30 10:43:10",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/103.79.79.105",
            "tags": "AS199959,C2,censys,CROWNCLOUD,Pupy,RAT",
            "anonymous": "0",
            "reporter": "DonPasci"
        }
    ],
    "1734053": [
        {
            "ioc_value": "43.139.50.42:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-01-17 20:52:32",
            "last_seen_utc": "2026-06-30 10:47:03",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1733763": [
        {
            "ioc_value": "113.250.188.15:8078",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-01-17 11:00:10",
            "last_seen_utc": "2026-06-30 10:46:35",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/113.250.188.15",
            "tags": "AS134420,C2,censys",
            "anonymous": "0",
            "reporter": "dyingbreeds_"
        }
    ],
    "1733589": [
        {
            "ioc_value": "poc.sekershuk.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-01-16 15:03:06",
            "last_seen_utc": "2026-06-30 11:12:04",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "Vidar",
            "anonymous": "0",
            "reporter": "crep1x"
        }
    ],
    "1733587": [
        {
            "ioc_value": "https://poc.sekershuk.com/",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-01-16 15:02:50",
            "last_seen_utc": "2026-06-30 11:12:04",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "Vidar",
            "anonymous": "0",
            "reporter": "crep1x"
        }
    ],
    "1732736": [
        {
            "ioc_value": "64.23.231.32:31337",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.sliver",
            "malware_alias": null,
            "malware_printable": "Sliver",
            "first_seen_utc": "2026-01-16 11:05:53",
            "last_seen_utc": "2026-06-30 10:45:59",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": "https://www.shodan.io/host/64.23.231.32#31337",
            "tags": "c2,shodan,sliver",
            "anonymous": "0",
            "reporter": "juroots"
        }
    ],
    "1732709": [
        {
            "ioc_value": "117.72.178.246:4848",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-01-16 11:03:46",
            "last_seen_utc": "2026-06-30 10:46:38",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": "https://www.shodan.io/host/117.72.178.246#4848",
            "tags": "c2,cobaltstrike,cs-watermark-987654321,shodan",
            "anonymous": "0",
            "reporter": "juroots"
        }
    ],
    "1732012": [
        {
            "ioc_value": "212.103.26.10:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.havoc",
            "malware_alias": "Havokiz",
            "malware_printable": "Havoc",
            "first_seen_utc": "2026-01-13 20:03:58",
            "last_seen_utc": "2026-06-30 10:44:35",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/212.103.26.10",
            "tags": "AS15557,C2,censys,Havoc,LDCOMNET",
            "anonymous": "0",
            "reporter": "DonPasci"
        }
    ],
    "1732009": [
        {
            "ioc_value": "47.84.83.56:8443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.sliver",
            "malware_alias": null,
            "malware_printable": "Sliver",
            "first_seen_utc": "2026-01-13 20:03:34",
            "last_seen_utc": "2026-06-30 10:45:47",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/47.84.83.56",
            "tags": "ALIBABA-CN-NET,AS45102,C2,censys,Sliver",
            "anonymous": "0",
            "reporter": "DonPasci"
        }
    ],
    "1731532": [
        {
            "ioc_value": "54.38.94.225:8881",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.eye_pyramid",
            "malware_alias": null,
            "malware_printable": "Eye Pyramid",
            "first_seen_utc": "2026-01-13 08:52:00",
            "last_seen_utc": "2026-06-30 10:45:55",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,EyePyramid",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1701407": [
        {
            "ioc_value": "64.23.248.252:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.havoc",
            "malware_alias": "Havokiz",
            "malware_printable": "Havoc",
            "first_seen_utc": "2026-01-12 23:00:32",
            "last_seen_utc": "2026-06-30 10:45:59",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/64.23.248.252",
            "tags": "AS14061,C2,censys,DIGITALOCEAN-ASN",
            "anonymous": "0",
            "reporter": "dyingbreeds_"
        }
    ],
    "1701312": [
        {
            "ioc_value": "130.12.181.93:2404",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-01-12 16:03:19",
            "last_seen_utc": "2026-06-30 10:43:21",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/130.12.181.93",
            "tags": "AS36680,C2,censys,NETIFACELLC,RAT,Remcos",
            "anonymous": "0",
            "reporter": "DonPasci"
        }
    ],
    "1700191": [
        {
            "ioc_value": "115.190.237.175:35555",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-01-09 20:02:46",
            "last_seen_utc": "2026-06-30 10:46:36",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/115.190.237.175",
            "tags": "AS137718,C2,censys,CobaltStrike,cs-watermark-666666666,VOLCANO-ENGINE",
            "anonymous": "0",
            "reporter": "DonPasci"
        }
    ],
    "1693493": [
        {
            "ioc_value": "137.184.93.131:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-01-09 11:01:05",
            "last_seen_utc": "2026-06-30 10:43:22",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/137.184.93.131",
            "tags": "AS14061,C2,censys,DIGITALOCEAN-ASN,Mythic",
            "anonymous": "0",
            "reporter": "dyingbreeds_"
        }
    ],
    "1693407": [
        {
            "ioc_value": "8.148.184.136:8880",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-01-09 04:02:43",
            "last_seen_utc": "2026-06-28 12:46:30",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/8.148.184.136",
            "tags": "ALIBABA-CN-NET,AS37963,C2,censys,CobaltStrike,cs-watermark-666666666",
            "anonymous": "0",
            "reporter": "DonPasci"
        }
    ],
    "1693365": [
        {
            "ioc_value": "117.72.178.246:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-01-08 23:00:12",
            "last_seen_utc": "2026-06-30 11:21:05",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/117.72.178.246",
            "tags": "AS141679,C2,censys",
            "anonymous": "0",
            "reporter": "dyingbreeds_"
        }
    ],
    "1693357": [
        {
            "ioc_value": "172.94.18.103:191",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-01-08 22:50:04",
            "last_seen_utc": "2026-06-30 10:43:50",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,RAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1692743": [
        {
            "ioc_value": "38.49.57.15:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-01-07 20:02:36",
            "last_seen_utc": "2026-06-30 11:21:08",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/38.49.57.15",
            "tags": "AS8796,C2,censys,CobaltStrike,cs-watermark-666666666,FD-298-8796",
            "anonymous": "0",
            "reporter": "DonPasci"
        }
    ],
    "1691952": [
        {
            "ioc_value": "115.190.233.79:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-01-06 08:02:23",
            "last_seen_utc": "2026-06-30 11:21:04",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/115.190.233.79",
            "tags": "AS137718,C2,censys,CobaltStrike,cs-watermark-987654321,VOLCANO-ENGINE",
            "anonymous": "0",
            "reporter": "DonPasci"
        }
    ],
    "1691605": [
        {
            "ioc_value": "http://213.5.130.122",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-01-05 13:21:42",
            "last_seen_utc": "2026-06-30 06:01:36",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "c2,REMPROXY",
            "anonymous": "0",
            "reporter": "BlackLotusLabs"
        }
    ],
    "1691603": [
        {
            "ioc_value": "http://213.5.130.151",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-01-05 13:21:41",
            "last_seen_utc": "2026-06-30 06:01:35",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "c2,REMPROXY",
            "anonymous": "0",
            "reporter": "BlackLotusLabs"
        }
    ],
    "1691604": [
        {
            "ioc_value": "http://213.5.130.124",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-01-05 13:21:40",
            "last_seen_utc": "2026-06-30 06:01:36",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "c2,REMPROXY",
            "anonymous": "0",
            "reporter": "BlackLotusLabs"
        }
    ],
    "1691606": [
        {
            "ioc_value": "http://213.5.130.187",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-01-05 13:21:40",
            "last_seen_utc": "2026-06-30 06:01:35",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "c2,REMPROXY",
            "anonymous": "0",
            "reporter": "BlackLotusLabs"
        }
    ],
    "1691547": [
        {
            "ioc_value": "ptn.passadisco.com.br",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-01-05 10:07:28",
            "last_seen_utc": "2026-06-30 11:11:52",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "Vidar",
            "anonymous": "0",
            "reporter": "crep1x"
        }
    ],
    "1691488": [
        {
            "ioc_value": "https://ptn.passadisco.com.br/",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-01-05 10:06:50",
            "last_seen_utc": "2026-06-30 11:11:51",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "Vidar",
            "anonymous": "0",
            "reporter": "crep1x"
        }
    ],
    "1689290": [
        {
            "ioc_value": "182.92.117.223:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-01-01 07:01:03",
            "last_seen_utc": "2026-06-30 09:54:10",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-987654321",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1688739": [
        {
            "ioc_value": "101.34.205.214:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-12-30 16:21:16",
            "last_seen_utc": "2026-06-30 11:21:24",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1688738": [
        {
            "ioc_value": "103.171.35.66:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-12-30 16:21:15",
            "last_seen_utc": "2026-06-30 11:21:24",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1688737": [
        {
            "ioc_value": "107.149.192.54:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-12-30 16:21:14",
            "last_seen_utc": "2026-06-30 11:21:23",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1688734": [
        {
            "ioc_value": "124.222.218.20:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-12-30 16:21:13",
            "last_seen_utc": "2026-06-30 11:21:22",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1688735": [
        {
            "ioc_value": "124.221.255.78:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-12-30 16:21:13",
            "last_seen_utc": "2026-06-30 11:21:22",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1688736": [
        {
            "ioc_value": "123.56.78.220:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-12-30 16:21:13",
            "last_seen_utc": "2026-06-30 11:21:22",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1688732": [
        {
            "ioc_value": "152.32.202.240:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-12-30 16:21:12",
            "last_seen_utc": "2026-06-30 11:21:21",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1688733": [
        {
            "ioc_value": "150.158.119.242:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-12-30 16:21:12",
            "last_seen_utc": "2026-06-30 11:21:21",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1688730": [
        {
            "ioc_value": "165.154.244.73:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-12-30 16:21:11",
            "last_seen_utc": "2026-06-30 11:21:20",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1688731": [
        {
            "ioc_value": "156.225.20.77:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-12-30 16:21:11",
            "last_seen_utc": "2026-06-30 11:21:21",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1688729": [
        {
            "ioc_value": "182.92.239.94:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-12-30 16:21:10",
            "last_seen_utc": "2026-06-30 11:21:19",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1688726": [
        {
            "ioc_value": "39.105.160.175:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-12-30 16:21:08",
            "last_seen_utc": "2026-06-30 11:21:18",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1688727": [
        {
            "ioc_value": "38.38.250.99:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-12-30 16:21:08",
            "last_seen_utc": "2026-06-30 11:21:18",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1688728": [
        {
            "ioc_value": "211.184.175.246:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-12-30 16:21:08",
            "last_seen_utc": "2026-06-30 11:21:18",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1688725": [
        {
            "ioc_value": "45.58.56.34:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-12-30 16:21:07",
            "last_seen_utc": "2026-06-30 11:21:30",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1688723": [
        {
            "ioc_value": "8.130.80.145:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-12-30 16:21:05",
            "last_seen_utc": "2026-06-30 11:21:15",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1688724": [
        {
            "ioc_value": "8.130.26.216:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-12-30 16:21:05",
            "last_seen_utc": "2026-06-30 11:21:15",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1688721": [
        {
            "ioc_value": "94.74.164.177:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-12-30 16:21:03",
            "last_seen_utc": "2026-06-30 11:21:14",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1688722": [
        {
            "ioc_value": "87.251.67.85:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-12-30 16:21:03",
            "last_seen_utc": "2026-06-30 11:21:14",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1688694": [
        {
            "ioc_value": "16.171.13.191:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2025-12-30 16:04:05",
            "last_seen_utc": "2026-06-30 10:43:40",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/16.171.13.191",
            "tags": "AMAZON-02,AS16509,C2,censys,Covenant",
            "anonymous": "0",
            "reporter": "DonPasci"
        }
    ],
    "1687817": [
        {
            "ioc_value": "118.89.88.183:56781",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-12-28 20:01:34",
            "last_seen_utc": "2026-06-30 10:46:40",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/118.89.88.183",
            "tags": "AS45090,C2,censys,CobaltStrike,cs-watermark-987654321,TENCENT-NET-AP",
            "anonymous": "0",
            "reporter": "DonPasci"
        }
    ],
    "1687807": [
        {
            "ioc_value": "163.181.213.114:4506",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.deimos_c2",
            "malware_alias": null,
            "malware_printable": "DeimosC2",
            "first_seen_utc": "2025-12-28 18:44:20",
            "last_seen_utc": "2026-06-30 10:43:43",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "Deimos,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1687327": [
        {
            "ioc_value": "37.72.172.58:8088",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2025-12-28 07:41:32",
            "last_seen_utc": "2026-06-30 10:45:28",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/37.72.172.58",
            "tags": "AS29802,C2,censys,HVC-AS,RAT",
            "anonymous": "0",
            "reporter": "dyingbreeds_"
        }
    ],
    "1687170": [
        {
            "ioc_value": "37.72.172.58:8808",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2025-12-27 16:02:33",
            "last_seen_utc": "2026-06-30 10:45:28",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/37.72.172.58",
            "tags": "AS29802,AsyncRAT,C2,censys,HVC-AS,RAT",
            "anonymous": "0",
            "reporter": "DonPasci"
        }
    ],
    "1686405": [
        {
            "ioc_value": "155.102.62.60:4506",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.deimos_c2",
            "malware_alias": null,
            "malware_printable": "DeimosC2",
            "first_seen_utc": "2025-12-25 18:44:15",
            "last_seen_utc": "2026-06-30 10:43:34",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "Deimos,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1686010": [
        {
            "ioc_value": "139.196.223.82:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-12-25 07:52:31",
            "last_seen_utc": "2026-06-30 11:21:06",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/139.196.223.82",
            "tags": "AS37963,C2,censys",
            "anonymous": "0",
            "reporter": "dyingbreeds_"
        }
    ],
    "1685856": [
        {
            "ioc_value": "helpremote.cc",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-12-24 12:48:51",
            "last_seen_utc": "2026-06-30 11:21:13",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1685596": [
        {
            "ioc_value": "172.94.18.103:190",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2025-12-23 22:45:05",
            "last_seen_utc": "2026-06-30 10:43:50",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,RAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1685256": [
        {
            "ioc_value": "115.190.160.206:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-12-23 20:01:06",
            "last_seen_utc": "2026-06-30 11:21:04",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/115.190.160.206",
            "tags": "AS137718,C2,censys,CobaltStrike,cs-watermark-987654321,VOLCANO-ENGINE",
            "anonymous": "0",
            "reporter": "DonPasci"
        }
    ],
    "1685210": [
        {
            "ioc_value": "196.251.107.104:7707",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2025-12-23 18:07:43",
            "last_seen_utc": "2026-06-30 10:44:21",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://tria.ge/251223-qezczazpcx",
            "tags": "AS9304,asyncrat,C2,rat,triage",
            "anonymous": "0",
            "reporter": "DonPasci"
        }
    ],
    "1685209": [
        {
            "ioc_value": "196.251.107.104:6606",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2025-12-23 18:07:42",
            "last_seen_utc": "2026-06-30 10:44:21",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://tria.ge/251223-qezczazpcx",
            "tags": "AS9304,asyncrat,C2,rat,triage",
            "anonymous": "0",
            "reporter": "DonPasci"
        }
    ],
    "1684938": [
        {
            "ioc_value": "8.159.146.72:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-12-23 03:00:34",
            "last_seen_utc": "2026-06-30 11:21:13",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1684936": [
        {
            "ioc_value": "missmovie.lol",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-12-23 02:54:49",
            "last_seen_utc": "2026-06-30 10:46:24",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1684826": [
        {
            "ioc_value": "179.43.186.214:7889",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-12-22 20:01:00",
            "last_seen_utc": "2026-06-30 10:46:53",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/179.43.186.214",
            "tags": "AS51852,C2,censys,CobaltStrike,cs-watermark-987654321,PLI-AS",
            "anonymous": "0",
            "reporter": "DonPasci"
        }
    ],
    "1684794": [
        {
            "ioc_value": "45.133.180.162:8848",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2025-12-22 18:02:02",
            "last_seen_utc": "2026-06-30 10:45:35",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://tria.ge/251222-d45vtstqc1",
            "tags": "AS9009,asyncrat,C2,rat,triage",
            "anonymous": "0",
            "reporter": "DonPasci"
        }
    ],
    "1684543": [
        {
            "ioc_value": "64.190.113.161:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pupy",
            "malware_alias": "Patpoopy",
            "malware_printable": "pupy",
            "first_seen_utc": "2025-12-22 00:01:20",
            "last_seen_utc": "2026-06-30 10:45:58",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/64.190.113.161",
            "tags": "AS399629,BLNWX,C2,censys,Pupy,RAT",
            "anonymous": "0",
            "reporter": "DonPasci"
        }
    ],
    "1682522": [
        {
            "ioc_value": "155.102.133.61:4506",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.deimos_c2",
            "malware_alias": null,
            "malware_printable": "DeimosC2",
            "first_seen_utc": "2025-12-18 18:44:36",
            "last_seen_utc": "2026-06-30 10:43:34",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "Deimos,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1681218": [
        {
            "ioc_value": "36.140.162.173:4433",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-12-17 04:00:34",
            "last_seen_utc": "2026-06-30 10:46:59",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/36.140.162.173",
            "tags": "AS9808,C2,censys,CHINAMOBILE-CN,CobaltStrike,cs-watermark-1234567890",
            "anonymous": "0",
            "reporter": "DonPasci"
        }
    ],
    "1680306": [
        {
            "ioc_value": "43.161.245.186:79",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-12-16 02:49:55",
            "last_seen_utc": "2026-06-30 10:47:04",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1676363": [
        {
            "ioc_value": "67.219.102.244:53",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-12-12 02:50:28",
            "last_seen_utc": "2026-06-30 10:47:14",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1674643": [
        {
            "ioc_value": "159.75.75.5:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-12-11 02:49:26",
            "last_seen_utc": "2026-06-30 10:46:50",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1673804": [
        {
            "ioc_value": "47.246.29.99:4506",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.deimos_c2",
            "malware_alias": null,
            "malware_printable": "DeimosC2",
            "first_seen_utc": "2025-12-09 18:49:53",
            "last_seen_utc": "2026-06-30 10:45:47",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "Deimos,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1670887": [
        {
            "ioc_value": "20.157.116.151:8000",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2025-12-08 14:58:40",
            "last_seen_utc": "2026-06-30 10:44:27",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/20.157.116.151",
            "tags": "AdaptixC2,AS8069,C2,censys,MICROSOFT-CORP-MSN-AS-BLOCK",
            "anonymous": "0",
            "reporter": "DonPasci"
        }
    ],
    "1668967": [
        {
            "ioc_value": "180.76.141.175:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-12-07 16:01:37",
            "last_seen_utc": "2026-06-30 11:21:08",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/180.76.141.175",
            "tags": "AS38365,BAIDU,C2,censys,CobaltStrike,cs-watermark-391144938",
            "anonymous": "0",
            "reporter": "DonPasci"
        }
    ],
    "1667182": [
        {
            "ioc_value": "216.238.89.173:4321",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2025-12-04 00:03:19",
            "last_seen_utc": "2026-06-30 10:45:17",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/216.238.89.173",
            "tags": "AdaptixC2,AS-VULTR,AS20473,C2,censys",
            "anonymous": "0",
            "reporter": "DonPasci"
        }
    ],
    "1667105": [
        {
            "ioc_value": "115.190.161.178:1234",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-12-03 20:01:15",
            "last_seen_utc": "2026-06-30 10:46:36",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/115.190.161.178",
            "tags": "AS137718,C2,censys,CobaltStrike,cs-watermark-987654321,VOLCANO-ENGINE",
            "anonymous": "0",
            "reporter": "DonPasci"
        }
    ],
    "1666902": [
        {
            "ioc_value": "122.114.10.199:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.sliver",
            "malware_alias": null,
            "malware_printable": "Sliver",
            "first_seen_utc": "2025-12-03 12:31:15",
            "last_seen_utc": "2026-06-30 10:43:19",
            "confidence_level": 90,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/122.114.10.199",
            "tags": "AS4837,C2,censys",
            "anonymous": "0",
            "reporter": "dyingbreeds_"
        }
    ],
    "1666137": [
        {
            "ioc_value": "8.137.149.67:8091",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-12-02 12:51:03",
            "last_seen_utc": "2026-06-30 10:47:16",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1665523": [
        {
            "ioc_value": "http://213.5.130.104",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2025-12-01 14:57:52",
            "last_seen_utc": "2026-06-30 06:01:34",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "c2,REMPROXY",
            "anonymous": "0",
            "reporter": "BlackLotusLabs"
        }
    ],
    "1665524": [
        {
            "ioc_value": "http://213.5.130.180",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2025-12-01 14:57:52",
            "last_seen_utc": "2026-06-30 06:01:34",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "c2,REMPROXY",
            "anonymous": "0",
            "reporter": "BlackLotusLabs"
        }
    ],
    "1665525": [
        {
            "ioc_value": "http://213.5.130.106",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2025-12-01 14:57:50",
            "last_seen_utc": "2026-06-30 06:01:34",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "c2,REMPROXY",
            "anonymous": "0",
            "reporter": "BlackLotusLabs"
        }
    ],
    "1665526": [
        {
            "ioc_value": "http://213.5.130.102",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2025-12-01 14:57:49",
            "last_seen_utc": "2026-06-30 06:01:33",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "c2,REMPROXY",
            "anonymous": "0",
            "reporter": "BlackLotusLabs"
        }
    ],
    "1665527": [
        {
            "ioc_value": "http://213.5.130.152",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2025-12-01 14:57:49",
            "last_seen_utc": "2026-06-30 06:01:34",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "c2,REMPROXY",
            "anonymous": "0",
            "reporter": "BlackLotusLabs"
        }
    ],
    "1665528": [
        {
            "ioc_value": "http://213.5.130.107",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2025-12-01 14:57:49",
            "last_seen_utc": "2026-06-30 06:01:33",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "c2,REMPROXY",
            "anonymous": "0",
            "reporter": "BlackLotusLabs"
        }
    ],
    "1665529": [
        {
            "ioc_value": "http://213.5.130.153",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2025-12-01 14:57:49",
            "last_seen_utc": "2026-06-30 06:01:34",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "c2,REMPROXY",
            "anonymous": "0",
            "reporter": "BlackLotusLabs"
        }
    ],
    "1665530": [
        {
            "ioc_value": "http://213.5.130.100",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2025-12-01 14:57:48",
            "last_seen_utc": "2026-06-30 06:01:33",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "c2,REMPROXY",
            "anonymous": "0",
            "reporter": "BlackLotusLabs"
        }
    ],
    "1665531": [
        {
            "ioc_value": "http://213.5.130.182",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2025-12-01 14:57:48",
            "last_seen_utc": "2026-06-30 06:01:36",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "c2,REMPROXY",
            "anonymous": "0",
            "reporter": "BlackLotusLabs"
        }
    ],
    "1665532": [
        {
            "ioc_value": "http://213.5.130.181",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2025-12-01 14:57:47",
            "last_seen_utc": "2026-06-30 06:01:35",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "c2,REMPROXY",
            "anonymous": "0",
            "reporter": "BlackLotusLabs"
        }
    ],
    "1665454": [
        {
            "ioc_value": "122.114.10.199:8001",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.sliver",
            "malware_alias": null,
            "malware_printable": "Sliver",
            "first_seen_utc": "2025-12-01 12:36:20",
            "last_seen_utc": "2026-06-30 10:43:19",
            "confidence_level": 90,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/122.114.10.199",
            "tags": "AS4837,C2,censys",
            "anonymous": "0",
            "reporter": "dyingbreeds_"
        }
    ],
    "1665331": [
        {
            "ioc_value": "47.84.83.56:31337",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.sliver",
            "malware_alias": null,
            "malware_printable": "Sliver",
            "first_seen_utc": "2025-12-01 06:57:39",
            "last_seen_utc": "2026-06-30 10:45:47",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": "https://www.shodan.io/host/47.84.83.56#31337",
            "tags": "c2,shodan,sliver",
            "anonymous": "0",
            "reporter": "juroots"
        }
    ],
    "1663611": [
        {
            "ioc_value": "103.110.65.166:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.sliver",
            "malware_alias": null,
            "malware_printable": "Sliver",
            "first_seen_utc": "2025-11-30 20:01:55",
            "last_seen_utc": "2026-06-30 10:43:08",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/103.110.65.166",
            "tags": "AS26383,ASNET,C2,censys,Sliver",
            "anonymous": "0",
            "reporter": "DonPasci"
        }
    ],
    "1663223": [
        {
            "ioc_value": "106.13.29.104:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-11-29 20:00:50",
            "last_seen_utc": "2026-06-30 10:46:32",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/106.13.29.104",
            "tags": "AS38365,BAIDU,C2,censys,CobaltStrike,cs-watermark-987654321",
            "anonymous": "0",
            "reporter": "DonPasci"
        }
    ],
    "1663012": [
        {
            "ioc_value": "47.236.56.15:4445",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-11-29 12:00:52",
            "last_seen_utc": "2026-06-30 10:47:11",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/47.236.56.15",
            "tags": "ALIBABA-CN-NET,AS45102,C2,censys,CobaltStrike,cs-watermark-0",
            "anonymous": "0",
            "reporter": "DonPasci"
        }
    ],
    "1660878": [
        {
            "ioc_value": "43.162.121.116:4000",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2025-11-29 04:01:42",
            "last_seen_utc": "2026-06-30 10:45:34",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/43.162.121.116",
            "tags": "AS132203,censys,EvilGinx,panel,Phishing,TENCENT-NET-AP-CN",
            "anonymous": "0",
            "reporter": "DonPasci"
        }
    ],
    "1651951": [
        {
            "ioc_value": "5.101.82.51:9999",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2025-11-28 04:01:01",
            "last_seen_utc": "2026-06-30 10:45:48",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/5.101.82.51",
            "tags": "AS-GLOBALTELEHOST,AS63023,C2,censys,RAT,Remcos",
            "anonymous": "0",
            "reporter": "DonPasci"
        }
    ],
    "1650889": [
        {
            "ioc_value": "job.itechno.cc",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-11-26 12:50:54",
            "last_seen_utc": "2026-06-30 10:46:24",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1650040": [
        {
            "ioc_value": "156.245.248.173:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-11-25 10:49:55",
            "last_seen_utc": "2026-06-30 11:21:33",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1649775": [
        {
            "ioc_value": "http://213.5.130.84",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2025-11-25 06:01:37",
            "last_seen_utc": "2026-06-30 06:01:35",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "c2,REMPROXY",
            "anonymous": "0",
            "reporter": "BlackLotusLabs"
        }
    ],
    "1649776": [
        {
            "ioc_value": "http://213.5.130.96",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2025-11-25 06:01:36",
            "last_seen_utc": "2026-06-30 06:01:33",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "c2,REMPROXY",
            "anonymous": "0",
            "reporter": "BlackLotusLabs"
        }
    ],
    "1649777": [
        {
            "ioc_value": "http://213.5.130.98",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2025-11-25 06:01:36",
            "last_seen_utc": "2026-06-30 06:01:35",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "c2,REMPROXY",
            "anonymous": "0",
            "reporter": "BlackLotusLabs"
        }
    ],
    "1649778": [
        {
            "ioc_value": "http://213.5.130.160",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2025-11-25 06:01:35",
            "last_seen_utc": "2026-06-30 06:01:35",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "c2,REMPROXY",
            "anonymous": "0",
            "reporter": "BlackLotusLabs"
        }
    ],
    "1649164": [
        {
            "ioc_value": "5.101.86.44:61288",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2025-11-23 08:00:29",
            "last_seen_utc": "2026-06-30 10:45:51",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/5.101.86.44",
            "tags": "AS-GLOBALTELEHOST,AS62563,C2,censys,RAT,Remcos",
            "anonymous": "0",
            "reporter": "DonPasci"
        }
    ],
    "1647446": [
        {
            "ioc_value": "193.233.245.114:38990",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.pink",
            "malware_alias": null,
            "malware_printable": "Pink",
            "first_seen_utc": "2025-11-21 06:30:46",
            "last_seen_utc": "2026-06-29 23:17:28",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "Pink",
            "anonymous": "0",
            "reporter": "Bitsight"
        }
    ],
    "1647575": [
        {
            "ioc_value": "123.58.64.57:34567",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-11-21 00:02:05",
            "last_seen_utc": "2026-06-30 10:46:42",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/123.58.64.57",
            "tags": "AS17623,C2,censys,CNCGROUP-SZ,CobaltStrike,cs-watermark-987654321",
            "anonymous": "0",
            "reporter": "DonPasci"
        }
    ],
    "1646839": [
        {
            "ioc_value": "43.156.63.124:64494",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-11-19 23:00:16",
            "last_seen_utc": "2026-06-30 09:54:04",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/43.156.63.124",
            "tags": "AS132203,C2,censys",
            "anonymous": "0",
            "reporter": "dyingbreeds_"
        }
    ],
    "1645785": [
        {
            "ioc_value": "47.236.149.142:46832",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-11-17 23:00:18",
            "last_seen_utc": "2026-06-30 10:47:10",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/47.236.149.142",
            "tags": "AS45102,C2,censys",
            "anonymous": "0",
            "reporter": "dyingbreeds_"
        }
    ],
    "1645505": [
        {
            "ioc_value": "194.233.73.173:4321",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2025-11-17 12:04:03",
            "last_seen_utc": "2026-06-30 10:44:19",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/194.233.73.173",
            "tags": "AdaptixC2,AS141995,C2,CAPL-AS-AP,censys",
            "anonymous": "0",
            "reporter": "DonPasci"
        }
    ],
    "1641582": [
        {
            "ioc_value": "62.4.0.66:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2025-11-15 08:48:18",
            "last_seen_utc": "2026-06-30 10:45:57",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1639703": [
        {
            "ioc_value": "62.60.226.183:483",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.tofsee",
            "malware_alias": "Gheg",
            "malware_printable": "Tofsee",
            "first_seen_utc": "2025-11-13 04:54:17",
            "last_seen_utc": "2026-06-30 11:22:28",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "c2,Tofsee",
            "anonymous": "0",
            "reporter": "Bitsight"
        }
    ],
    "1638854": [
        {
            "ioc_value": "54.165.230.182:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2025-11-12 04:02:31",
            "last_seen_utc": "2026-06-30 10:45:55",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/54.165.230.182",
            "tags": "AMAZON-AES,AS14618,C2,censys,Covenant",
            "anonymous": "0",
            "reporter": "DonPasci"
        }
    ],
    "1638274": [
        {
            "ioc_value": "38.242.212.5:4321",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2025-11-10 18:47:41",
            "last_seen_utc": "2026-06-30 10:45:30",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1638236": [
        {
            "ioc_value": "154.205.145.109:2096",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.havoc",
            "malware_alias": "Havokiz",
            "malware_printable": "Havoc",
            "first_seen_utc": "2025-11-10 16:02:55",
            "last_seen_utc": "2026-06-30 10:43:33",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/154.205.145.109",
            "tags": "AS138915,C2,censys,Havoc,KAOPU-HK",
            "anonymous": "0",
            "reporter": "DonPasci"
        }
    ],
    "1637255": [
        {
            "ioc_value": "62.60.226.65:43155",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2025-11-09 08:02:17",
            "last_seen_utc": "2026-06-30 10:45:58",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/62.60.226.65",
            "tags": "AS214351,C2,censys,FEMOIT,RAT,Remcos",
            "anonymous": "0",
            "reporter": "DonPasci"
        }
    ],
    "1636099": [
        {
            "ioc_value": "111.228.55.96:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-11-07 23:00:12",
            "last_seen_utc": "2026-06-30 11:21:03",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/111.228.55.96",
            "tags": "AS141679,C2,censys",
            "anonymous": "0",
            "reporter": "dyingbreeds_"
        }
    ],
    "1636044": [
        {
            "ioc_value": "193.143.1.216:8848",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.dcrat",
            "malware_alias": "DarkCrystal RAT",
            "malware_printable": "DCRat",
            "first_seen_utc": "2025-11-07 18:48:21",
            "last_seen_utc": "2026-06-30 10:44:16",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DCRat,drb-ra,RAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1634744": [
        {
            "ioc_value": "165.154.225.239:8443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-11-07 02:49:37",
            "last_seen_utc": "2026-06-30 10:46:50",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1634389": [
        {
            "ioc_value": "139.196.111.118:8088",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-11-06 07:26:25",
            "last_seen_utc": "2026-06-30 10:46:45",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-666666666",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1633705": [
        {
            "ioc_value": "8.155.161.181:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-11-05 07:54:55",
            "last_seen_utc": "2026-06-30 10:47:16",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-987654321",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1633501": [
        {
            "ioc_value": "59.110.28.230:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-11-04 20:01:04",
            "last_seen_utc": "2026-06-30 11:21:11",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/59.110.28.230",
            "tags": "ALIBABA-CN-NET,AS37963,C2,censys,CobaltStrike,cs-watermark-987654321",
            "anonymous": "0",
            "reporter": "DonPasci"
        }
    ],
    "1633194": [
        {
            "ioc_value": "51.15.8.6:31337",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.sliver",
            "malware_alias": null,
            "malware_printable": "Sliver",
            "first_seen_utc": "2025-11-04 08:00:54",
            "last_seen_utc": "2026-06-30 10:45:54",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/51.15.8.6",
            "tags": "AS12876,C2,censys,Online,Sliver",
            "anonymous": "0",
            "reporter": "DonPasci"
        }
    ],
    "1633063": [
        {
            "ioc_value": "192.253.227.88:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-11-04 02:49:22",
            "last_seen_utc": "2026-06-30 11:21:19",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1633061": [
        {
            "ioc_value": "167.88.168.76:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-11-04 02:49:14",
            "last_seen_utc": "2026-06-30 11:21:20",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1632776": [
        {
            "ioc_value": "83.229.126.183:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-11-03 20:00:26",
            "last_seen_utc": "2026-06-30 10:47:19",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/83.229.126.183",
            "tags": "AS139659,C2,censys,CobaltStrike,cs-watermark-987654321,LUCID-AS-AP",
            "anonymous": "0",
            "reporter": "DonPasci"
        }
    ],
    "1631753": [
        {
            "ioc_value": "117.72.175.125:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.vshell",
            "malware_alias": null,
            "malware_printable": "VShell",
            "first_seen_utc": "2025-11-03 12:08:57",
            "last_seen_utc": "2026-06-30 11:21:37",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://www.nviso.eu/blog",
            "tags": "C2,NVISO,VShell",
            "anonymous": "0",
            "reporter": "0xThiebaut"
        }
    ],
    "1631367": [
        {
            "ioc_value": "117.72.242.9:9999",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-11-03 09:03:04",
            "last_seen_utc": "2026-06-30 10:46:38",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/117.72.242.9",
            "tags": "AS141679,C2,censys",
            "anonymous": "0",
            "reporter": "dyingbreeds_"
        }
    ],
    "1631471": [
        {
            "ioc_value": "119.42.148.186:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-11-03 07:01:12",
            "last_seen_utc": "2026-06-30 11:21:22",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": "https://www.shodan.io/host/119.42.148.186#443",
            "tags": "c2,cobaltstrike,cs-watermark-666666666,shodan",
            "anonymous": "0",
            "reporter": "juroots"
        }
    ],
    "1630767": [
        {
            "ioc_value": "159.223.0.103:31337",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.sliver",
            "malware_alias": null,
            "malware_printable": "Sliver",
            "first_seen_utc": "2025-11-01 12:33:11",
            "last_seen_utc": "2026-06-30 10:43:39",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": "https://www.shodan.io/host/159.223.0.103#31337",
            "tags": "c2,shodan,sliver",
            "anonymous": "0",
            "reporter": "juroots"
        }
    ],
    "1630704": [
        {
            "ioc_value": "117.72.175.125:8087",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-11-01 12:31:38",
            "last_seen_utc": "2026-06-30 10:46:38",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": "https://www.shodan.io/host/117.72.175.125#8087",
            "tags": "c2,cobaltstrike,cs-watermark-391144938,shodan",
            "anonymous": "0",
            "reporter": "juroots"
        }
    ],
    "1630391": [
        {
            "ioc_value": "85.215.57.133:8080",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2025-10-31 16:01:24",
            "last_seen_utc": "2026-06-30 10:46:12",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/85.215.57.133",
            "tags": "AdaptixC2,AS8560,C2,censys,IONOS-AS",
            "anonymous": "0",
            "reporter": "DonPasci"
        }
    ],
    "1629384": [
        {
            "ioc_value": "103.149.93.146:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-10-30 04:00:42",
            "last_seen_utc": "2026-06-30 11:21:24",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/103.149.93.146",
            "tags": "AS401696,C2,censys,CobaltStrike,COGNETCLOUD,cs-watermark-666666666",
            "anonymous": "0",
            "reporter": "DonPasci"
        }
    ],
    "1628814": [
        {
            "ioc_value": "179.43.186.214:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-10-29 09:23:45",
            "last_seen_utc": "2026-06-30 10:46:53",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-987654321",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1628691": [
        {
            "ioc_value": "8.17.56.128:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-10-29 02:49:59",
            "last_seen_utc": "2026-06-30 10:47:17",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1628076": [
        {
            "ioc_value": "8.137.149.67:8060",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-10-28 12:28:01",
            "last_seen_utc": "2026-06-30 10:47:16",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-987654321",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1627925": [
        {
            "ioc_value": "182.254.155.23:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-10-28 04:00:27",
            "last_seen_utc": "2026-06-30 11:21:20",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/182.254.155.23",
            "tags": "AS45090,C2,censys,CobaltStrike,cs-watermark-987654321,TENCENT-NET-AP",
            "anonymous": "0",
            "reporter": "DonPasci"
        }
    ],
    "1627719": [
        {
            "ioc_value": "182.16.98.83:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-10-28 02:49:21",
            "last_seen_utc": "2026-06-30 11:21:32",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1627659": [
        {
            "ioc_value": "182.16.98.84:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-10-27 20:50:01",
            "last_seen_utc": "2026-06-30 11:21:32",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1626705": [
        {
            "ioc_value": "196.251.83.89:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-10-26 07:39:14",
            "last_seen_utc": "2026-06-30 11:21:19",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/196.251.83.89",
            "tags": "AS401120,C2,censys,CHEAPY-HOST",
            "anonymous": "0",
            "reporter": "dyingbreeds_"
        }
    ],
    "1626312": [
        {
            "ioc_value": "173.212.216.226:8080",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.chaos",
            "malware_alias": "FakeRyuk,RyukJoke,Yashma",
            "malware_printable": "Chaos",
            "first_seen_utc": "2025-10-25 04:02:07",
            "last_seen_utc": "2026-06-30 10:43:51",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/173.212.216.226",
            "tags": "AS51167,censys,Chaos,CONTABO,panel",
            "anonymous": "0",
            "reporter": "DonPasci"
        }
    ],
    "1626300": [
        {
            "ioc_value": "47.121.135.201:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-10-25 04:00:11",
            "last_seen_utc": "2026-06-30 11:21:16",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/47.121.135.201",
            "tags": "ALIBABA-CN-NET,AS37963,C2,censys,CobaltStrike,cs-watermark-987654321",
            "anonymous": "0",
            "reporter": "DonPasci"
        }
    ],
    "1626112": [
        {
            "ioc_value": "140.143.194.253:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-10-24 16:00:08",
            "last_seen_utc": "2026-06-30 11:21:34",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/140.143.194.253",
            "tags": "AS45090,C2,censys,CobaltStrike,cs-watermark-987654321,TENCENT-NET-AP",
            "anonymous": "0",
            "reporter": "DonPasci"
        }
    ],
    "1625642": [
        {
            "ioc_value": "maelootp.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-10-23 16:48:58",
            "last_seen_utc": "2026-06-30 11:21:25",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1625564": [
        {
            "ioc_value": "evil.ritademo.io.vn",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-10-23 12:50:22",
            "last_seen_utc": "2026-06-30 11:21:25",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1625393": [
        {
            "ioc_value": "40.66.42.246:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.havoc",
            "malware_alias": "Havokiz",
            "malware_printable": "Havoc",
            "first_seen_utc": "2025-10-23 08:02:52",
            "last_seen_utc": "2026-06-30 10:45:31",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/40.66.42.246",
            "tags": "AS8075,C2,censys,Havoc,MICROSOFT-CORP-MSN-AS-BLOCK",
            "anonymous": "0",
            "reporter": "DonPasci"
        }
    ],
    "1625174": [
        {
            "ioc_value": "40.66.42.246:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.havoc",
            "malware_alias": "Havokiz",
            "malware_printable": "Havoc",
            "first_seen_utc": "2025-10-22 22:00:43",
            "last_seen_utc": "2026-06-30 10:45:31",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/40.66.42.246",
            "tags": "AS8075,C2,censys,MICROSOFT-CORP-MSN-AS-BLOCK",
            "anonymous": "0",
            "reporter": "dyingbreeds_"
        }
    ],
    "1625107": [
        {
            "ioc_value": "185.72.8.137:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.ransomhub",
            "malware_alias": null,
            "malware_printable": "RansomHub",
            "first_seen_utc": "2025-10-22 18:45:52",
            "last_seen_utc": "2026-06-30 10:44:10",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RansomHub",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1625108": [
        {
            "ioc_value": "185.72.8.137:7882",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.ransomhub",
            "malware_alias": null,
            "malware_printable": "RansomHub",
            "first_seen_utc": "2025-10-22 18:45:52",
            "last_seen_utc": "2026-06-30 10:44:10",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RansomHub",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1624905": [
        {
            "ioc_value": "116.62.226.163:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-10-22 15:43:44",
            "last_seen_utc": "2026-06-30 11:21:37",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": null,
            "tags": "c2,censys,cobalt strike",
            "anonymous": "0",
            "reporter": "sojubear"
        }
    ],
    "1624664": [
        {
            "ioc_value": "115.190.140.220:1443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-10-22 08:02:02",
            "last_seen_utc": "2026-06-30 10:46:36",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/115.190.140.220",
            "tags": "AS137718,C2,censys,CobaltStrike,cs-watermark-987654321,VOLCANO-ENGINE",
            "anonymous": "0",
            "reporter": "DonPasci"
        }
    ],
    "1624300": [
        {
            "ioc_value": "47.110.67.64:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-10-21 20:01:59",
            "last_seen_utc": "2026-06-30 11:21:29",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/47.110.67.64",
            "tags": "ALIBABA-CN-NET,AS37963,C2,censys,CobaltStrike,cs-watermark-987654321",
            "anonymous": "0",
            "reporter": "DonPasci"
        }
    ],
    "1624166": [
        {
            "ioc_value": "http://213.5.130.75",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2025-10-21 13:19:24",
            "last_seen_utc": "2026-06-30 06:01:35",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "c2,REMPROXY",
            "anonymous": "0",
            "reporter": "BlackLotusLabs"
        }
    ],
    "1624167": [
        {
            "ioc_value": "http://213.5.130.10",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2025-10-21 13:19:23",
            "last_seen_utc": "2026-06-30 06:01:33",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "c2,REMPROXY",
            "anonymous": "0",
            "reporter": "BlackLotusLabs"
        }
    ],
    "1624170": [
        {
            "ioc_value": "http://213.5.130.89",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2025-10-21 13:19:22",
            "last_seen_utc": "2026-06-30 06:01:34",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "c2,REMPROXY",
            "anonymous": "0",
            "reporter": "BlackLotusLabs"
        }
    ],
    "1618876": [
        {
            "ioc_value": "www.salesf0rce.club",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-10-21 02:49:37",
            "last_seen_utc": "2026-06-30 11:21:13",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1617577": [
        {
            "ioc_value": "143.92.43.246:8011",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-10-18 12:49:25",
            "last_seen_utc": "2026-06-30 10:46:45",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1617285": [
        {
            "ioc_value": "5.152.16.189:8443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.netsupportmanager_rat",
            "malware_alias": "NetSupport",
            "malware_printable": "NetSupportManager RAT",
            "first_seen_utc": "2025-10-17 12:02:17",
            "last_seen_utc": "2026-06-30 10:45:52",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/5.152.16.189",
            "tags": "AS35805,C2,censys,Netsupport,RAT,SILKNET-AS",
            "anonymous": "0",
            "reporter": "DonPasci"
        }
    ],
    "1617002": [
        {
            "ioc_value": "3.143.55.137:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2025-10-17 08:02:43",
            "last_seen_utc": "2026-06-30 10:45:22",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/3.143.55.137",
            "tags": "AMAZON-02,AS16509,C2,censys,Mythic",
            "anonymous": "0",
            "reporter": "DonPasci"
        }
    ],
    "1616729": [
        {
            "ioc_value": "47.129.2.130:53",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-10-16 22:50:54",
            "last_seen_utc": "2026-06-30 10:47:10",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1616728": [
        {
            "ioc_value": "ns1.gygiuh.online",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-10-16 22:49:04",
            "last_seen_utc": "2026-06-30 10:46:25",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1615761": [
        {
            "ioc_value": "89.58.30.49:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2025-10-14 20:02:48",
            "last_seen_utc": "2026-06-30 10:46:15",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/89.58.30.49",
            "tags": "AS197540,C2,censys,Covenant,NETCUP-AS",
            "anonymous": "0",
            "reporter": "DonPasci"
        }
    ],
    "1614712": [
        {
            "ioc_value": "5.101.82.60:2404",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2025-10-14 08:01:33",
            "last_seen_utc": "2026-06-30 10:45:48",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/5.101.82.60",
            "tags": "AS-GLOBALTELEHOST,AS63023,C2,censys,RAT,Remcos",
            "anonymous": "0",
            "reporter": "DonPasci"
        }
    ],
    "1608605": [
        {
            "ioc_value": "143.92.43.153:8011",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-10-07 02:49:11",
            "last_seen_utc": "2026-06-30 10:46:45",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1608606": [
        {
            "ioc_value": "143.92.43.231:8011",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-10-07 02:49:11",
            "last_seen_utc": "2026-06-30 10:46:45",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1604499": [
        {
            "ioc_value": "149.50.135.215:49152",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2025-09-30 00:02:15",
            "last_seen_utc": "2026-06-30 10:43:31",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/149.50.135.215",
            "tags": "AdaptixC2,AS27823,C2,censys,Dattatec.com",
            "anonymous": "0",
            "reporter": "DonPasci"
        }
    ],
    "1603281": [
        {
            "ioc_value": "154.92.15.229:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-09-28 15:48:32",
            "last_seen_utc": "2026-06-30 11:21:21",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": null,
            "tags": "c2,censys,cobalt strike",
            "anonymous": "0",
            "reporter": "sojubear"
        }
    ],
    "1602818": [
        {
            "ioc_value": "84.27.86.226:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.netsupportmanager_rat",
            "malware_alias": "NetSupport",
            "malware_printable": "NetSupportManager RAT",
            "first_seen_utc": "2025-09-27 16:02:13",
            "last_seen_utc": "2026-06-30 10:46:11",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/84.27.86.226",
            "tags": "AS33915,C2,censys,Netsupport,RAT,TNF-AS",
            "anonymous": "0",
            "reporter": "DonPasci"
        }
    ],
    "1601556": [
        {
            "ioc_value": "115.120.245.134:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-09-25 20:00:39",
            "last_seen_utc": "2026-06-30 11:21:04",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/115.120.245.134",
            "tags": "AS55990,C2,censys,CobaltStrike,cs-watermark-987654321,HWCSNET",
            "anonymous": "0",
            "reporter": "DonPasci"
        }
    ],
    "1601359": [
        {
            "ioc_value": "196.251.69.253:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-09-25 12:51:01",
            "last_seen_utc": "2026-06-30 11:21:19",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1599651": [
        {
            "ioc_value": "47.113.186.138:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-09-24 20:00:10",
            "last_seen_utc": "2026-06-30 11:21:29",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/47.113.186.138",
            "tags": "ALIBABA-CN-NET,AS37963,C2,censys,CobaltStrike,cs-watermark-987654321",
            "anonymous": "0",
            "reporter": "DonPasci"
        }
    ],
    "1599442": [
        {
            "ioc_value": "43.162.114.240:4000",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2025-09-24 08:02:13",
            "last_seen_utc": "2026-06-30 10:45:34",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/43.162.114.240",
            "tags": "AS132203,censys,EvilGinx,panel,Phishing,TENCENT-NET-AP-CN",
            "anonymous": "0",
            "reporter": "DonPasci"
        }
    ],
    "1598336": [
        {
            "ioc_value": "43.139.170.200:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-09-23 06:06:58",
            "last_seen_utc": "2026-06-30 10:47:03",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-100000",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1598300": [
        {
            "ioc_value": "43.162.114.107:4000",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2025-09-23 04:00:59",
            "last_seen_utc": "2026-06-30 10:45:34",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/43.162.114.107",
            "tags": "AS132203,censys,EvilGinx,Phishing",
            "anonymous": "0",
            "reporter": "dyingbreeds_"
        }
    ],
    "1598102": [
        {
            "ioc_value": "159.75.211.248:53",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-09-22 14:51:05",
            "last_seen_utc": "2026-06-30 10:46:50",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1598100": [
        {
            "ioc_value": "cstest.mucfc.store",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-09-22 14:49:30",
            "last_seen_utc": "2026-06-30 10:46:22",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1597898": [
        {
            "ioc_value": "ns2.cryptwechat.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-09-22 08:49:38",
            "last_seen_utc": "2026-06-30 10:46:26",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1597894": [
        {
            "ioc_value": "ns1.cryptwechat.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-09-22 08:49:35",
            "last_seen_utc": "2026-06-30 10:46:25",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1596535": [
        {
            "ioc_value": "43.162.108.133:4000",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2025-09-21 16:01:22",
            "last_seen_utc": "2026-06-30 10:45:34",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/43.162.108.133",
            "tags": "AS132203,censys,EvilGinx,panel,Phishing,TENCENT-NET-AP-CN",
            "anonymous": "0",
            "reporter": "DonPasci"
        }
    ],
    "1590702": [
        {
            "ioc_value": "61.155.145.182:8090",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-09-15 20:01:53",
            "last_seen_utc": "2026-06-30 10:47:13",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/61.155.145.182",
            "tags": "AS140292,C2,censys,CHINATELECOM-JIANGSU-SUZHOU-5G-NETWORK,CobaltStrike,cs-watermark-987654321",
            "anonymous": "0",
            "reporter": "DonPasci"
        }
    ],
    "1589068": [
        {
            "ioc_value": "18.167.174.198:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pupy",
            "malware_alias": "Patpoopy",
            "malware_printable": "pupy",
            "first_seen_utc": "2025-09-13 04:01:58",
            "last_seen_utc": "2026-06-30 10:43:55",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/18.167.174.198",
            "tags": "AMAZON-02,AS16509,C2,censys,Pupy,RAT",
            "anonymous": "0",
            "reporter": "DonPasci"
        }
    ],
    "1588133": [
        {
            "ioc_value": "195.178.110.135:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-09-11 20:01:36",
            "last_seen_utc": "2026-06-30 11:21:19",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/195.178.110.135",
            "tags": "AS48090,C2,censys,CobaltStrike,cs-watermark-426352781,DMZHOST",
            "anonymous": "0",
            "reporter": "DonPasci"
        }
    ],
    "1588128": [
        {
            "ioc_value": "150.158.170.241:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-09-11 20:01:30",
            "last_seen_utc": "2026-06-30 11:21:21",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/150.158.170.241",
            "tags": "AS45090,C2,censys,CobaltStrike,cs-watermark-987654321,TENCENT-NET-AP",
            "anonymous": "0",
            "reporter": "DonPasci"
        }
    ],
    "1587773": [
        {
            "ioc_value": "106.12.111.209:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-09-11 06:43:14",
            "last_seen_utc": "2026-06-30 11:21:23",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-1234567890",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1587441": [
        {
            "ioc_value": "101.32.109.112:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-09-10 20:01:24",
            "last_seen_utc": "2026-06-30 11:21:24",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/101.32.109.112",
            "tags": "AS132203,C2,censys,CobaltStrike,cs-watermark-987654321,TENCENT-NET-AP-CN",
            "anonymous": "0",
            "reporter": "DonPasci"
        }
    ],
    "1587229": [
        {
            "ioc_value": "142.93.86.246:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2025-09-10 16:02:07",
            "last_seen_utc": "2026-06-30 10:43:26",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/142.93.86.246",
            "tags": "AS14061,C2,censys,DIGITALOCEAN-ASN,Mythic",
            "anonymous": "0",
            "reporter": "DonPasci"
        }
    ],
    "1582910": [
        {
            "ioc_value": "8.138.222.215:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-09-06 20:01:18",
            "last_seen_utc": "2026-06-30 11:21:15",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/8.138.222.215",
            "tags": "ALIBABA-CN-NET,AS37963,C2,censys,CobaltStrike,cs-watermark-666666666",
            "anonymous": "0",
            "reporter": "DonPasci"
        }
    ],
    "1582784": [
        {
            "ioc_value": "103.236.70.158:8000",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.dcrat",
            "malware_alias": "DarkCrystal RAT",
            "malware_printable": "DCRat",
            "first_seen_utc": "2025-09-06 12:01:48",
            "last_seen_utc": "2026-06-30 10:43:09",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/103.236.70.158",
            "tags": "AS134768,C2,censys,CHINANET-SHAANXI-CLOUD-BASE,DcRAT,RAT",
            "anonymous": "0",
            "reporter": "DonPasci"
        }
    ],
    "1581557": [
        {
            "ioc_value": "8.148.194.157:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-09-04 07:40:17",
            "last_seen_utc": "2026-06-30 11:21:15",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": "https://www.shodan.io/host/8.148.194.157#443",
            "tags": "c2,cobaltstrike,cs-watermark-666666666,shodan",
            "anonymous": "0",
            "reporter": "juroots"
        }
    ],
    "1580723": [
        {
            "ioc_value": "47.236.159.248:53",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-09-02 18:52:55",
            "last_seen_utc": "2026-06-30 10:47:11",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1580721": [
        {
            "ioc_value": "ns2.microoosoft.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-09-02 18:50:45",
            "last_seen_utc": "2026-06-30 10:46:26",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1580720": [
        {
            "ioc_value": "ns1.microoosoft.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-09-02 18:50:42",
            "last_seen_utc": "2026-06-30 10:46:25",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1580257": [
        {
            "ioc_value": "47.121.137.8:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-09-02 05:43:42",
            "last_seen_utc": "2026-06-30 10:47:09",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": "https://www.shodan.io/host/47.121.137.8#80",
            "tags": "c2,cobaltstrike,cs-watermark-666666666,shodan",
            "anonymous": "0",
            "reporter": "juroots"
        }
    ],
    "1580237": [
        {
            "ioc_value": "47.99.196.178:7001",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2025-09-02 04:01:38",
            "last_seen_utc": "2026-06-30 10:45:47",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/47.99.196.178",
            "tags": "AdaptixC2,ALIBABA-CN-NET,AS37963,C2,censys",
            "anonymous": "0",
            "reporter": "DonPasci"
        }
    ],
    "1578899": [
        {
            "ioc_value": "103.73.66.43:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-08-31 20:50:07",
            "last_seen_utc": "2026-06-30 11:21:38",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1577783": [
        {
            "ioc_value": "43.199.78.142:53",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-08-29 22:50:45",
            "last_seen_utc": "2026-06-30 10:47:05",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1577775": [
        {
            "ioc_value": "n1.google-analytcis.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-08-29 22:49:03",
            "last_seen_utc": "2026-06-30 10:46:24",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1577776": [
        {
            "ioc_value": "n2.google-analytcis.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-08-29 22:49:03",
            "last_seen_utc": "2026-06-30 10:46:24",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1577777": [
        {
            "ioc_value": "n3.google-analytcis.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-08-29 22:49:03",
            "last_seen_utc": "2026-06-30 10:46:24",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1577774": [
        {
            "ioc_value": "lab.google-analytcis.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-08-29 22:49:01",
            "last_seen_utc": "2026-06-30 10:46:24",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1574437": [
        {
            "ioc_value": "183.63.173.29:8008",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-08-25 16:50:36",
            "last_seen_utc": "2026-06-29 10:46:41",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1574099": [
        {
            "ioc_value": "89.216.98.17:3085",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.netsupportmanager_rat",
            "malware_alias": "NetSupport",
            "malware_printable": "NetSupportManager RAT",
            "first_seen_utc": "2025-08-25 08:14:17",
            "last_seen_utc": "2026-06-30 10:46:14",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": "https://www.shodan.io/host/89.216.98.17#3085",
            "tags": "c2,netsupport,shodan",
            "anonymous": "0",
            "reporter": "juroots"
        }
    ],
    "1573705": [
        {
            "ioc_value": "43.163.112.217:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-08-25 00:00:27",
            "last_seen_utc": "2026-06-30 11:21:17",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/43.163.112.217",
            "tags": "AS132203,C2,censys,CobaltStrike,cs-watermark-987654321,TENCENT-NET-AP-CN",
            "anonymous": "0",
            "reporter": "DonPasci"
        }
    ],
    "1573120": [
        {
            "ioc_value": "62.60.226.133:61287",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2025-08-23 18:00:42",
            "last_seen_utc": "2026-06-30 10:45:57",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://tria.ge/250823-wglgsaxsdv",
            "tags": "AS214351,C2,rat,remcos,triage",
            "anonymous": "0",
            "reporter": "DonPasci"
        }
    ],
    "1571607": [
        {
            "ioc_value": "178.16.55.53:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-08-20 08:02:12",
            "last_seen_utc": "2026-06-30 11:21:32",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/178.16.55.53",
            "tags": "C2,censys,CobaltStrike,cs-watermark-666666666",
            "anonymous": "0",
            "reporter": "DonPasci"
        }
    ],
    "1570775": [
        {
            "ioc_value": "116.203.31.207:9999",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-08-18 20:01:59",
            "last_seen_utc": "2026-06-30 10:46:37",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/116.203.31.207",
            "tags": "AS24940,C2,censys,CobaltStrike,cs-watermark-987654321,HETZNER-AS",
            "anonymous": "0",
            "reporter": "DonPasci"
        }
    ],
    "1570558": [
        {
            "ioc_value": "150.187.25.242:9999",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-08-17 20:01:54",
            "last_seen_utc": "2026-06-30 10:46:46",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/150.187.25.242",
            "tags": "AS20312,C2,censys,CobaltStrike,cs-watermark-987654321,Fundacion",
            "anonymous": "0",
            "reporter": "DonPasci"
        }
    ],
    "1569825": [
        {
            "ioc_value": "8.138.167.123:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-08-16 15:22:26",
            "last_seen_utc": "2026-06-30 11:21:15",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": "https://www.shodan.io/host/8.138.167.123#443",
            "tags": "c2,cobaltstrike,shodan",
            "anonymous": "0",
            "reporter": "juroots"
        }
    ],
    "1569780": [
        {
            "ioc_value": "119.29.231.118:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-08-16 08:01:47",
            "last_seen_utc": "2026-06-30 11:21:22",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/119.29.231.118",
            "tags": "AS45090,C2,censys,CobaltStrike,cs-watermark-666666666,TENCENT-NET-AP",
            "anonymous": "0",
            "reporter": "DonPasci"
        }
    ],
    "1569167": [
        {
            "ioc_value": "116.198.233.179:6666",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-08-15 21:57:45",
            "last_seen_utc": "2026-06-30 10:46:36",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": "https://www.shodan.io/host/116.198.233.179#6666",
            "tags": "c2,cobaltstrike,cs-watermark-987654321,shodan",
            "anonymous": "0",
            "reporter": "juroots"
        }
    ],
    "1569004": [
        {
            "ioc_value": "8ve3qsgxk7rs6.cfc-execute.bj.baidubce.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-08-15 12:49:06",
            "last_seen_utc": "2026-06-30 10:46:21",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1568713": [
        {
            "ioc_value": "117.72.184.172:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-08-15 06:21:34",
            "last_seen_utc": "2026-06-30 11:21:36",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/117.72.184.172",
            "tags": "AS141679,C2,censys",
            "anonymous": "0",
            "reporter": "dyingbreeds_"
        }
    ],
    "1568192": [
        {
            "ioc_value": "115.190.138.41:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-08-13 16:01:30",
            "last_seen_utc": "2026-06-30 10:46:36",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/115.190.138.41",
            "tags": "AS137718,C2,censys,CobaltStrike,cs-watermark-391144938,VOLCANO-ENGINE",
            "anonymous": "0",
            "reporter": "DonPasci"
        }
    ],
    "1567756": [
        {
            "ioc_value": "116.198.233.179:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-08-12 20:01:25",
            "last_seen_utc": "2026-06-30 11:21:37",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/116.198.233.179",
            "tags": "AS137699,C2,censys,CHINATELECOM-JIANGSU-SUQIAN-IDC,CobaltStrike,cs-watermark-987654321",
            "anonymous": "0",
            "reporter": "DonPasci"
        }
    ],
    "1567668": [
        {
            "ioc_value": "62.117.98.115:8001",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2025-08-12 12:01:59",
            "last_seen_utc": "2026-06-30 10:45:57",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/62.117.98.115",
            "tags": "AS8732,C2,censys,COMCOR-AS,Mythic",
            "anonymous": "0",
            "reporter": "DonPasci"
        }
    ],
    "1567648": [
        {
            "ioc_value": "107.174.115.43:53",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-08-12 10:50:19",
            "last_seen_utc": "2026-06-30 10:46:33",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1567604": [
        {
            "ioc_value": "68.64.176.172:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-08-12 06:35:23",
            "last_seen_utc": "2026-06-30 10:47:14",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-666666666",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1567234": [
        {
            "ioc_value": "45.204.216.24:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-08-11 08:01:15",
            "last_seen_utc": "2026-06-30 11:21:17",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/45.204.216.24",
            "tags": "AS62468,C2,censys,CobaltStrike,cs-watermark-987654321,HKCLOUDX",
            "anonymous": "0",
            "reporter": "DonPasci"
        }
    ],
    "1565164": [
        {
            "ioc_value": "8.219.76.168:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-08-06 12:54:26",
            "last_seen_utc": "2026-06-30 11:21:13",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1564496": [
        {
            "ioc_value": "47.105.36.109:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-08-05 08:53:36",
            "last_seen_utc": "2026-06-30 11:21:17",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1564345": [
        {
            "ioc_value": "185.233.166.124:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.ransomhub",
            "malware_alias": null,
            "malware_printable": "RansomHub",
            "first_seen_utc": "2025-08-04 20:45:44",
            "last_seen_utc": "2026-06-30 10:44:08",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RansomHub",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1564346": [
        {
            "ioc_value": "185.233.166.124:9702",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.ransomhub",
            "malware_alias": null,
            "malware_printable": "RansomHub",
            "first_seen_utc": "2025-08-04 20:45:44",
            "last_seen_utc": "2026-06-30 10:44:08",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RansomHub",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1563211": [
        {
            "ioc_value": "89.197.168.150:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2025-08-01 20:01:06",
            "last_seen_utc": "2026-06-30 10:46:14",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/89.197.168.150",
            "tags": "AS47474,C2,censys,Mythic,VIRTUAL1",
            "anonymous": "0",
            "reporter": "DonPasci"
        }
    ],
    "1562934": [
        {
            "ioc_value": "103.233.8.39:8888",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2025-07-31 20:00:58",
            "last_seen_utc": "2026-06-28 13:05:08",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/103.233.8.39",
            "tags": "AS133201,C2,censys,COMING-AS,Supershell",
            "anonymous": "0",
            "reporter": "DonPasci"
        }
    ],
    "1561181": [
        {
            "ioc_value": "117.72.181.104:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-07-27 16:00:55",
            "last_seen_utc": "2026-06-30 11:21:23",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/117.72.181.104",
            "tags": "AS141679,C2,censys,CHINATELECOM-IDC-BTHBD-AP,CobaltStrike,cs-watermark-666666",
            "anonymous": "0",
            "reporter": "DonPasci"
        }
    ],
    "1560617": [
        {
            "ioc_value": "47.236.130.154:53",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-07-25 10:51:18",
            "last_seen_utc": "2026-06-30 10:47:10",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1559822": [
        {
            "ioc_value": "47.122.152.65:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-07-23 16:00:37",
            "last_seen_utc": "2026-06-30 10:47:09",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/47.122.152.65",
            "tags": "ALIBABA-CN-NET,AS37963,C2,censys,CobaltStrike,cs-watermark-987654321",
            "anonymous": "0",
            "reporter": "DonPasci"
        }
    ],
    "1558329": [
        {
            "ioc_value": "103.125.248.109:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-07-19 12:49:30",
            "last_seen_utc": "2026-06-30 11:21:24",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1558180": [
        {
            "ioc_value": "104.167.16.88:4321",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2025-07-19 00:01:30",
            "last_seen_utc": "2026-06-30 10:43:11",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/104.167.16.88",
            "tags": "AdaptixC2,AS16276,C2,censys,OVH",
            "anonymous": "0",
            "reporter": "DonPasci"
        }
    ],
    "1558066": [
        {
            "ioc_value": "193.112.84.248:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-07-18 12:51:20",
            "last_seen_utc": "2026-06-30 11:21:19",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1558027": [
        {
            "ioc_value": "206.189.227.148:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2025-07-18 08:01:12",
            "last_seen_utc": "2026-06-30 10:44:30",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/206.189.227.148",
            "tags": "AS14061,C2,censys,DIGITALOCEAN-ASN,Mythic",
            "anonymous": "0",
            "reporter": "DonPasci"
        }
    ],
    "1557619": [
        {
            "ioc_value": "ns3.nsebseshop.cloud",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-07-16 22:49:04",
            "last_seen_utc": "2026-06-30 10:46:27",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1557618": [
        {
            "ioc_value": "ns2.nsebseshop.cloud",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-07-16 22:49:03",
            "last_seen_utc": "2026-06-30 10:46:27",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1557617": [
        {
            "ioc_value": "ns1.nsebseshop.cloud",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-07-16 22:49:02",
            "last_seen_utc": "2026-06-30 10:46:26",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1556099": [
        {
            "ioc_value": "51.81.171.234:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.havoc",
            "malware_alias": "Havokiz",
            "malware_printable": "Havoc",
            "first_seen_utc": "2025-07-12 00:01:36",
            "last_seen_utc": "2026-06-30 10:45:54",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/51.81.171.234",
            "tags": "AS16276,C2,censys,Havoc,OVH",
            "anonymous": "0",
            "reporter": "DonPasci"
        }
    ],
    "1555914": [
        {
            "ioc_value": "38.207.178.172:8002",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.chaos",
            "malware_alias": "FakeRyuk,RyukJoke,Yashma",
            "malware_printable": "Chaos",
            "first_seen_utc": "2025-07-11 12:05:09",
            "last_seen_utc": "2026-06-30 10:45:30",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "AS139659,chaos,LUCIDACLOUD LIMITED",
            "anonymous": "0",
            "reporter": "antiphishorg"
        }
    ],
    "1554642": [
        {
            "ioc_value": "88.129.151.109:8080",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.deimos_c2",
            "malware_alias": null,
            "malware_printable": "DeimosC2",
            "first_seen_utc": "2025-07-08 20:56:28",
            "last_seen_utc": "2026-06-30 10:46:13",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "Deimos,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1554340": [
        {
            "ioc_value": "88.129.147.201:8080",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.deimos_c2",
            "malware_alias": null,
            "malware_printable": "DeimosC2",
            "first_seen_utc": "2025-07-07 20:54:20",
            "last_seen_utc": "2026-06-30 10:46:13",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "Deimos,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1554064": [
        {
            "ioc_value": "8.152.99.85:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-07-06 20:00:32",
            "last_seen_utc": "2026-06-30 11:21:14",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/8.152.99.85",
            "tags": "ALIBABA-CN-NET,AS37963,C2,censys,CobaltStrike,cs-watermark-666666666",
            "anonymous": "0",
            "reporter": "DonPasci"
        }
    ],
    "1553070": [
        {
            "ioc_value": "112.125.19.107:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-07-03 20:00:15",
            "last_seen_utc": "2026-06-30 10:46:34",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/112.125.19.107",
            "tags": "ALIBABA-CN-NET,AS37963,C2,censys,CobaltStrike,cs-watermark-1234567890",
            "anonymous": "0",
            "reporter": "DonPasci"
        }
    ],
    "1551457": [
        {
            "ioc_value": "217.154.212.25:8000",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-06-30 05:36:40",
            "last_seen_utc": "2026-06-30 10:46:57",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": "https://www.shodan.io/host/217.154.212.25#8000",
            "tags": "c2,cobaltstrike,cs-watermark-987654321,shodan",
            "anonymous": "0",
            "reporter": "juroots"
        }
    ],
    "1550784": [
        {
            "ioc_value": "116.205.143.204:53",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-06-28 10:54:22",
            "last_seen_utc": "2026-06-30 10:46:37",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1550783": [
        {
            "ioc_value": "dns1.globalcdn.autos",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-06-28 10:53:12",
            "last_seen_utc": "2026-06-30 10:46:23",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1550284": [
        {
            "ioc_value": "54.38.94.225:8886",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.eye_pyramid",
            "malware_alias": null,
            "malware_printable": "Eye Pyramid",
            "first_seen_utc": "2025-06-28 08:51:18",
            "last_seen_utc": "2026-06-30 10:45:56",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,EyePyramid",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1549925": [
        {
            "ioc_value": "67.205.141.81:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2025-06-27 07:00:53",
            "last_seen_utc": "2026-06-30 10:46:01",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": "https://www.shodan.io/host/67.205.141.81#7443",
            "tags": "c2,mythic,shodan",
            "anonymous": "0",
            "reporter": "juroots"
        }
    ],
    "1549030": [
        {
            "ioc_value": "156.227.233.153:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-06-25 04:00:19",
            "last_seen_utc": "2026-06-30 11:21:20",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/156.227.233.153",
            "tags": "AS138152,C2,censys",
            "anonymous": "0",
            "reporter": "dyingbreeds_"
        }
    ],
    "1548335": [
        {
            "ioc_value": "107.173.122.193:53",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-06-21 18:56:08",
            "last_seen_utc": "2026-06-30 10:46:33",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1548333": [
        {
            "ioc_value": "ns3.admlistdel.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-06-21 18:55:13",
            "last_seen_utc": "2026-06-30 10:46:27",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1548330": [
        {
            "ioc_value": "ns2.admlistdel.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-06-21 18:55:10",
            "last_seen_utc": "2026-06-30 10:46:26",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1547925": [
        {
            "ioc_value": "82.156.156.160:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-06-20 06:01:32",
            "last_seen_utc": "2026-06-30 11:21:14",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-666666666",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1546246": [
        {
            "ioc_value": "191.93.118.254:9000",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2025-06-18 08:02:37",
            "last_seen_utc": "2026-06-30 10:44:13",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://bazaar.abuse.ch/sample/9265a6e0b26a240f1f8bffddf3b36d0e533919d0c894bd66839a90e351961464/",
            "tags": "AsyncRAT,RAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1546232": [
        {
            "ioc_value": "191.93.118.254:8848",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2025-06-18 07:58:54",
            "last_seen_utc": "2026-06-30 10:44:13",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://bazaar.abuse.ch/sample/6ecbf71d231e9b9e7459b97c97d94aed467481b5b4f22af288bbaea5945c1af4/",
            "tags": "AsyncRAT,RAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1545615": [
        {
            "ioc_value": "8.147.128.54:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-06-17 03:12:25",
            "last_seen_utc": "2026-06-30 11:21:15",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1545597": [
        {
            "ioc_value": "47.107.136.106:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-06-16 23:10:50",
            "last_seen_utc": "2026-06-30 10:47:08",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1545348": [
        {
            "ioc_value": "8.137.149.67:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-06-16 12:01:46",
            "last_seen_utc": "2026-06-30 10:47:16",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/8.137.149.67",
            "tags": "ALIBABA-CN-NET,AS37963,C2,censys,CobaltStrike,cs-watermark-987654321",
            "anonymous": "0",
            "reporter": "DonPasci"
        }
    ],
    "1545221": [
        {
            "ioc_value": "107.173.122.193:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-06-16 08:01:46",
            "last_seen_utc": "2026-06-30 10:46:33",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/107.173.122.193",
            "tags": "AS-COLOCROSSING,AS36352,C2,censys,CobaltStrike,cs-watermark-391144938",
            "anonymous": "0",
            "reporter": "DonPasci"
        }
    ],
    "1544612": [
        {
            "ioc_value": "47.109.48.57:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-06-13 20:01:30",
            "last_seen_utc": "2026-06-30 11:21:17",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/47.109.48.57",
            "tags": "ALIBABA-CN-NET,AS37963,C2,censys,CobaltStrike,cs-watermark-987654321",
            "anonymous": "0",
            "reporter": "DonPasci"
        }
    ],
    "1544039": [
        {
            "ioc_value": "39.104.78.25:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-06-12 08:56:19",
            "last_seen_utc": "2026-06-30 11:21:18",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/39.104.78.25",
            "tags": "AS37963,C2,censys",
            "anonymous": "0",
            "reporter": "dyingbreeds_"
        }
    ],
    "1543390": [
        {
            "ioc_value": "8.155.0.238:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-06-10 16:01:13",
            "last_seen_utc": "2026-06-30 11:21:14",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/8.155.0.238",
            "tags": "ALIBABA-CN-NET,AS37963,C2,censys,CobaltStrike,cs-watermark-987654321",
            "anonymous": "0",
            "reporter": "DonPasci"
        }
    ],
    "1542784": [
        {
            "ioc_value": "162.248.224.223:7882",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.ransomhub",
            "malware_alias": null,
            "malware_printable": "RansomHub",
            "first_seen_utc": "2025-06-08 20:45:49",
            "last_seen_utc": "2026-06-30 10:43:41",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RansomHub",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1542783": [
        {
            "ioc_value": "162.248.224.223:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.ransomhub",
            "malware_alias": null,
            "malware_printable": "RansomHub",
            "first_seen_utc": "2025-06-08 20:45:48",
            "last_seen_utc": "2026-06-30 10:43:41",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RansomHub",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1542759": [
        {
            "ioc_value": "119.45.29.172:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-06-08 20:01:01",
            "last_seen_utc": "2026-06-30 11:21:36",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/119.45.29.172",
            "tags": "AS45090,C2,censys,CobaltStrike,cs-watermark-987654321,TENCENT-NET-AP",
            "anonymous": "0",
            "reporter": "DonPasci"
        }
    ],
    "1542057": [
        {
            "ioc_value": "172.81.131.230:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2025-06-06 20:01:59",
            "last_seen_utc": "2026-06-30 10:43:49",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/172.81.131.230",
            "tags": "AS27176,C2,censys,DATAWAGON,Mythic",
            "anonymous": "0",
            "reporter": "DonPasci"
        }
    ],
    "1541666": [
        {
            "ioc_value": "3.19.238.211:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.sliver",
            "malware_alias": null,
            "malware_printable": "Sliver",
            "first_seen_utc": "2025-06-06 16:01:21",
            "last_seen_utc": "2026-06-30 10:45:23",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/3.19.238.211",
            "tags": "AMAZON-02,AS16509,C2,censys,Sliver",
            "anonymous": "0",
            "reporter": "DonPasci"
        }
    ],
    "1541652": [
        {
            "ioc_value": "68.64.176.42:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-06-06 16:00:50",
            "last_seen_utc": "2026-06-30 11:21:16",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/68.64.176.42",
            "tags": "AS139659,C2,censys,CobaltStrike,cs-watermark-391144938,LUCID-AS-AP",
            "anonymous": "0",
            "reporter": "DonPasci"
        }
    ],
    "1541446": [
        {
            "ioc_value": "ns1.admlistdel.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-06-06 02:53:59",
            "last_seen_utc": "2026-06-30 10:46:25",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1538881": [
        {
            "ioc_value": "193.239.85.15:2083",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.havoc",
            "malware_alias": "Havokiz",
            "malware_printable": "Havoc",
            "first_seen_utc": "2025-06-02 12:01:04",
            "last_seen_utc": "2026-06-30 10:44:17",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/193.239.85.15",
            "tags": "AS9009,C2,censys,Havoc,M247",
            "anonymous": "0",
            "reporter": "DonPasci"
        }
    ],
    "1538799": [
        {
            "ioc_value": "47.109.198.8:6000",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-06-02 05:47:28",
            "last_seen_utc": "2026-06-30 10:47:09",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": "https://www.shodan.io/host/47.109.198.8#6000",
            "tags": "c2,cobaltstrike,cs-watermark-987654321,shodan",
            "anonymous": "0",
            "reporter": "juroots"
        }
    ],
    "1538358": [
        {
            "ioc_value": "54.38.94.225:8885",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.eye_pyramid",
            "malware_alias": null,
            "malware_printable": "Eye Pyramid",
            "first_seen_utc": "2025-06-01 08:52:56",
            "last_seen_utc": "2026-06-30 10:45:56",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,EyePyramid",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1537676": [
        {
            "ioc_value": "101.43.91.156:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-05-31 07:45:39",
            "last_seen_utc": "2026-06-30 11:21:39",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://x.com/abodovic1",
            "tags": "c2,censys,CobaltStrike",
            "anonymous": "0",
            "reporter": "Abodovic"
        }
    ],
    "1537678": [
        {
            "ioc_value": "59.110.7.32:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-05-31 07:45:38",
            "last_seen_utc": "2026-06-30 11:21:27",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://x.com/abodovic1",
            "tags": "c2,censys,CobaltStrike",
            "anonymous": "0",
            "reporter": "Abodovic"
        }
    ],
    "1536850": [
        {
            "ioc_value": "99.112.198.249:8080",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.deimos_c2",
            "malware_alias": null,
            "malware_printable": "DeimosC2",
            "first_seen_utc": "2025-05-30 08:53:21",
            "last_seen_utc": "2026-06-30 10:46:20",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "Deimos,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1536831": [
        {
            "ioc_value": "129.28.85.210:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-05-30 08:00:11",
            "last_seen_utc": "2026-06-30 11:21:22",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/129.28.85.210",
            "tags": "AS45090,C2,censys,CobaltStrike,cs-watermark-666666666,TENCENT-NET-AP",
            "anonymous": "0",
            "reporter": "DonPasci"
        }
    ],
    "1536730": [
        {
            "ioc_value": "111.229.4.108:2096",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-05-30 02:55:17",
            "last_seen_utc": "2026-06-30 10:46:33",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1536683": [
        {
            "ioc_value": "161.35.176.231:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.havoc",
            "malware_alias": "Havokiz",
            "malware_printable": "Havoc",
            "first_seen_utc": "2025-05-29 22:26:34",
            "last_seen_utc": "2026-06-30 10:43:41",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/161.35.176.231",
            "tags": "AS14061,C2,censys,DIGITALOCEAN-ASN,Havoc",
            "anonymous": "0",
            "reporter": "DonPasci"
        }
    ],
    "1533613": [
        {
            "ioc_value": "221.132.29.137:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2025-05-24 20:01:31",
            "last_seen_utc": "2026-06-30 10:45:18",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/221.132.29.137",
            "tags": "AS45899,C2,censys,Mythic,VNPT-AS-VN",
            "anonymous": "0",
            "reporter": "DonPasci"
        }
    ],
    "1533071": [
        {
            "ioc_value": "1.15.174.189:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-05-24 11:13:44",
            "last_seen_utc": "2026-06-30 11:21:25",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://x.com/abodovic1",
            "tags": "c2,censys,CobaltStrike",
            "anonymous": "0",
            "reporter": "Abodovic"
        }
    ],
    "1532332": [
        {
            "ioc_value": "8.140.239.162:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-05-23 05:34:51",
            "last_seen_utc": "2026-06-30 11:21:26",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://x.com/abodovic1",
            "tags": "c2,censys,CobaltStrike",
            "anonymous": "0",
            "reporter": "Abodovic"
        }
    ],
    "1532306": [
        {
            "ioc_value": "178.217.98.23:8080",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.chaos",
            "malware_alias": "FakeRyuk,RyukJoke,Yashma",
            "malware_printable": "Chaos",
            "first_seen_utc": "2025-05-22 20:01:48",
            "last_seen_utc": "2026-06-30 10:43:54",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/178.217.98.23",
            "tags": "AS48282,censys,Chaos,panel,VDSINA-AS",
            "anonymous": "0",
            "reporter": "DonPasci"
        }
    ],
    "1531654": [
        {
            "ioc_value": "122.10.49.137:808",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-05-21 16:00:35",
            "last_seen_utc": "2026-06-30 10:46:42",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/122.10.49.137",
            "tags": "AS134548,C2,censys,CobaltStrike,cs-watermark-1234567890,DXTL-HK",
            "anonymous": "0",
            "reporter": "DonPasci"
        }
    ],
    "1527752": [
        {
            "ioc_value": "117.72.206.39:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-05-21 08:00:35",
            "last_seen_utc": "2026-06-30 11:21:36",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/117.72.206.39",
            "tags": "AS141679,C2,censys,CHINATELECOM-IDC-BTHBD-AP,CobaltStrike,cs-watermark-666666666",
            "anonymous": "0",
            "reporter": "DonPasci"
        }
    ],
    "1527457": [
        {
            "ioc_value": "122.10.25.26:808",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-05-21 00:00:32",
            "last_seen_utc": "2026-06-30 10:46:41",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/122.10.25.26",
            "tags": "AS134548,C2,censys,CobaltStrike,cs-watermark-1234567890,DXTL-HK",
            "anonymous": "0",
            "reporter": "DonPasci"
        }
    ],
    "1526357": [
        {
            "ioc_value": "106.54.61.188:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-05-20 06:37:42",
            "last_seen_utc": "2026-06-30 11:21:23",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-987654321",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1525250": [
        {
            "ioc_value": "124.223.114.203:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-05-18 15:34:22",
            "last_seen_utc": "2026-06-30 11:21:22",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://intelinsights.substack.com/p/from-939-to-85-hunting-cobalt-strike",
            "tags": "censys,cobaltstrike",
            "anonymous": "0",
            "reporter": "orlof_v"
        }
    ],
    "1524773": [
        {
            "ioc_value": "167.99.51.2:31337",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.sliver",
            "malware_alias": null,
            "malware_printable": "Sliver",
            "first_seen_utc": "2025-05-17 14:42:08",
            "last_seen_utc": "2026-06-30 10:43:45",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": "https://www.shodan.io/host/167.99.51.2#31337",
            "tags": "c2,shodan,sliver",
            "anonymous": "0",
            "reporter": "juroots"
        }
    ],
    "1524641": [
        {
            "ioc_value": "167.99.51.2:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.sliver",
            "malware_alias": null,
            "malware_printable": "Sliver",
            "first_seen_utc": "2025-05-17 08:00:32",
            "last_seen_utc": "2026-06-30 10:43:46",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/167.99.51.2",
            "tags": "AS14061,C2,censys,DIGITALOCEAN-ASN,Sliver",
            "anonymous": "0",
            "reporter": "DonPasci"
        }
    ],
    "1524319": [
        {
            "ioc_value": "101.35.109.246:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-05-17 06:26:23",
            "last_seen_utc": "2026-06-30 11:21:24",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": "https://www.shodan.io/host/101.35.109.246#443",
            "tags": "c2,cobaltstrike,cs-watermark-987654321,shodan",
            "anonymous": "0",
            "reporter": "juroots"
        }
    ],
    "1523466": [
        {
            "ioc_value": "103.171.35.26:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-05-15 21:14:57",
            "last_seen_utc": "2026-06-30 11:21:24",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://x.com/abodovic1",
            "tags": "c2,censys,cobalt_strike",
            "anonymous": "0",
            "reporter": "Abodovic"
        }
    ],
    "1523462": [
        {
            "ioc_value": "60.204.169.16:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-05-15 21:14:47",
            "last_seen_utc": "2026-06-30 11:21:26",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://x.com/abodovic1",
            "tags": "c2,censys,cobalt_strike",
            "anonymous": "0",
            "reporter": "Abodovic"
        }
    ],
    "1523434": [
        {
            "ioc_value": "179.43.186.223:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-05-15 21:13:56",
            "last_seen_utc": "2026-06-30 11:21:20",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://x.com/abodovic1",
            "tags": "c2,censys,cobalt_strike",
            "anonymous": "0",
            "reporter": "Abodovic"
        }
    ],
    "1523246": [
        {
            "ioc_value": "8.134.70.73:7777",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-05-15 05:25:01",
            "last_seen_utc": "2026-06-30 09:54:11",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-987654321",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1521639": [
        {
            "ioc_value": "8.134.70.73:88",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-05-13 14:08:42",
            "last_seen_utc": "2026-06-30 10:47:15",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "beacon,c2,Cobalt Strike,CobaltStrike",
            "anonymous": "0",
            "reporter": "pancak3lullz"
        }
    ],
    "1520343": [
        {
            "ioc_value": "38.54.112.234:53",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-05-12 20:58:42",
            "last_seen_utc": "2026-06-30 10:46:59",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1520342": [
        {
            "ioc_value": "asusupdateserver.asuscomm.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-05-12 20:55:40",
            "last_seen_utc": "2026-06-30 10:46:21",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1519438": [
        {
            "ioc_value": "47.109.190.151:60000",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2025-05-11 06:11:06",
            "last_seen_utc": "2026-06-30 10:45:46",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/47.109.190.151",
            "tags": "AS37963,censys,Viper",
            "anonymous": "0",
            "reporter": "dyingbreeds_"
        }
    ],
    "1519450": [
        {
            "ioc_value": "https://topguningit.com/test/",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.latrodectus",
            "malware_alias": "BLACKWIDOW,IceNova,Latrodectus,Lotus",
            "malware_printable": "Latrodectus",
            "first_seen_utc": "2025-05-11 05:00:17",
            "last_seen_utc": "2026-06-30 11:11:08",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": null,
            "anonymous": "0",
            "reporter": "Rony"
        }
    ],
    "1518529": [
        {
            "ioc_value": "47.108.140.10:60000",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2025-05-09 05:36:03",
            "last_seen_utc": "2026-06-30 10:45:46",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/47.108.140.10",
            "tags": "AS37963,censys,Viper",
            "anonymous": "0",
            "reporter": "dyingbreeds_"
        }
    ],
    "1518023": [
        {
            "ioc_value": "106.52.207.50:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-05-07 13:00:19",
            "last_seen_utc": "2026-06-30 10:46:32",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1513590": [
        {
            "ioc_value": "54.38.94.225:8882",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.eye_pyramid",
            "malware_alias": null,
            "malware_printable": "Eye Pyramid",
            "first_seen_utc": "2025-04-29 08:53:29",
            "last_seen_utc": "2026-06-30 10:45:55",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,EyePyramid",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1513585": [
        {
            "ioc_value": "107.143.144.154:8080",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.deimos_c2",
            "malware_alias": null,
            "malware_printable": "DeimosC2",
            "first_seen_utc": "2025-04-29 08:43:42",
            "last_seen_utc": "2026-06-30 10:43:12",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "Deimos,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1511186": [
        {
            "ioc_value": "23.254.215.118:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.havoc",
            "malware_alias": "Havokiz",
            "malware_printable": "Havoc",
            "first_seen_utc": "2025-04-25 08:10:27",
            "last_seen_utc": "2026-06-30 10:45:20",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": "https://www.shodan.io/host/23.254.215.118#443",
            "tags": "c2,havoc,shodan",
            "anonymous": "0",
            "reporter": "juroots"
        }
    ],
    "1509966": [
        {
            "ioc_value": "167.71.13.103:31337",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.sliver",
            "malware_alias": null,
            "malware_printable": "Sliver",
            "first_seen_utc": "2025-04-22 12:21:47",
            "last_seen_utc": "2026-06-30 10:43:45",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": "https://www.shodan.io/host/167.71.13.103#31337",
            "tags": "c2,shodan,sliver",
            "anonymous": "0",
            "reporter": "juroots"
        }
    ],
    "1492480": [
        {
            "ioc_value": "113.45.253.80:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-04-16 16:01:35",
            "last_seen_utc": "2026-06-30 10:46:35",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/113.45.253.80",
            "tags": "AS55990,C2,censys,CobaltStrike,cs-watermark-666666666,HWCSNET",
            "anonymous": "0",
            "reporter": "DonPasci"
        }
    ],
    "1492012": [
        {
            "ioc_value": "47.83.134.97:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.havoc",
            "malware_alias": "Havokiz",
            "malware_printable": "Havoc",
            "first_seen_utc": "2025-04-15 16:02:30",
            "last_seen_utc": "2026-06-30 10:45:47",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/47.83.134.97",
            "tags": "ALIBABA-CN-NET,AS45102,C2,censys,Havoc",
            "anonymous": "0",
            "reporter": "DonPasci"
        }
    ],
    "1491748": [
        {
            "ioc_value": "193.142.146.70:56004",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2025-04-15 04:01:37",
            "last_seen_utc": "2026-06-30 10:44:16",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/193.142.146.70",
            "tags": "AS213438,C2,censys,COLOCATEL-INC,RAT,Remcos",
            "anonymous": "0",
            "reporter": "DonPasci"
        }
    ],
    "1486437": [
        {
            "ioc_value": "167.71.13.103:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.sliver",
            "malware_alias": null,
            "malware_printable": "Sliver",
            "first_seen_utc": "2025-04-10 05:55:49",
            "last_seen_utc": "2026-06-30 10:43:45",
            "confidence_level": 90,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/167.71.13.103",
            "tags": "AS14061,C2,censys,DIGITALOCEAN-ASN",
            "anonymous": "0",
            "reporter": "dyingbreeds_"
        }
    ],
    "1484905": [
        {
            "ioc_value": "3.132.75.97:55520",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "apk.vo1d",
            "malware_alias": null,
            "malware_printable": "vo1d",
            "first_seen_utc": "2025-04-05 05:50:38",
            "last_seen_utc": "2026-06-30 00:29:39",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "redirector,Vo1d",
            "anonymous": "0",
            "reporter": "Bitsight"
        }
    ],
    "1463173": [
        {
            "ioc_value": "38.46.218.36:9999",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "apk.vo1d",
            "malware_alias": null,
            "malware_printable": "vo1d",
            "first_seen_utc": "2025-04-02 10:08:14",
            "last_seen_utc": "2026-06-30 11:10:04",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "Vo1d",
            "anonymous": "0",
            "reporter": "Bitsight"
        }
    ],
    "1463174": [
        {
            "ioc_value": "38.46.218.38:9999",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "apk.vo1d",
            "malware_alias": null,
            "malware_printable": "vo1d",
            "first_seen_utc": "2025-04-02 10:08:13",
            "last_seen_utc": "2026-06-30 07:35:54",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "Vo1d",
            "anonymous": "0",
            "reporter": "Bitsight"
        }
    ],
    "1463176": [
        {
            "ioc_value": "38.46.218.39:9999",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "apk.vo1d",
            "malware_alias": null,
            "malware_printable": "vo1d",
            "first_seen_utc": "2025-04-02 10:08:12",
            "last_seen_utc": "2026-06-30 10:09:00",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "Vo1d",
            "anonymous": "0",
            "reporter": "Bitsight"
        }
    ],
    "1463152": [
        {
            "ioc_value": "200.107.126.227:3085",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.netsupportmanager_rat",
            "malware_alias": "NetSupport",
            "malware_printable": "NetSupportManager RAT",
            "first_seen_utc": "2025-04-02 08:01:26",
            "last_seen_utc": "2026-06-30 10:44:27",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/200.107.126.227",
            "tags": "AS14754,C2,censys,Netsupport,RAT,TELECOMUNICACIONES",
            "anonymous": "0",
            "reporter": "DonPasci"
        }
    ],
    "1462468": [
        {
            "ioc_value": "43.143.229.126:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-04-01 10:24:30",
            "last_seen_utc": "2026-06-30 11:21:17",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-666666666",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1459722": [
        {
            "ioc_value": "193.142.146.70:2404",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2025-03-28 04:00:35",
            "last_seen_utc": "2026-06-30 10:44:16",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/193.142.146.70",
            "tags": "AS213438,C2,censys,COLOCATEL-INC,RAT,Remcos",
            "anonymous": "0",
            "reporter": "DonPasci"
        }
    ],
    "1458716": [
        {
            "ioc_value": "ehchq7m7rpvdr.cfc-execute.bj.baidubce.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-03-25 22:53:24",
            "last_seen_utc": "2026-06-30 11:21:14",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1457513": [
        {
            "ioc_value": "103.142.147.17:60000",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2025-03-24 06:29:33",
            "last_seen_utc": "2026-06-30 10:43:08",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/103.142.147.17",
            "tags": "AS135581,censys,Viper",
            "anonymous": "0",
            "reporter": "dyingbreeds_"
        }
    ],
    "1454148": [
        {
            "ioc_value": "103.142.147.18:60000",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2025-03-22 20:43:16",
            "last_seen_utc": "2026-06-30 10:43:08",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1454149": [
        {
            "ioc_value": "103.142.147.19:60000",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2025-03-22 20:43:16",
            "last_seen_utc": "2026-06-30 10:43:08",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1452404": [
        {
            "ioc_value": "47.116.208.81:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-03-20 12:01:27",
            "last_seen_utc": "2026-06-30 11:21:28",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/47.116.208.81",
            "tags": "ALIBABA-CN-NET,AS37963,C2,censys,CobaltStrike,cs-watermark-666666666",
            "anonymous": "0",
            "reporter": "DonPasci"
        }
    ],
    "1446559": [
        {
            "ioc_value": "www.dyshop.online",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-03-12 02:47:28",
            "last_seen_utc": "2026-06-30 10:46:28",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1446149": [
        {
            "ioc_value": "210.2.169.213:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.havoc",
            "malware_alias": "Havokiz",
            "malware_printable": "Havoc",
            "first_seen_utc": "2025-03-11 12:01:13",
            "last_seen_utc": "2026-06-30 10:44:34",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/210.2.169.213",
            "tags": "AS23966,C2,censys,Havoc,LDN-AS-PK",
            "anonymous": "0",
            "reporter": "DonPasci"
        }
    ],
    "1441769": [
        {
            "ioc_value": "51.81.171.234:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.havoc",
            "malware_alias": "Havokiz",
            "malware_printable": "Havoc",
            "first_seen_utc": "2025-03-06 04:01:35",
            "last_seen_utc": "2026-06-30 10:45:54",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/51.81.171.234",
            "tags": "AS16276,C2,censys,Havoc,OVH",
            "anonymous": "0",
            "reporter": "DonPasci"
        }
    ],
    "1440611": [
        {
            "ioc_value": "43.153.2.113:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-03-04 00:00:37",
            "last_seen_utc": "2026-06-30 10:47:04",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/43.153.2.113",
            "tags": "AS132203,C2,censys,CobaltStrike,cs-watermark-100000,TENCENT-NET-AP-CN",
            "anonymous": "0",
            "reporter": "DonPasci"
        }
    ],
    "1440087": [
        {
            "ioc_value": "15.204.95.228:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.havoc",
            "malware_alias": "Havokiz",
            "malware_printable": "Havoc",
            "first_seen_utc": "2025-03-03 12:01:16",
            "last_seen_utc": "2026-06-30 10:43:31",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/15.204.95.228",
            "tags": "AS16276,C2,censys,Havoc,OVH",
            "anonymous": "0",
            "reporter": "DonPasci"
        }
    ],
    "1439776": [
        {
            "ioc_value": "150.5.174.231:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2025-03-02 20:01:03",
            "last_seen_utc": "2026-06-30 10:43:32",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/150.5.174.231",
            "tags": "AS150436,BYTEPLUS-AS-AP,C2,censys,Mythic",
            "anonymous": "0",
            "reporter": "DonPasci"
        }
    ],
    "1439368": [
        {
            "ioc_value": "54.38.94.225:8887",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.eye_pyramid",
            "malware_alias": null,
            "malware_printable": "Eye Pyramid",
            "first_seen_utc": "2025-03-02 08:46:23",
            "last_seen_utc": "2026-06-30 10:45:56",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,EyePyramid",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1439168": [
        {
            "ioc_value": "47.129.171.26:53",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-03-01 20:47:46",
            "last_seen_utc": "2026-06-30 10:47:10",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1439166": [
        {
            "ioc_value": "ns.1.3.0o0.foo",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-03-01 20:46:51",
            "last_seen_utc": "2026-06-30 10:46:25",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1439167": [
        {
            "ioc_value": "ns.1.4.0o0.foo",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-03-01 20:46:51",
            "last_seen_utc": "2026-06-30 10:46:25",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1428313": [
        {
            "ioc_value": "8.134.51.218:24444",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-02-20 12:49:39",
            "last_seen_utc": "2026-06-30 10:47:15",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1424136": [
        {
            "ioc_value": "118.24.121.59:60000",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2025-02-20 06:12:03",
            "last_seen_utc": "2026-06-30 10:43:18",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/118.24.121.59",
            "tags": "AS45090,censys,Viper",
            "anonymous": "0",
            "reporter": "dyingbreeds_"
        }
    ],
    "1411885": [
        {
            "ioc_value": "192.52.167.140:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.netsupportmanager_rat",
            "malware_alias": "NetSupport",
            "malware_printable": "NetSupportManager RAT",
            "first_seen_utc": "2025-02-14 00:01:07",
            "last_seen_utc": "2026-06-30 10:44:15",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/192.52.167.140",
            "tags": "AS199959,C2,censys,CROWNCLOUD,Netsupport,RAT",
            "anonymous": "0",
            "reporter": "DonPasci"
        }
    ],
    "1409420": [
        {
            "ioc_value": "103.215.81.156:60000",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2025-02-10 20:43:10",
            "last_seen_utc": "2026-06-30 10:43:09",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1405307": [
        {
            "ioc_value": "https://apworsindos.com/test/",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.latrodectus",
            "malware_alias": "BLACKWIDOW,IceNova,Latrodectus,Lotus",
            "malware_printable": "Latrodectus",
            "first_seen_utc": "2025-02-06 13:54:51",
            "last_seen_utc": "2026-06-30 11:20:12",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": null,
            "anonymous": "0",
            "reporter": "Rony"
        }
    ],
    "1405308": [
        {
            "ioc_value": "https://reminasolirol.com/test/",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.latrodectus",
            "malware_alias": "BLACKWIDOW,IceNova,Latrodectus,Lotus",
            "malware_printable": "Latrodectus",
            "first_seen_utc": "2025-02-06 13:54:51",
            "last_seen_utc": "2026-06-30 11:12:10",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": null,
            "anonymous": "0",
            "reporter": "Rony"
        }
    ],
    "1404178": [
        {
            "ioc_value": "20.74.209.192:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-02-05 22:51:06",
            "last_seen_utc": "2026-06-30 11:21:18",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1402495": [
        {
            "ioc_value": "62.60.226.42:43155",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2025-02-02 16:00:48",
            "last_seen_utc": "2026-06-30 10:45:57",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/62.60.226.42",
            "tags": "AS214351,C2,censys,FEMOIT,RAT,Remcos",
            "anonymous": "0",
            "reporter": "DonPasci"
        }
    ],
    "1402480": [
        {
            "ioc_value": "service-rchqbzvz-1301033415.sh.tencentapigw.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-02-02 12:49:35",
            "last_seen_utc": "2026-06-30 11:21:13",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1398921": [
        {
            "ioc_value": "62.60.226.6:43155",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2025-02-01 04:00:38",
            "last_seen_utc": "2026-06-30 10:45:57",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/62.60.226.6",
            "tags": "AS214351,C2,censys,FEMOIT,RAT,Remcos",
            "anonymous": "0",
            "reporter": "DonPasci"
        }
    ],
    "1398820": [
        {
            "ioc_value": "162.252.173.12:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.ransomhub",
            "malware_alias": null,
            "malware_printable": "RansomHub",
            "first_seen_utc": "2025-01-31 13:44:30",
            "last_seen_utc": "2026-06-30 10:43:42",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RansomHub",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1398810": [
        {
            "ioc_value": "162.252.173.12:8000",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.ransomhub",
            "malware_alias": null,
            "malware_printable": "RansomHub",
            "first_seen_utc": "2025-01-31 12:01:38",
            "last_seen_utc": "2026-06-30 10:43:42",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/162.252.173.12",
            "tags": "AS9009,backdoor,C2,censys,M247,Ransomhub",
            "anonymous": "0",
            "reporter": "DonPasci"
        }
    ],
    "1398657": [
        {
            "ioc_value": "8.134.108.73:60000",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2025-01-31 07:01:30",
            "last_seen_utc": "2026-06-30 10:46:06",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/8.134.108.73",
            "tags": "AS37963,censys,Viper",
            "anonymous": "0",
            "reporter": "dyingbreeds_"
        }
    ],
    "1396136": [
        {
            "ioc_value": "38.146.28.93:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.ransomhub",
            "malware_alias": null,
            "malware_printable": "RansomHub",
            "first_seen_utc": "2025-01-30 08:47:19",
            "last_seen_utc": "2026-06-30 10:45:29",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RansomHub",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1396135": [
        {
            "ioc_value": "185.33.86.15:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.ransomhub",
            "malware_alias": null,
            "malware_printable": "RansomHub",
            "first_seen_utc": "2025-01-30 08:45:48",
            "last_seen_utc": "2026-06-30 10:44:09",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RansomHub",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1396130": [
        {
            "ioc_value": "38.146.28.93:8000",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.ransomhub",
            "malware_alias": null,
            "malware_printable": "RansomHub",
            "first_seen_utc": "2025-01-30 08:01:38",
            "last_seen_utc": "2026-06-30 10:45:29",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/38.146.28.93",
            "tags": "AS174,backdoor,C2,censys,COGENT-174,Ransomhub",
            "anonymous": "0",
            "reporter": "DonPasci"
        }
    ],
    "1396102": [
        {
            "ioc_value": "185.33.86.15:8000",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.ransomhub",
            "malware_alias": null,
            "malware_printable": "RansomHub",
            "first_seen_utc": "2025-01-30 04:01:31",
            "last_seen_utc": "2026-06-30 10:44:10",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/185.33.86.15",
            "tags": "AS202015,backdoor,C2,censys,HZ-US-AS,Ransomhub",
            "anonymous": "0",
            "reporter": "DonPasci"
        }
    ],
    "1394408": [
        {
            "ioc_value": "54.38.94.225:8883",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.eye_pyramid",
            "malware_alias": null,
            "malware_printable": "Eye Pyramid",
            "first_seen_utc": "2025-01-26 08:46:00",
            "last_seen_utc": "2026-06-30 10:45:55",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,EyePyramid",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1394158": [
        {
            "ioc_value": "54.38.94.225:8880",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.eye_pyramid",
            "malware_alias": null,
            "malware_printable": "Eye Pyramid",
            "first_seen_utc": "2025-01-25 20:47:04",
            "last_seen_utc": "2026-06-30 10:45:55",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,EyePyramid",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1391610": [
        {
            "ioc_value": "45.82.85.50:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.ransomhub",
            "malware_alias": null,
            "malware_printable": "RansomHub",
            "first_seen_utc": "2025-01-22 17:46:05",
            "last_seen_utc": "2026-06-30 10:45:43",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RansomHub",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1386236": [
        {
            "ioc_value": "https://135.181.31.18",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2025-01-18 16:10:00",
            "last_seen_utc": "2026-06-30 11:10:59",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": null,
            "anonymous": "0",
            "reporter": "Gi7w0rm"
        }
    ],
    "1384933": [
        {
            "ioc_value": "38.180.81.153:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.ransomhub",
            "malware_alias": null,
            "malware_printable": "RansomHub",
            "first_seen_utc": "2025-01-17 09:15:21",
            "last_seen_utc": "2026-06-30 10:45:29",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RansomHub",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1384934": [
        {
            "ioc_value": "38.180.81.153:8000",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.ransomhub",
            "malware_alias": null,
            "malware_printable": "RansomHub",
            "first_seen_utc": "2025-01-17 09:15:21",
            "last_seen_utc": "2026-06-30 10:45:30",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RansomHub",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1384921": [
        {
            "ioc_value": "167.99.139.231:8004",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.eye_pyramid",
            "malware_alias": null,
            "malware_printable": "Eye Pyramid",
            "first_seen_utc": "2025-01-17 09:14:13",
            "last_seen_utc": "2026-06-30 10:43:45",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,EyePyramid",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1384912": [
        {
            "ioc_value": "185.174.101.240:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.ransomhub",
            "malware_alias": null,
            "malware_printable": "RansomHub",
            "first_seen_utc": "2025-01-17 09:13:19",
            "last_seen_utc": "2026-06-30 10:44:04",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RansomHub",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1384913": [
        {
            "ioc_value": "185.174.101.240:8000",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.ransomhub",
            "malware_alias": null,
            "malware_printable": "RansomHub",
            "first_seen_utc": "2025-01-17 09:13:19",
            "last_seen_utc": "2026-06-30 10:44:04",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RansomHub",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1384914": [
        {
            "ioc_value": "185.174.101.69:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.ransomhub",
            "malware_alias": null,
            "malware_printable": "RansomHub",
            "first_seen_utc": "2025-01-17 09:13:19",
            "last_seen_utc": "2026-06-30 10:44:04",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RansomHub",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1384915": [
        {
            "ioc_value": "185.174.101.69:8000",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.ransomhub",
            "malware_alias": null,
            "malware_printable": "RansomHub",
            "first_seen_utc": "2025-01-17 09:13:19",
            "last_seen_utc": "2026-06-30 10:44:04",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RansomHub",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1384908": [
        {
            "ioc_value": "108.181.115.171:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.ransomhub",
            "malware_alias": null,
            "malware_printable": "RansomHub",
            "first_seen_utc": "2025-01-17 09:12:27",
            "last_seen_utc": "2026-06-30 10:43:15",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RansomHub",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1384909": [
        {
            "ioc_value": "108.181.115.171:8000",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.ransomhub",
            "malware_alias": null,
            "malware_printable": "RansomHub",
            "first_seen_utc": "2025-01-17 09:12:27",
            "last_seen_utc": "2026-06-30 10:43:15",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RansomHub",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1384910": [
        {
            "ioc_value": "108.181.182.143:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.ransomhub",
            "malware_alias": null,
            "malware_printable": "RansomHub",
            "first_seen_utc": "2025-01-17 09:12:27",
            "last_seen_utc": "2026-06-30 10:43:15",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RansomHub",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1384911": [
        {
            "ioc_value": "108.181.182.143:8000",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.ransomhub",
            "malware_alias": null,
            "malware_printable": "RansomHub",
            "first_seen_utc": "2025-01-17 09:12:27",
            "last_seen_utc": "2026-06-30 10:43:16",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RansomHub",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1384790": [
        {
            "ioc_value": "at1.227api.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-01-17 07:45:55",
            "last_seen_utc": "2026-06-30 10:46:21",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1384791": [
        {
            "ioc_value": "at2.227api.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-01-17 07:45:55",
            "last_seen_utc": "2026-06-30 10:46:21",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1384792": [
        {
            "ioc_value": "at3.227api.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-01-17 07:45:55",
            "last_seen_utc": "2026-06-30 10:46:21",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1381420": [
        {
            "ioc_value": "77.238.236.123:18300",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.deimos_c2",
            "malware_alias": null,
            "malware_printable": "DeimosC2",
            "first_seen_utc": "2025-01-10 13:55:47",
            "last_seen_utc": "2026-06-30 10:46:05",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "Deimos,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1381067": [
        {
            "ioc_value": "112.5.58.181:7001",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.deimos_c2",
            "malware_alias": null,
            "malware_printable": "DeimosC2",
            "first_seen_utc": "2025-01-10 13:43:51",
            "last_seen_utc": "2026-06-30 10:43:17",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "Deimos,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1380875": [
        {
            "ioc_value": "update.mloadspring.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-01-10 09:14:38",
            "last_seen_utc": "2026-06-30 10:46:28",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1380878": [
        {
            "ioc_value": "upgrade.mloadspring.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-01-10 09:14:38",
            "last_seen_utc": "2026-06-30 10:46:28",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1380837": [
        {
            "ioc_value": "ns3.akawowfast.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-01-10 09:14:30",
            "last_seen_utc": "2026-06-30 10:46:27",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1380841": [
        {
            "ioc_value": "ns3.translategoos.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-01-10 09:14:30",
            "last_seen_utc": "2026-06-30 10:46:27",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1380833": [
        {
            "ioc_value": "ns2.translategoos.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-01-10 09:14:29",
            "last_seen_utc": "2026-06-30 10:46:27",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1380818": [
        {
            "ioc_value": "ns2.cmbchina.top",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-01-10 09:14:27",
            "last_seen_utc": "2026-06-30 10:46:26",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1380815": [
        {
            "ioc_value": "ns2.akawowfast.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-01-10 09:14:26",
            "last_seen_utc": "2026-06-30 10:46:26",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1380811": [
        {
            "ioc_value": "ns1.translategoos.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-01-10 09:14:25",
            "last_seen_utc": "2026-06-30 10:46:26",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1380783": [
        {
            "ioc_value": "ns1.akawowfast.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-01-10 09:14:20",
            "last_seen_utc": "2026-06-30 10:46:25",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1380787": [
        {
            "ioc_value": "ns1.cmbchina.top",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-01-10 09:14:20",
            "last_seen_utc": "2026-06-30 10:46:25",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1380635": [
        {
            "ioc_value": "8.219.78.159:53",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-01-10 08:18:57",
            "last_seen_utc": "2026-06-30 10:47:18",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1380629": [
        {
            "ioc_value": "70.34.196.238:53",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-01-10 08:18:43",
            "last_seen_utc": "2026-06-30 10:47:14",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1380607": [
        {
            "ioc_value": "47.98.134.252:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-01-10 08:18:28",
            "last_seen_utc": "2026-06-30 11:21:16",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1380569": [
        {
            "ioc_value": "38.54.115.233:8880",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-01-10 08:17:37",
            "last_seen_utc": "2026-06-30 10:46:59",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1380533": [
        {
            "ioc_value": "207.148.68.118:53",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-01-10 08:17:20",
            "last_seen_utc": "2026-06-30 10:46:56",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1380446": [
        {
            "ioc_value": "139.180.189.95:53",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-01-10 08:16:21",
            "last_seen_utc": "2026-06-30 10:46:45",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1380421": [
        {
            "ioc_value": "118.25.91.151:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-01-10 08:15:44",
            "last_seen_utc": "2026-06-30 11:21:36",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1380420": [
        {
            "ioc_value": "117.72.39.83:43872",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-01-10 08:15:43",
            "last_seen_utc": "2026-06-30 10:46:39",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1380232": [
        {
            "ioc_value": "38.207.179.146:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2025-01-10 04:04:28",
            "last_seen_utc": "2026-06-30 10:45:30",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/38.207.179.146",
            "tags": "AS139659,C2,censys,LUCID-AS-AP,Mythic",
            "anonymous": "0",
            "reporter": "DonPasci"
        }
    ],
    "1376919": [
        {
            "ioc_value": "86.124.168.255:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "js.fakeupdates",
            "malware_alias": "FakeUpdate,GhoLoader,SocGholish",
            "malware_printable": "FAKEUPDATES",
            "first_seen_utc": "2025-01-01 04:03:19",
            "last_seen_utc": "2026-06-30 10:46:12",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/86.124.168.255",
            "tags": "AS8708,c2,censys,RCS-RDS,SocGholish",
            "anonymous": "0",
            "reporter": "DonPasci"
        }
    ],
    "1359401": [
        {
            "ioc_value": "8.153.97.202:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2024-12-24 08:00:43",
            "last_seen_utc": "2026-06-30 11:21:13",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/8.153.97.202",
            "tags": "ALIBABA-CN-NET,AS37963,C2,censys,CobaltStrike,cs-watermark-987654321",
            "anonymous": "0",
            "reporter": "DonPasci"
        }
    ],
    "1359309": [
        {
            "ioc_value": "91.199.154.103:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.sliver",
            "malware_alias": null,
            "malware_printable": "Sliver",
            "first_seen_utc": "2024-12-24 04:01:34",
            "last_seen_utc": "2026-06-30 10:46:16",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/91.199.154.103",
            "tags": "AS62212,C2,censys,Sliver",
            "anonymous": "0",
            "reporter": "DonPasci"
        }
    ],
    "1358941": [
        {
            "ioc_value": "112.124.71.123:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2024-12-21 16:00:27",
            "last_seen_utc": "2026-06-29 17:05:06",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/112.124.71.123",
            "tags": "ALIBABA-CN-NET,AS37963,C2,censys,CobaltStrike,cs-watermark-987654321",
            "anonymous": "0",
            "reporter": "DonPasci"
        }
    ],
    "1358842": [
        {
            "ioc_value": "149.28.61.158:8773",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2024-12-20 16:01:53",
            "last_seen_utc": "2026-06-30 10:43:31",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/149.28.61.158",
            "tags": "AS-VULTR,AS20473,C2,censys,Mythic",
            "anonymous": "0",
            "reporter": "DonPasci"
        }
    ],
    "1357389": [
        {
            "ioc_value": "45.56.69.210:3333",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2024-12-16 16:01:41",
            "last_seen_utc": "2026-06-30 10:45:39",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/45.56.69.210",
            "tags": "AKAMAI-LINODE-AP,AS63949,censys,EvilGoPhish,panel,Phishing",
            "anonymous": "0",
            "reporter": "DonPasci"
        }
    ],
    "1356002": [
        {
            "ioc_value": "113.44.90.0:60000",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2024-12-12 06:21:40",
            "last_seen_utc": "2026-06-30 10:43:17",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/113.44.90.0",
            "tags": "AS55990,censys,Viper",
            "anonymous": "0",
            "reporter": "dyingbreeds_"
        }
    ],
    "1352876": [
        {
            "ioc_value": "139.196.126.161:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2024-12-06 07:36:52",
            "last_seen_utc": "2026-06-30 11:21:34",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-987654321",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1350210": [
        {
            "ioc_value": "117.72.39.83:4433",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2024-12-02 21:01:15",
            "last_seen_utc": "2026-06-30 10:46:39",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/117.72.39.83",
            "tags": "AS141679,C2,censys",
            "anonymous": "0",
            "reporter": "dyingbreeds_"
        }
    ],
    "1349957": [
        {
            "ioc_value": "117.72.39.83:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2024-12-01 07:43:42",
            "last_seen_utc": "2026-06-30 10:46:39",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-391144938",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1349567": [
        {
            "ioc_value": "216.118.101.24:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2024-11-30 20:06:19",
            "last_seen_utc": "2026-06-30 10:44:58",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "censys,panel,Viper",
            "anonymous": "0",
            "reporter": "NDA0E"
        }
    ],
    "1349531": [
        {
            "ioc_value": "216.118.101.132:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2024-11-30 20:06:11",
            "last_seen_utc": "2026-06-30 10:44:42",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "censys,panel,Viper",
            "anonymous": "0",
            "reporter": "NDA0E"
        }
    ],
    "1349510": [
        {
            "ioc_value": "216.118.101.199:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2024-11-30 20:06:08",
            "last_seen_utc": "2026-06-30 10:44:52",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "censys,panel,Viper",
            "anonymous": "0",
            "reporter": "NDA0E"
        }
    ],
    "1349492": [
        {
            "ioc_value": "216.118.101.216:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2024-11-30 20:06:04",
            "last_seen_utc": "2026-06-30 10:44:55",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "censys,panel,Viper",
            "anonymous": "0",
            "reporter": "NDA0E"
        }
    ],
    "1349438": [
        {
            "ioc_value": "216.118.101.54:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2024-11-30 20:05:51",
            "last_seen_utc": "2026-06-30 10:45:09",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "censys,panel,Viper",
            "anonymous": "0",
            "reporter": "NDA0E"
        }
    ],
    "1348902": [
        {
            "ioc_value": "216.118.101.108:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2024-11-29 13:56:30",
            "last_seen_utc": "2026-06-30 10:44:38",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "Viper",
            "anonymous": "0",
            "reporter": "dyingbreeds_"
        }
    ],
    "1348295": [
        {
            "ioc_value": "47.90.142.15:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2024-11-27 19:47:54",
            "last_seen_utc": "2026-06-30 11:21:27",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "censys,CobaltStrike",
            "anonymous": "0",
            "reporter": "NDA0E"
        }
    ],
    "1348026": [
        {
            "ioc_value": "8.137.114.210:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2024-11-27 19:47:07",
            "last_seen_utc": "2026-06-30 11:21:15",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "censys,CobaltStrike",
            "anonymous": "0",
            "reporter": "NDA0E"
        }
    ],
    "1346058": [
        {
            "ioc_value": "servicioremotoempresas.info",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2024-11-19 18:00:05",
            "last_seen_utc": "2026-06-30 11:21:39",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1340201": [
        {
            "ioc_value": "146.70.158.198:31337",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.sliver",
            "malware_alias": null,
            "malware_printable": "Sliver",
            "first_seen_utc": "2024-10-30 17:53:55",
            "last_seen_utc": "2026-06-30 10:43:27",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://github.com/TheRavenFile/Daily-Hunt/blob/main/Sliver%20C2",
            "tags": "c2,sliver,sliverc2",
            "anonymous": "0",
            "reporter": "TheRavenFile"
        }
    ],
    "1338675": [
        {
            "ioc_value": "https://stripplasst.com/live/",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.latrodectus",
            "malware_alias": "BLACKWIDOW,IceNova,Latrodectus,Lotus",
            "malware_printable": "Latrodectus",
            "first_seen_utc": "2024-10-22 13:56:41",
            "last_seen_utc": "2026-06-30 11:24:44",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://www.vmray.com/latrodectus-a-year-in-the-making/",
            "tags": "c2,latrodectus,vmray",
            "anonymous": "0",
            "reporter": "DonPasci"
        }
    ],
    "1338673": [
        {
            "ioc_value": "https://skinnyjeanso.com/live/",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.latrodectus",
            "malware_alias": "BLACKWIDOW,IceNova,Latrodectus,Lotus",
            "malware_printable": "Latrodectus",
            "first_seen_utc": "2024-10-22 13:56:39",
            "last_seen_utc": "2026-06-30 11:17:03",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://www.vmray.com/latrodectus-a-year-in-the-making/",
            "tags": "c2,latrodectus,vmray",
            "anonymous": "0",
            "reporter": "DonPasci"
        }
    ],
    "1338670": [
        {
            "ioc_value": "https://coolarition.com/live/",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.latrodectus",
            "malware_alias": "BLACKWIDOW,IceNova,Latrodectus,Lotus",
            "malware_printable": "Latrodectus",
            "first_seen_utc": "2024-10-22 13:56:34",
            "last_seen_utc": "2026-06-30 11:14:42",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://www.vmray.com/latrodectus-a-year-in-the-making/",
            "tags": "c2,latrodectus,vmray",
            "anonymous": "0",
            "reporter": "DonPasci"
        }
    ],
    "1332624": [
        {
            "ioc_value": "154.221.17.44:2888",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2024-10-02 06:31:45",
            "last_seen_utc": "2026-06-30 10:46:48",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-666666666",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1332328": [
        {
            "ioc_value": "195.100.198.220:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2024-10-01 16:02:09",
            "last_seen_utc": "2026-06-30 10:44:20",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/195.100.198.220",
            "tags": "AS5400,BT,C2,censys,Mythic",
            "anonymous": "0",
            "reporter": "DonPasci"
        }
    ],
    "1329064": [
        {
            "ioc_value": "meet.google.com-join.us",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2024-09-25 09:48:18",
            "last_seen_utc": "2026-06-30 00:17:48",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://x.com/crep1x/status/1838873758833975802",
            "tags": "ClickFix",
            "anonymous": "0",
            "reporter": "crep1x"
        }
    ],
    "1329042": [
        {
            "ioc_value": "118.25.148.25:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2024-09-25 08:00:47",
            "last_seen_utc": "2026-06-30 11:21:23",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/118.25.148.25",
            "tags": "AS45090,C2,censys,CobaltStrike,cs-watermark-391144938,TENCENT-NET-AP",
            "anonymous": "0",
            "reporter": "DonPasci"
        }
    ],
    "1326604": [
        {
            "ioc_value": "206.210.123.104:8889",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.netsupportmanager_rat",
            "malware_alias": "NetSupport",
            "malware_printable": "NetSupportManager RAT",
            "first_seen_utc": "2024-09-20 08:01:06",
            "last_seen_utc": "2026-06-30 10:44:30",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/206.210.123.104",
            "tags": "AS33130,C2,censys,IASL,RAT",
            "anonymous": "0",
            "reporter": "DonPasci"
        }
    ],
    "1326051": [
        {
            "ioc_value": "https://isomicrotich.com/test/",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.latrodectus",
            "malware_alias": "BLACKWIDOW,IceNova,Latrodectus,Lotus",
            "malware_printable": "Latrodectus",
            "first_seen_utc": "2024-09-19 14:07:51",
            "last_seen_utc": "2026-06-30 11:10:54",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": null,
            "tags": "1.7,Alpha",
            "anonymous": "0",
            "reporter": "spamhaus"
        }
    ],
    "1326052": [
        {
            "ioc_value": "https://rilomenifis.com/test/",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.latrodectus",
            "malware_alias": "BLACKWIDOW,IceNova,Latrodectus,Lotus",
            "malware_printable": "Latrodectus",
            "first_seen_utc": "2024-09-19 14:07:50",
            "last_seen_utc": "2026-06-30 11:20:57",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": null,
            "tags": "1.7,Alpha",
            "anonymous": "0",
            "reporter": "spamhaus"
        }
    ],
    "1321901": [
        {
            "ioc_value": "64.23.213.61:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2024-09-07 16:01:45",
            "last_seen_utc": "2026-06-30 10:45:59",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/64.23.213.61",
            "tags": "AS14061,C2,censys,DIGITALOCEAN-ASN,Mythic",
            "anonymous": "0",
            "reporter": "DonPasci"
        }
    ],
    "1319266": [
        {
            "ioc_value": "154.221.17.44:2666",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2024-09-01 12:00:42",
            "last_seen_utc": "2026-06-30 10:46:48",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/154.221.17.44",
            "tags": "AS142403,C2,censys,CobaltStrike,cs-watermark-666666666,YISUCLOUDLTD-HK",
            "anonymous": "0",
            "reporter": "DonPasci"
        }
    ],
    "1317376": [
        {
            "ioc_value": "https://pikchestop.com/test/",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.lactrodectus",
            "malware_alias": "BLACKWIDOW,IceNova,Latrodectus,Lotus",
            "malware_printable": "Latrodectus",
            "first_seen_utc": "2024-08-30 07:05:10",
            "last_seen_utc": "2026-06-30 11:24:47",
            "confidence_level": 49,
            "is_compromised": false,
            "reference": "https://www.netskope.com/jp/blog/latrodectus-rapid-evolution-continues-with-latest-new-payload-features",
            "tags": null,
            "anonymous": "0",
            "reporter": "johannes"
        }
    ],
    "1317377": [
        {
            "ioc_value": "https://indepahote.com/test/",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.lactrodectus",
            "malware_alias": "BLACKWIDOW,IceNova,Latrodectus,Lotus",
            "malware_printable": "Latrodectus",
            "first_seen_utc": "2024-08-30 07:05:10",
            "last_seen_utc": "2026-06-30 11:14:44",
            "confidence_level": 49,
            "is_compromised": false,
            "reference": "https://www.netskope.com/jp/blog/latrodectus-rapid-evolution-continues-with-latest-new-payload-features",
            "tags": null,
            "anonymous": "0",
            "reporter": "johannes"
        }
    ],
    "1317070": [
        {
            "ioc_value": "86.53.241.21:447",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.netsupportmanager_rat",
            "malware_alias": "NetSupport",
            "malware_printable": "NetSupportManager RAT",
            "first_seen_utc": "2024-08-29 00:01:11",
            "last_seen_utc": "2026-06-30 10:46:12",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/86.53.241.21",
            "tags": "AS3257,C2,censys,GTT-BACKBONE,RAT",
            "anonymous": "0",
            "reporter": "DonPasci"
        }
    ],
    "1316522": [
        {
            "ioc_value": "107.22.165.49:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.netsupportmanager_rat",
            "malware_alias": "NetSupport",
            "malware_printable": "NetSupportManager RAT",
            "first_seen_utc": "2024-08-27 04:00:34",
            "last_seen_utc": "2026-06-30 10:43:15",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/107.22.165.49",
            "tags": "AMAZON-AES,AS14618,C2,censys,RAT",
            "anonymous": "0",
            "reporter": "DonPasci"
        }
    ],
    "1314694": [
        {
            "ioc_value": "83.229.120.73:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2024-08-22 10:04:33",
            "last_seen_utc": "2026-06-30 10:46:10",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/83.229.120.73",
            "tags": "AS139659,C2,censys,Mythic",
            "anonymous": "0",
            "reporter": "DonPasci"
        }
    ],
    "1313657": [
        {
            "ioc_value": "193.19.242.55:1443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.netsupportmanager_rat",
            "malware_alias": "NetSupport",
            "malware_printable": "NetSupportManager RAT",
            "first_seen_utc": "2024-08-19 19:55:59",
            "last_seen_utc": "2026-06-30 10:44:17",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/193.19.242.55",
            "tags": "AS35319,AS48964,C2,censys,RAT",
            "anonymous": "0",
            "reporter": "DonPasci"
        }
    ],
    "1313194": [
        {
            "ioc_value": "110.13.35.37:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.netsupportmanager_rat",
            "malware_alias": "NetSupport",
            "malware_printable": "NetSupportManager RAT",
            "first_seen_utc": "2024-08-18 14:04:40",
            "last_seen_utc": "2026-06-30 10:43:16",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/110.13.35.37",
            "tags": "AS9318,C2,censys,RAT,SKB-AS",
            "anonymous": "0",
            "reporter": "DonPasci"
        }
    ],
    "1312402": [
        {
            "ioc_value": "20.188.119.195:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.havoc",
            "malware_alias": "Havokiz",
            "malware_printable": "Havoc",
            "first_seen_utc": "2024-08-17 14:04:20",
            "last_seen_utc": "2026-06-30 10:44:27",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/20.188.119.195",
            "tags": "AS8075,C2,censys,MICROSOFT-CORP-MSN-AS-BLOCK",
            "anonymous": "0",
            "reporter": "DonPasci"
        }
    ],
    "1312338": [
        {
            "ioc_value": "210.249.114.154:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.netsupportmanager_rat",
            "malware_alias": "NetSupport",
            "malware_printable": "NetSupportManager RAT",
            "first_seen_utc": "2024-08-17 02:04:24",
            "last_seen_utc": "2026-06-30 10:44:35",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/210.249.114.154",
            "tags": "AS2516,C2,censys,RAT",
            "anonymous": "0",
            "reporter": "DonPasci"
        }
    ],
    "1312117": [
        {
            "ioc_value": "20.188.119.195:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.havoc",
            "malware_alias": "Havokiz",
            "malware_printable": "Havoc",
            "first_seen_utc": "2024-08-16 14:02:33",
            "last_seen_utc": "2026-06-30 10:44:27",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/20.188.119.195",
            "tags": "AS8075,C2,censys,MICROSOFT-CORP-MSN-AS-BLOCK",
            "anonymous": "0",
            "reporter": "DonPasci"
        }
    ],
    "1311619": [
        {
            "ioc_value": "23.24.178.35:3085",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.netsupportmanager_rat",
            "malware_alias": "NetSupport",
            "malware_printable": "NetSupportManager RAT",
            "first_seen_utc": "2024-08-15 22:40:43",
            "last_seen_utc": "2026-06-30 10:45:20",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/23.24.178.35",
            "tags": "AS20214,C2,censys,COMCAST-20214,RAT",
            "anonymous": "0",
            "reporter": "DonPasci"
        }
    ],
    "1311614": [
        {
            "ioc_value": "120.25.239.36:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.netsupportmanager_rat",
            "malware_alias": "NetSupport",
            "malware_printable": "NetSupportManager RAT",
            "first_seen_utc": "2024-08-15 22:40:39",
            "last_seen_utc": "2026-06-30 10:43:19",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/120.25.239.36",
            "tags": "ALIBABA-CN-NET,AS37963,C2,censys,RAT",
            "anonymous": "0",
            "reporter": "DonPasci"
        }
    ],
    "1309755": [
        {
            "ioc_value": "146.70.158.198:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.sliver",
            "malware_alias": null,
            "malware_printable": "Sliver",
            "first_seen_utc": "2024-08-11 21:50:57",
            "last_seen_utc": "2026-06-30 10:43:28",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/146.70.158.198",
            "tags": "AS9009,C2,censys,M247",
            "anonymous": "0",
            "reporter": "DonPasci"
        }
    ],
    "1296480": [
        {
            "ioc_value": "43.138.0.179:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2024-07-09 19:05:36",
            "last_seen_utc": "2026-06-30 11:21:18",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-0,TENCENT-NET-AP Shenzhen Tencent Computer Systems Company Limited",
            "anonymous": "0",
            "reporter": "drb_ra"
        }
    ],
    "1296006": [
        {
            "ioc_value": "213.149.181.121:469",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.netsupportmanager_rat",
            "malware_alias": "NetSupport",
            "malware_printable": "NetSupportManager RAT",
            "first_seen_utc": "2024-07-09 06:51:58",
            "last_seen_utc": "2026-06-30 10:44:36",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/213.149.181.121",
            "tags": "CYTA-NETWORK Internet Services,NetSupportRAT",
            "anonymous": "0",
            "reporter": "drb_ra"
        }
    ],
    "1296003": [
        {
            "ioc_value": "20.105.139.205:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.netsupportmanager_rat",
            "malware_alias": "NetSupport",
            "malware_printable": "NetSupportManager RAT",
            "first_seen_utc": "2024-07-09 06:51:48",
            "last_seen_utc": "2026-06-30 10:44:26",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/20.105.139.205",
            "tags": "MICROSOFT-CORP-MSN-AS-BLOCK,NetSupportRAT",
            "anonymous": "0",
            "reporter": "drb_ra"
        }
    ],
    "1295752": [
        {
            "ioc_value": "210.249.114.153:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.netsupportmanager_rat",
            "malware_alias": "NetSupport",
            "malware_printable": "NetSupportManager RAT",
            "first_seen_utc": "2024-07-08 06:51:14",
            "last_seen_utc": "2026-06-30 10:44:35",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/210.249.114.153",
            "tags": "KDDI KDDI CORPORATION,NetSupportRAT",
            "anonymous": "0",
            "reporter": "drb_ra"
        }
    ],
    "1295405": [
        {
            "ioc_value": "23.24.178.33:3085",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.netsupportmanager_rat",
            "malware_alias": "NetSupport",
            "malware_printable": "NetSupportManager RAT",
            "first_seen_utc": "2024-07-07 03:48:38",
            "last_seen_utc": "2026-06-30 10:45:20",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/23.24.178.33",
            "tags": "COMCAST-7922,NetSupportRAT",
            "anonymous": "0",
            "reporter": "drb_ra"
        }
    ],
    "1292877": [
        {
            "ioc_value": "210.249.114.154:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.netsupportmanager_rat",
            "malware_alias": "NetSupport",
            "malware_printable": "NetSupportManager RAT",
            "first_seen_utc": "2024-07-03 06:52:14",
            "last_seen_utc": "2026-06-30 10:44:35",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/210.249.114.154",
            "tags": "KDDI KDDI CORPORATION,NetSupportRAT",
            "anonymous": "0",
            "reporter": "drb_ra"
        }
    ],
    "1291417": [
        {
            "ioc_value": "198.244.197.118:9443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.netsupportmanager_rat",
            "malware_alias": "NetSupport",
            "malware_printable": "NetSupportManager RAT",
            "first_seen_utc": "2024-07-01 10:05:40",
            "last_seen_utc": "2026-06-30 10:44:23",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/198.244.197.118",
            "tags": "NetSupportRAT,OVH",
            "anonymous": "0",
            "reporter": "drb_ra"
        }
    ],
    "1291414": [
        {
            "ioc_value": "206.210.123.104:8888",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.netsupportmanager_rat",
            "malware_alias": "NetSupport",
            "malware_printable": "NetSupportManager RAT",
            "first_seen_utc": "2024-07-01 10:05:30",
            "last_seen_utc": "2026-06-30 10:44:30",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/206.210.123.104",
            "tags": "IASL,NetSupportRAT",
            "anonymous": "0",
            "reporter": "drb_ra"
        }
    ],
    "1291411": [
        {
            "ioc_value": "61.96.204.117:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.netsupportmanager_rat",
            "malware_alias": "NetSupport",
            "malware_printable": "NetSupportManager RAT",
            "first_seen_utc": "2024-07-01 10:05:19",
            "last_seen_utc": "2026-06-30 10:45:57",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/61.96.204.117",
            "tags": "DREAMX-AS DREAMLINE CO.,NetSupportRAT",
            "anonymous": "0",
            "reporter": "drb_ra"
        }
    ],
    "1291410": [
        {
            "ioc_value": "185.23.192.33:444",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.netsupportmanager_rat",
            "malware_alias": "NetSupport",
            "malware_printable": "NetSupportManager RAT",
            "first_seen_utc": "2024-07-01 10:05:15",
            "last_seen_utc": "2026-06-30 10:44:08",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/185.23.192.33",
            "tags": "NetSupportRAT,WINET",
            "anonymous": "0",
            "reporter": "drb_ra"
        }
    ],
    "1291409": [
        {
            "ioc_value": "2.136.235.200:3085",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.netsupportmanager_rat",
            "malware_alias": "NetSupport",
            "malware_printable": "NetSupportManager RAT",
            "first_seen_utc": "2024-07-01 10:05:10",
            "last_seen_utc": "2026-06-30 10:44:24",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/2.136.235.200",
            "tags": "NetSupportRAT,TELEFONICA_DE_ESPANA",
            "anonymous": "0",
            "reporter": "drb_ra"
        }
    ],
    "1291397": [
        {
            "ioc_value": "210.249.114.153:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.netsupportmanager_rat",
            "malware_alias": "NetSupport",
            "malware_printable": "NetSupportManager RAT",
            "first_seen_utc": "2024-07-01 10:04:31",
            "last_seen_utc": "2026-06-30 10:44:34",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/210.249.114.153",
            "tags": "KDDI KDDI CORPORATION,NetSupportRAT",
            "anonymous": "0",
            "reporter": "drb_ra"
        }
    ],
    "1291297": [
        {
            "ioc_value": "londopas.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2024-06-30 21:00:04",
            "last_seen_utc": "2026-06-30 11:21:40",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1291296": [
        {
            "ioc_value": "berjimek.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2024-06-30 21:00:03",
            "last_seen_utc": "2026-06-30 11:21:40",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1291010": [
        {
            "ioc_value": "www.qianxinnbplus.xyz",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2024-06-30 10:13:19",
            "last_seen_utc": "2026-06-30 11:21:39",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-666666666,HKLNIL Landui Cloud ComputingHK Limited",
            "anonymous": "0",
            "reporter": "drb_ra"
        }
    ],
    "1289423": [
        {
            "ioc_value": "152.32.202.240:8443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2024-06-26 17:07:43",
            "last_seen_utc": "2026-06-30 10:46:47",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-666666",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1287670": [
        {
            "ioc_value": "91.199.154.103:34211",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.sliver",
            "malware_alias": null,
            "malware_printable": "Sliver",
            "first_seen_utc": "2024-06-22 06:45:48",
            "last_seen_utc": "2026-06-30 10:46:15",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/91.199.154.103",
            "tags": "Sliver",
            "anonymous": "0",
            "reporter": "drb_ra"
        }
    ],
    "1285430": [
        {
            "ioc_value": "ieee-ecce.info",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2024-06-16 14:42:03",
            "last_seen_utc": "2026-06-30 11:21:40",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1285431": [
        {
            "ioc_value": "kauzalvip.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2024-06-16 14:42:03",
            "last_seen_utc": "2026-06-30 11:21:40",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1285432": [
        {
            "ioc_value": "nakit-yok.org",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2024-06-16 14:42:03",
            "last_seen_utc": "2026-06-30 11:21:40",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1285433": [
        {
            "ioc_value": "nathanhr.services",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2024-06-16 14:42:03",
            "last_seen_utc": "2026-06-30 11:21:40",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1283657": [
        {
            "ioc_value": "support.whatsappsignup.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2024-06-10 09:26:05",
            "last_seen_utc": "2026-06-30 11:21:40",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-987654321,PEG TECH INC",
            "anonymous": "0",
            "reporter": "drb_ra"
        }
    ],
    "1278385": [
        {
            "ioc_value": "static.nvidiadrives.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2024-06-02 19:42:15",
            "last_seen_utc": "2026-06-30 11:21:47",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1278172": [
        {
            "ioc_value": "119.91.208.190:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2024-06-02 08:38:33",
            "last_seen_utc": "2026-06-30 11:21:42",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-987654321,Shenzhen Tencent Computer Systems Company Limited",
            "anonymous": "0",
            "reporter": "drb_ra"
        }
    ],
    "1277937": [
        {
            "ioc_value": "47.109.69.135:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2024-06-01 13:08:25",
            "last_seen_utc": "2026-06-30 11:21:45",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-987654321,Hangzhou Alibaba Advertising Co.Ltd.",
            "anonymous": "0",
            "reporter": "drb_ra"
        }
    ],
    "1277588": [
        {
            "ioc_value": "101.43.32.212:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2024-05-31 12:57:33",
            "last_seen_utc": "2026-06-30 11:21:41",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-100000,Shenzhen Tencent Computer Systems Company Limited",
            "anonymous": "0",
            "reporter": "drb_ra"
        }
    ],
    "1276810": [
        {
            "ioc_value": "asterchildrenshoes.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2024-05-29 12:53:46",
            "last_seen_utc": "2026-06-30 11:21:47",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "BL Networks,CobaltStrike,cs-watermark-987654321",
            "anonymous": "0",
            "reporter": "drb_ra"
        }
    ],
    "1276802": [
        {
            "ioc_value": "124.223.41.181:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2024-05-29 12:52:55",
            "last_seen_utc": "2026-06-30 11:21:43",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-666666666,Shenzhen Tencent Computer Systems Company Limited",
            "anonymous": "0",
            "reporter": "drb_ra"
        }
    ],
    "1276786": [
        {
            "ioc_value": "8.210.9.201:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2024-05-29 10:17:04",
            "last_seen_utc": "2026-06-30 11:21:47",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ALIBABA-CN-NET Alibaba US Technology Co. Ltd.,CobaltStrike,cs-watermark-0",
            "anonymous": "0",
            "reporter": "drb_ra"
        }
    ],
    "1276244": [
        {
            "ioc_value": "https://65.108.55.55:9000/",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2024-05-27 16:13:21",
            "last_seen_utc": "2026-06-30 11:10:28",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "Vidar",
            "anonymous": "0",
            "reporter": "crep1x"
        }
    ],
    "1275630": [
        {
            "ioc_value": "pt-security.ru",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2024-05-25 22:18:29",
            "last_seen_utc": "2026-06-30 11:21:40",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-987654321,MTW-AS",
            "anonymous": "0",
            "reporter": "drb_ra"
        }
    ],
    "1274726": [
        {
            "ioc_value": "47.92.127.53:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2024-05-24 13:15:35",
            "last_seen_utc": "2026-06-30 11:21:46",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-391144938,Hangzhou Alibaba Advertising Co.Ltd.",
            "anonymous": "0",
            "reporter": "drb_ra"
        }
    ],
    "1273973": [
        {
            "ioc_value": "119.28.83.149:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2024-05-22 11:06:58",
            "last_seen_utc": "2026-06-30 11:21:42",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-987654321,Tencent Building Kejizhongyi Avenue",
            "anonymous": "0",
            "reporter": "drb_ra"
        }
    ],
    "1273882": [
        {
            "ioc_value": "51.15.16.116:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "js.fakeupdates",
            "malware_alias": "FakeUpdate,GhoLoader,SocGholish",
            "malware_printable": "FAKEUPDATES",
            "first_seen_utc": "2024-05-21 18:51:48",
            "last_seen_utc": "2026-06-30 10:45:54",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/51.15.16.116",
            "tags": "Online SAS,SocGholish",
            "anonymous": "0",
            "reporter": "drb_ra"
        }
    ],
    "1273456": [
        {
            "ioc_value": "139.159.203.44:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2024-05-21 12:53:29",
            "last_seen_utc": "2026-06-30 11:21:44",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-987654321,HWCSNET Huawei Cloud Service data center",
            "anonymous": "0",
            "reporter": "drb_ra"
        }
    ],
    "1272788": [
        {
            "ioc_value": "123.58.198.236:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2024-05-19 07:56:13",
            "last_seen_utc": "2026-06-30 11:21:43",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-391144938,UCLOUD INFORMATION TECHNOLOGY (HK) LIMITED",
            "anonymous": "0",
            "reporter": "drb_ra"
        }
    ],
    "1271699": [
        {
            "ioc_value": "vip8806.mom",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2024-05-16 07:53:43",
            "last_seen_utc": "2026-06-30 11:21:40",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CNSERVERS LLC,CobaltStrike,cs-watermark-987654321",
            "anonymous": "0",
            "reporter": "drb_ra"
        }
    ],
    "1271605": [
        {
            "ioc_value": "blmdiscount.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2024-05-15 22:13:26",
            "last_seen_utc": "2026-06-30 11:21:40",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-674054486,FBWNETWORKS",
            "anonymous": "0",
            "reporter": "drb_ra"
        }
    ],
    "1271606": [
        {
            "ioc_value": "91.238.181.235:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2024-05-15 22:13:26",
            "last_seen_utc": "2026-06-30 11:21:47",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-674054486,FBWNETWORKS",
            "anonymous": "0",
            "reporter": "drb_ra"
        }
    ],
    "1271347": [
        {
            "ioc_value": "118.25.85.198:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2024-05-15 15:33:07",
            "last_seen_utc": "2026-06-30 11:21:36",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/118.25.85.198",
            "tags": "AS45090,c2,censys,CobaltStrike,cs-watermark-305419896,TENCENT-NET-AP",
            "anonymous": "0",
            "reporter": "DonPasci"
        }
    ],
    "1270684": [
        {
            "ioc_value": "64.7.198.58:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2024-05-14 10:14:21",
            "last_seen_utc": "2026-06-30 11:21:46",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "BLNWX,CobaltStrike,cs-watermark-426352781",
            "anonymous": "0",
            "reporter": "drb_ra"
        }
    ],
    "1269727": [
        {
            "ioc_value": "113.31.105.33:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2024-05-11 22:47:31",
            "last_seen_utc": "2026-06-30 11:21:42",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "China Telecom (Group),CobaltStrike,cs-watermark-987654321",
            "anonymous": "0",
            "reporter": "drb_ra"
        }
    ],
    "1269724": [
        {
            "ioc_value": "185.196.8.18:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2024-05-11 22:47:10",
            "last_seen_utc": "2026-06-30 11:21:44",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-987654321,Simple Carrier LLC",
            "anonymous": "0",
            "reporter": "drb_ra"
        }
    ],
    "1269723": [
        {
            "ioc_value": "action-winds.cfd",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2024-05-11 22:47:09",
            "last_seen_utc": "2026-06-30 11:21:47",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-987654321,Simple Carrier LLC",
            "anonymous": "0",
            "reporter": "drb_ra"
        }
    ],
    "1269721": [
        {
            "ioc_value": "microstar.cfd",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2024-05-11 22:47:08",
            "last_seen_utc": "2026-06-30 11:21:48",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-987654321,Simple Carrier LLC",
            "anonymous": "0",
            "reporter": "drb_ra"
        }
    ],
    "1267565": [
        {
            "ioc_value": "113.31.106.106:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2024-05-07 10:14:57",
            "last_seen_utc": "2026-06-30 11:21:42",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CHINANET-SHANGHAI-MAN China Telecom Group,CobaltStrike,cs-watermark-987654321",
            "anonymous": "0",
            "reporter": "drb_ra"
        }
    ],
    "1267486": [
        {
            "ioc_value": "111.230.12.238:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2024-05-07 07:48:08",
            "last_seen_utc": "2026-06-30 11:21:41",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/111.230.12.238",
            "tags": "AS45090,c2,censys,CobaltStrike,cs-watermark-391144938,TENCENT-NET-AP",
            "anonymous": "0",
            "reporter": "DonPasci"
        }
    ],
    "1266959": [
        {
            "ioc_value": "134.122.130.186:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2024-05-06 12:49:25",
            "last_seen_utc": "2026-06-30 11:21:43",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "BGPNET Global ASN,CobaltStrike,cs-watermark-987654321",
            "anonymous": "0",
            "reporter": "drb_ra"
        }
    ],
    "1263972": [
        {
            "ioc_value": "134.122.130.181:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2024-04-29 12:51:26",
            "last_seen_utc": "2026-06-30 11:21:43",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "BGPNET Global ASN,CobaltStrike,cs-watermark-987654321",
            "anonymous": "0",
            "reporter": "drb_ra"
        }
    ],
    "1263319": [
        {
            "ioc_value": "124.71.106.234:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2024-04-28 17:59:06",
            "last_seen_utc": "2026-06-30 11:21:43",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-666666666,Huawei Cloud Service data center",
            "anonymous": "0",
            "reporter": "drb_ra"
        }
    ],
    "1262666": [
        {
            "ioc_value": "118.31.116.9:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2024-04-26 12:59:31",
            "last_seen_utc": "2026-06-30 11:21:42",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-987654321,Hangzhou Alibaba Advertising Co.Ltd.",
            "anonymous": "0",
            "reporter": "drb_ra"
        }
    ],
    "1262568": [
        {
            "ioc_value": "8.134.11.7:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2024-04-25 22:12:56",
            "last_seen_utc": "2026-06-30 11:21:46",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ALIBABA-CN-NET Hangzhou Alibaba Advertising Co.Ltd.,CobaltStrike,cs-watermark-987654321",
            "anonymous": "0",
            "reporter": "drb_ra"
        }
    ],
    "1261845": [
        {
            "ioc_value": "165.227.108.186:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2024-04-24 13:08:20",
            "last_seen_utc": "2026-06-30 11:21:44",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-970865301,DigitalOcean LLC",
            "anonymous": "0",
            "reporter": "drb_ra"
        }
    ],
    "1260893": [
        {
            "ioc_value": "80.66.75.9:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2024-04-23 18:05:49",
            "last_seen_utc": "2026-06-30 11:21:47",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-987654321,GRIZ-INET-SERVICE",
            "anonymous": "0",
            "reporter": "drb_ra"
        }
    ],
    "1260890": [
        {
            "ioc_value": "101.201.54.74:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2024-04-23 18:05:43",
            "last_seen_utc": "2026-06-30 11:21:41",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-987654321,Hangzhou Alibaba Advertising Co.Ltd.",
            "anonymous": "0",
            "reporter": "drb_ra"
        }
    ],
    "1259796": [
        {
            "ioc_value": "62.204.41.11:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2024-04-21 15:09:17",
            "last_seen_utc": "2026-06-30 11:21:46",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/62.204.41.11",
            "tags": "AS59425,c2,censys,CobaltStrike,cs-watermark-1580103824,HORIZONMSK-AS",
            "anonymous": "0",
            "reporter": "DonPasci"
        }
    ],
    "1255726": [
        {
            "ioc_value": "124.220.6.158:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2024-04-11 10:15:16",
            "last_seen_utc": "2026-06-30 10:46:43",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/search?resource=hosts&virtual_hosts=EXCLUDE&q=%28services.software.uniform_resource_identifier%3A+%60cpe%3A2.3%3Aa%3Afortra%3Acobalt_strike%3A%2A%3A%2A%3A%2A%3A%2A%3A%2A%3A%2A%3A%2A%3A%2A%60%29+and+autonomous_system.name%3D%60TENCENT-NET-AP+Shenzhen+Tencent+Computer+Systems+Company+Limited%60",
            "tags": "AS45090,c2,censys,CobaltStrike,TENCENT-NET-AP",
            "anonymous": "0",
            "reporter": "DonPasci"
        }
    ],
    "1255727": [
        {
            "ioc_value": "124.220.6.158:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2024-04-11 10:15:15",
            "last_seen_utc": "2026-06-30 10:46:43",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/search?resource=hosts&virtual_hosts=EXCLUDE&q=%28services.software.uniform_resource_identifier%3A+%60cpe%3A2.3%3Aa%3Afortra%3Acobalt_strike%3A%2A%3A%2A%3A%2A%3A%2A%3A%2A%3A%2A%3A%2A%3A%2A%60%29+and+autonomous_system.name%3D%60TENCENT-NET-AP+Shenzhen+Tencent+Computer+Systems+Company+Limited%60",
            "tags": "AS45090,c2,censys,CobaltStrike,TENCENT-NET-AP",
            "anonymous": "0",
            "reporter": "DonPasci"
        }
    ],
    "1255012": [
        {
            "ioc_value": "159.223.0.103:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.havoc",
            "malware_alias": "Havokiz",
            "malware_printable": "Havoc",
            "first_seen_utc": "2024-04-09 06:47:29",
            "last_seen_utc": "2026-06-30 10:43:40",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/159.223.0.103",
            "tags": "DIGITALOCEAN-ASN,Havoc",
            "anonymous": "0",
            "reporter": "drb_ra"
        }
    ],
    "1252542": [
        {
            "ioc_value": "185.196.10.121:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2024-04-02 10:17:26",
            "last_seen_utc": "2026-06-30 11:21:44",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-987654321,SIMPLECARRIER",
            "anonymous": "0",
            "reporter": "drb_ra"
        }
    ],
    "1250157": [
        {
            "ioc_value": "soneypaly.club",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2024-03-27 14:42:02",
            "last_seen_utc": "2026-06-30 11:21:48",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1249815": [
        {
            "ioc_value": "47.105.69.34:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2024-03-27 07:57:29",
            "last_seen_utc": "2026-06-30 11:21:45",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ALIBABA-CN-NET Hangzhou Alibaba Advertising Co.Ltd.,CobaltStrike,cs-watermark-987654321",
            "anonymous": "0",
            "reporter": "drb_ra"
        }
    ],
    "1248363": [
        {
            "ioc_value": "https://titnovacrion.top/live/",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.unidentified_111",
            "malware_alias": "BLACKWIDOW,IceNova,Latrodectus,Lotus",
            "malware_printable": "Unidentified 111 (Latrodectus)",
            "first_seen_utc": "2024-03-22 19:47:18",
            "last_seen_utc": "2026-06-30 11:16:39",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": null,
            "anonymous": "0",
            "reporter": "Cryptolaemus1"
        }
    ],
    "1245476": [
        {
            "ioc_value": "47.100.87.177:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2024-03-09 20:54:40",
            "last_seen_utc": "2026-06-30 11:21:45",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ALIBABA-CN-NET Hangzhou Alibaba Advertising Co.Ltd.,CobaltStrike,cs-watermark-987654321",
            "anonymous": "0",
            "reporter": "drb_ra"
        }
    ],
    "1244781": [
        {
            "ioc_value": "194.165.16.55:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2024-03-06 20:55:37",
            "last_seen_utc": "2026-06-30 11:21:44",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-674054486,FLYSERVERS-ENDCLIENTS",
            "anonymous": "0",
            "reporter": "drb_ra"
        }
    ],
    "1244726": [
        {
            "ioc_value": "googlesupportacc.top",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2024-03-06 10:12:56",
            "last_seen_utc": "2026-06-30 11:21:48",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ASSEFLOW,CobaltStrike,cs-watermark-987654321",
            "anonymous": "0",
            "reporter": "drb_ra"
        }
    ],
    "1241656": [
        {
            "ioc_value": "121.43.55.149:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2024-02-21 22:13:19",
            "last_seen_utc": "2026-06-30 11:21:43",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ALIBABA-CN-NET Hangzhou Alibaba Advertising Co.Ltd.,CobaltStrike,cs-watermark-391144938",
            "anonymous": "0",
            "reporter": "drb_ra"
        }
    ],
    "1237621": [
        {
            "ioc_value": "qw.regcssv.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2024-02-07 10:12:21",
            "last_seen_utc": "2026-06-30 11:21:50",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-1580103824,FLYSERVERS-ASN",
            "anonymous": "0",
            "reporter": "drb_ra"
        }
    ],
    "1236577": [
        {
            "ioc_value": "ec2-3-22-66-152.us-east-2.compute.amazonaws.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2024-02-03 19:38:15",
            "last_seen_utc": "2026-06-30 11:21:50",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/3.22.66.152+ec2-3-22-66-152.us-east-2.compute.amazonaws.com",
            "tags": "AMAZON-02,AS16509,C2,censys",
            "anonymous": "0",
            "reporter": "thehappydinoa"
        }
    ],
    "1236276": [
        {
            "ioc_value": "20.56.70.245:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2024-02-02 06:00:13",
            "last_seen_utc": "2026-06-30 11:21:45",
            "confidence_level": 80,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": "0",
            "reporter": "malpulse"
        }
    ],
    "1235332": [
        {
            "ioc_value": "www.louangelwolf.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2024-01-30 06:20:34",
            "last_seen_utc": "2026-06-30 11:21:52",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "cobaltstrike,cs-watermark-1551089073",
            "anonymous": "0",
            "reporter": "myceliumbroker"
        }
    ],
    "1234854": [
        {
            "ioc_value": "kkudndkwatnfevcaqeefytqnh.top",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2024-01-28 06:22:18",
            "last_seen_utc": "2026-06-30 11:21:51",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "cobaltstrike,cs-watermark-987654321",
            "anonymous": "0",
            "reporter": "myceliumbroker"
        }
    ],
    "1234859": [
        {
            "ioc_value": "whxzqkbbtzvdyxdeseoiyujzs.co",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2024-01-28 06:22:17",
            "last_seen_utc": "2026-06-30 11:21:52",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "cobaltstrike,cs-watermark-987654321",
            "anonymous": "0",
            "reporter": "myceliumbroker"
        }
    ],
    "1234860": [
        {
            "ioc_value": "uohhunkmnfhbimtagizqgwpmv.to",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2024-01-28 06:22:17",
            "last_seen_utc": "2026-06-30 11:21:52",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "cobaltstrike,cs-watermark-987654321",
            "anonymous": "0",
            "reporter": "myceliumbroker"
        }
    ],
    "1234928": [
        {
            "ioc_value": "114.55.133.151:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2024-01-27 14:31:40",
            "last_seen_utc": "2026-06-30 11:21:42",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/114.55.133.151",
            "tags": "AS37963,C2,censys",
            "anonymous": "0",
            "reporter": "thehappydinoa"
        }
    ],
    "1234909": [
        {
            "ioc_value": "117.72.39.83:30005",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2024-01-27 14:31:20",
            "last_seen_utc": "2026-06-30 10:46:39",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/117.72.39.83",
            "tags": "AS141679,C2,censys",
            "anonymous": "0",
            "reporter": "thehappydinoa"
        }
    ],
    "1234304": [
        {
            "ioc_value": "38.147.189.199:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pupy",
            "malware_alias": "Patpoopy",
            "malware_printable": "pupy",
            "first_seen_utc": "2024-01-24 18:49:24",
            "last_seen_utc": "2026-06-30 10:45:29",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/38.147.189.199",
            "tags": "Pupy RAT,XNNET",
            "anonymous": "0",
            "reporter": "drb_ra"
        }
    ],
    "1233919": [
        {
            "ioc_value": "www.idn15r69vh3fwhzclfoeuaoy.today",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2024-01-23 13:53:21",
            "last_seen_utc": "2026-06-30 11:21:52",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/8.219.229.99+www.idn15r69vh3fwhzclfoeuaoy.today",
            "tags": "AS45102,C2,censys",
            "anonymous": "0",
            "reporter": "thehappydinoa"
        }
    ],
    "1231802": [
        {
            "ioc_value": "164-90-169-184.cprapid.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2024-01-18 13:44:13",
            "last_seen_utc": "2026-06-30 11:21:52",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/164.90.169.184+164-90-169-184.cprapid.com",
            "tags": "C2,censys,DIGITALOCEAN-ASN",
            "anonymous": "0",
            "reporter": "thehappydinoa"
        }
    ],
    "1230963": [
        {
            "ioc_value": "https://65.21.187.53/",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2024-01-16 08:13:32",
            "last_seen_utc": "2026-06-30 11:10:16",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "Vidar",
            "anonymous": "0",
            "reporter": "crep1x"
        }
    ],
    "1230909": [
        {
            "ioc_value": "lz4.tiktok123.life",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2024-01-15 16:27:00",
            "last_seen_utc": "2026-06-30 11:21:51",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "cobaltstrike,cs-watermark-987654321",
            "anonymous": "0",
            "reporter": "myceliumbroker"
        }
    ],
    "1230478": [
        {
            "ioc_value": "164.92.79.49:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.havoc",
            "malware_alias": "Havokiz",
            "malware_printable": "Havoc",
            "first_seen_utc": "2024-01-13 06:47:25",
            "last_seen_utc": "2026-06-30 10:43:44",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/164.92.79.49",
            "tags": "DIGITALOCEAN-ASN,Havoc",
            "anonymous": "0",
            "reporter": "drb_ra"
        }
    ],
    "1230429": [
        {
            "ioc_value": "site.dev.hutechweb.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2024-01-12 18:36:24",
            "last_seen_utc": "2026-06-30 11:21:52",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "cobaltstrike,cs-watermark-987654321",
            "anonymous": "0",
            "reporter": "myceliumbroker"
        }
    ],
    "1230076": [
        {
            "ioc_value": "ns1.fiducaire.lu",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2024-01-11 06:54:21",
            "last_seen_utc": "2026-06-30 11:21:51",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "cobaltstrike,cs-watermark-1263551644",
            "anonymous": "0",
            "reporter": "myceliumbroker"
        }
    ],
    "1230077": [
        {
            "ioc_value": "ns1.asurances.lu",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2024-01-11 06:54:21",
            "last_seen_utc": "2026-06-30 11:21:51",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "cobaltstrike,cs-watermark-1263551644",
            "anonymous": "0",
            "reporter": "myceliumbroker"
        }
    ],
    "1230078": [
        {
            "ioc_value": "sagsblog.telinduslab.lu",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2024-01-11 06:54:20",
            "last_seen_utc": "2026-06-30 11:21:51",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "cobaltstrike,cs-watermark-1263551644",
            "anonymous": "0",
            "reporter": "myceliumbroker"
        }
    ],
    "1230079": [
        {
            "ioc_value": "ns1.jocelynhealth.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2024-01-11 06:54:20",
            "last_seen_utc": "2026-06-30 11:21:51",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "cobaltstrike,cs-watermark-1590258876",
            "anonymous": "0",
            "reporter": "myceliumbroker"
        }
    ],
    "1229840": [
        {
            "ioc_value": "ns.emaratalyoum.me",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2024-01-10 10:50:13",
            "last_seen_utc": "2026-06-30 11:21:51",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "cobaltstrike,cs-watermark-1727139162",
            "anonymous": "0",
            "reporter": "myceliumbroker"
        }
    ],
    "1229817": [
        {
            "ioc_value": "161.35.239.147:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.havoc",
            "malware_alias": "Havokiz",
            "malware_printable": "Havoc",
            "first_seen_utc": "2024-01-10 06:48:20",
            "last_seen_utc": "2026-06-30 10:43:41",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/161.35.239.147",
            "tags": "DIGITALOCEAN-ASN,Havoc",
            "anonymous": "0",
            "reporter": "drb_ra"
        }
    ],
    "1229694": [
        {
            "ioc_value": "emailmigration.org",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2024-01-09 14:55:19",
            "last_seen_utc": "2026-06-30 11:21:50",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "cobaltstrike,cs-watermark-1892870985",
            "anonymous": "0",
            "reporter": "myceliumbroker"
        }
    ],
    "1229695": [
        {
            "ioc_value": "ns1.emailmigration.org",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2024-01-09 14:55:17",
            "last_seen_utc": "2026-06-30 11:21:51",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "cobaltstrike,cs-watermark-1892870985",
            "anonymous": "0",
            "reporter": "myceliumbroker"
        }
    ],
    "1229661": [
        {
            "ioc_value": "111.92.243.236:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2024-01-09 08:45:29",
            "last_seen_utc": "2026-06-30 11:21:41",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-666666666,HFTCL-AS-AP High Family Technology Co. Limited",
            "anonymous": "0",
            "reporter": "drb_ra"
        }
    ],
    "1228458": [
        {
            "ioc_value": "139.9.62.19:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2024-01-05 21:31:13",
            "last_seen_utc": "2026-06-30 11:21:44",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/139.9.62.19",
            "tags": "C2,censys",
            "anonymous": "0",
            "reporter": "thehappydinoa"
        }
    ],
    "1228033": [
        {
            "ioc_value": "143.110.151.209:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.sliver",
            "malware_alias": null,
            "malware_printable": "Sliver",
            "first_seen_utc": "2024-01-05 06:45:36",
            "last_seen_utc": "2026-06-30 10:43:26",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/143.110.151.209",
            "tags": "DIGITALOCEAN-ASN,Sliver",
            "anonymous": "0",
            "reporter": "drb_ra"
        }
    ],
    "1227297": [
        {
            "ioc_value": "106.54.209.36:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2024-01-02 14:31:12",
            "last_seen_utc": "2026-06-30 11:21:41",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/106.54.209.36",
            "tags": "C2,censys",
            "anonymous": "0",
            "reporter": "thehappydinoa"
        }
    ],
    "1226488": [
        {
            "ioc_value": "astra4512.startdedicated.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-12-30 11:33:25",
            "last_seen_utc": "2026-06-30 11:21:52",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-987654321,GD-EMEA-DC-SXB1",
            "anonymous": "0",
            "reporter": "drb_ra"
        }
    ],
    "1224105": [
        {
            "ioc_value": "cs.xcb.one",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-12-27 22:15:29",
            "last_seen_utc": "2026-06-30 11:21:53",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-987654321,MICROSOFT-CORP-MSN-AS-BLOCK",
            "anonymous": "0",
            "reporter": "drb_ra"
        }
    ],
    "1223678": [
        {
            "ioc_value": "8.140.203.92:7817",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.deimos",
            "malware_alias": null,
            "malware_printable": "Deimos",
            "first_seen_utc": "2023-12-26 06:46:27",
            "last_seen_utc": "2026-06-30 10:46:06",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/8.140.203.92",
            "tags": "ALIBABA-CN-NET Hangzhou Alibaba Advertising Co.Ltd.,Deimos",
            "anonymous": "0",
            "reporter": "drb_ra"
        }
    ],
    "1221451": [
        {
            "ioc_value": "62.234.27.204:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-12-18 05:00:11",
            "last_seen_utc": "2026-06-30 11:21:46",
            "confidence_level": 80,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": "0",
            "reporter": "malpulse"
        }
    ],
    "1213636": [
        {
            "ioc_value": "MicrosoftSyst3m.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-12-16 22:12:14",
            "last_seen_utc": "2026-06-30 11:21:53",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-674054486,GLOBALLAYER",
            "anonymous": "0",
            "reporter": "drb_ra"
        }
    ],
    "1213211": [
        {
            "ioc_value": "117.72.39.83:33333",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-12-15 18:59:31",
            "last_seen_utc": "2026-06-30 10:46:39",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/117.72.39.83",
            "tags": "C2,censys",
            "anonymous": "0",
            "reporter": "thehappydinoa"
        }
    ],
    "1209246": [
        {
            "ioc_value": "unzip2.xyz",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-12-04 08:45:50",
            "last_seen_utc": "2026-06-30 11:21:53",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-987654321,TENCENT-NET-AP-CN Tencent Building Kejizhongyi Avenue",
            "anonymous": "0",
            "reporter": "drb_ra"
        }
    ],
    "1205166": [
        {
            "ioc_value": "techsyscloud.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-11-24 08:21:04",
            "last_seen_utc": "2026-06-30 11:21:55",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1205167": [
        {
            "ioc_value": "yify88.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-11-24 08:21:04",
            "last_seen_utc": "2026-06-30 11:21:55",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1205164": [
        {
            "ioc_value": "americcorp.net",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-11-24 08:21:02",
            "last_seen_utc": "2026-06-30 11:21:54",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1204685": [
        {
            "ioc_value": "tech-guard.vguard.tech",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-11-22 20:04:09",
            "last_seen_utc": "2026-06-30 11:21:55",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/44.204.120.159+tech-guard.vguard.tech",
            "tags": "AMAZON-AES,C2,censys",
            "anonymous": "0",
            "reporter": "thehappydinoa"
        }
    ],
    "1202628": [
        {
            "ioc_value": "ns.manager.moonlighter.space",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-11-15 20:24:37",
            "last_seen_utc": "2026-06-30 11:21:55",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-1893164628,DIGITALOCEAN-ASN",
            "anonymous": "0",
            "reporter": "drb_ra"
        }
    ],
    "1201144": [
        {
            "ioc_value": "101.34.222.38:60000",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "apk.viper_rat",
            "malware_alias": null,
            "malware_printable": "Viper RAT",
            "first_seen_utc": "2023-11-09 17:50:07",
            "last_seen_utc": "2026-06-30 10:43:03",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/101.34.222.38",
            "tags": "C2,censys,RAT",
            "anonymous": "0",
            "reporter": "thehappydinoa"
        }
    ],
    "1200343": [
        {
            "ioc_value": "dev.theokanegroup.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-11-09 04:06:44",
            "last_seen_utc": "2026-06-30 11:21:55",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/134.209.164.110+dev.theokanegroup.com",
            "tags": "C2,censys,DIGITALOCEAN-ASN",
            "anonymous": "0",
            "reporter": "thehappydinoa"
        }
    ],
    "1199545": [
        {
            "ioc_value": "38.54.115.233:4443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-11-06 21:04:29",
            "last_seen_utc": "2026-06-30 10:46:59",
            "confidence_level": 80,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": "0",
            "reporter": "malpulse"
        }
    ],
    "1199506": [
        {
            "ioc_value": "bwyb.love",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-11-06 18:07:30",
            "last_seen_utc": "2026-06-30 11:21:54",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/47.242.158.114+bwyb.love",
            "tags": "C2,censys",
            "anonymous": "0",
            "reporter": "thehappydinoa"
        }
    ],
    "1199160": [
        {
            "ioc_value": "www.sunwu.world",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-11-05 15:00:42",
            "last_seen_utc": "2026-06-30 11:21:55",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/82.157.149.194+www.sunwu.world",
            "tags": "C2,censys",
            "anonymous": "0",
            "reporter": "thehappydinoa"
        }
    ],
    "1192255": [
        {
            "ioc_value": "139.155.148.131:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-10-24 10:39:59",
            "last_seen_utc": "2026-06-30 11:21:44",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/139.155.148.131",
            "tags": "C2,censys",
            "anonymous": "0",
            "reporter": "thehappydinoa"
        }
    ],
    "1191379": [
        {
            "ioc_value": "www.goocoinorg.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-10-20 21:57:56",
            "last_seen_utc": "2026-06-30 11:21:55",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/search?resource=hosts&sort=RELEVANCE&per_page=25&virtual_hosts=INCLUDE&q=name%3A+www.goocoinorg.com&ref=threatfox",
            "tags": "C2,censys",
            "anonymous": "0",
            "reporter": "thehappydinoa"
        }
    ],
    "1189545": [
        {
            "ioc_value": "airlinesapp.net",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-10-16 08:49:32",
            "last_seen_utc": "2026-06-30 11:21:54",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-587247372,DigitalOcean LLC",
            "anonymous": "0",
            "reporter": "drb_ra"
        }
    ],
    "1188605": [
        {
            "ioc_value": "lectricelfuel.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-10-13 19:49:34",
            "last_seen_utc": "2026-06-30 11:21:54",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/search?resource=hosts&sort=RELEVANCE&per_page=25&virtual_hosts=INCLUDE&q=name%3A+lectricelfuel.com&ref=threatfox",
            "tags": "C2,censys,DIGITALOCEAN-ASN",
            "anonymous": "0",
            "reporter": "thehappydinoa"
        }
    ],
    "1187879": [
        {
            "ioc_value": "143.110.151.209:31337",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.sliver",
            "malware_alias": null,
            "malware_printable": "Sliver",
            "first_seen_utc": "2023-10-12 01:35:38",
            "last_seen_utc": "2026-06-30 10:43:26",
            "confidence_level": 90,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/143.110.151.209",
            "tags": "C2,censys,DIGITALOCEAN-ASN",
            "anonymous": "0",
            "reporter": "thehappydinoa"
        }
    ],
    "1187462": [
        {
            "ioc_value": "117.72.8.192:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-10-11 12:59:56",
            "last_seen_utc": "2026-06-30 11:21:42",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/117.72.8.192",
            "tags": "C2,censys",
            "anonymous": "0",
            "reporter": "thehappydinoa"
        }
    ],
    "1180378": [
        {
            "ioc_value": "111.229.187.212:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-09-30 16:12:13",
            "last_seen_utc": "2026-06-30 11:21:41",
            "confidence_level": 80,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": "0",
            "reporter": "malpulse"
        }
    ],
    "1165497": [
        {
            "ioc_value": "igo0gle.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-09-21 09:29:08",
            "last_seen_utc": "2026-06-30 11:21:53",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "AS-ALVIVA,CobaltStrike,cs-watermark-674054486",
            "anonymous": "0",
            "reporter": "drb_ra"
        }
    ],
    "1165172": [
        {
            "ioc_value": "8.217.217.243:8082",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.deimos",
            "malware_alias": null,
            "malware_printable": "Deimos",
            "first_seen_utc": "2023-09-20 18:47:20",
            "last_seen_utc": "2026-06-30 10:46:07",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/8.217.217.243",
            "tags": "ALIBABA-CN-NET Alibaba US Technology Co. Ltd.,Deimos",
            "anonymous": "0",
            "reporter": "drb_ra"
        }
    ],
    "1155921": [
        {
            "ioc_value": "csxv.sec.cm",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-09-09 20:06:55",
            "last_seen_utc": "2026-06-30 11:21:54",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CHANGWAY-AS,CobaltStrike,cs-watermark-987654321",
            "anonymous": "0",
            "reporter": "drb_ra"
        }
    ],
    "1155319": [
        {
            "ioc_value": "43.136.38.59:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-09-05 21:52:59",
            "last_seen_utc": "2026-06-30 11:21:45",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-1580103824,Shenzhen Tencent Computer Systems Company Limited",
            "anonymous": "0",
            "reporter": "drb_ra"
        }
    ],
    "1152278": [
        {
            "ioc_value": "withoutedge.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-08-26 18:42:05",
            "last_seen_utc": "2026-06-30 11:21:59",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1152277": [
        {
            "ioc_value": "thconnewfoot.org",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-08-26 18:42:04",
            "last_seen_utc": "2026-06-30 11:21:58",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1152274": [
        {
            "ioc_value": "caixas.link",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-08-26 18:42:03",
            "last_seen_utc": "2026-06-30 11:21:56",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1152275": [
        {
            "ioc_value": "ddllsearch.site",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-08-26 18:42:03",
            "last_seen_utc": "2026-06-30 11:21:57",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1152276": [
        {
            "ioc_value": "gepcash.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-08-26 18:42:03",
            "last_seen_utc": "2026-06-30 11:21:57",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1152272": [
        {
            "ioc_value": "amazonclouds.link",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-08-26 18:42:02",
            "last_seen_utc": "2026-06-30 11:21:56",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1152273": [
        {
            "ioc_value": "amur-city.online",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-08-26 18:42:02",
            "last_seen_utc": "2026-06-30 11:21:56",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1151693": [
        {
            "ioc_value": "43.153.222.28:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-08-23 11:56:21",
            "last_seen_utc": "2026-06-30 11:21:30",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-100000,Tencent Building Kejizhongyi Avenue",
            "anonymous": "0",
            "reporter": "drb_ra"
        }
    ],
    "1149951": [
        {
            "ioc_value": "164.92.145.128:7810",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.brute_ratel_c4",
            "malware_alias": "BOLDBADGER,BruteRatel",
            "malware_printable": "Brute Ratel C4",
            "first_seen_utc": "2023-08-14 18:46:43",
            "last_seen_utc": "2026-06-30 10:43:44",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/164.92.145.128",
            "tags": "Brute Ratel C4,DIGITALOCEAN-ASN",
            "anonymous": "0",
            "reporter": "drb_ra"
        }
    ],
    "1149946": [
        {
            "ioc_value": "pctor.link",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-08-14 16:00:05",
            "last_seen_utc": "2026-06-30 11:21:59",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1149945": [
        {
            "ioc_value": "tehomics.link",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-08-14 16:00:04",
            "last_seen_utc": "2026-06-30 11:21:59",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1149944": [
        {
            "ioc_value": "instant-healthonline.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-08-14 16:00:03",
            "last_seen_utc": "2026-06-30 11:21:59",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1148731": [
        {
            "ioc_value": "stratpringl.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-08-05 14:38:23",
            "last_seen_utc": "2026-06-30 11:21:58",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-1580103824,PINDC-AS",
            "anonymous": "0",
            "reporter": "drb_ra"
        }
    ],
    "1148487": [
        {
            "ioc_value": "onlinetechdesk.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-08-04 11:01:52",
            "last_seen_utc": "2026-06-30 11:21:59",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "AS-COLOCROSSING,CobaltStrike,cs-watermark-587247372",
            "anonymous": "0",
            "reporter": "drb_ra"
        }
    ],
    "1146843": [
        {
            "ioc_value": "harmonyshoused.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-08-03 10:25:44",
            "last_seen_utc": "2026-06-30 11:21:59",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-206546002,HVC-AS",
            "anonymous": "0",
            "reporter": "drb_ra"
        }
    ],
    "1146834": [
        {
            "ioc_value": "api.office-updates.org",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-08-03 10:24:41",
            "last_seen_utc": "2026-06-30 11:21:54",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-494165167,DIGITALOCEAN-ASN",
            "anonymous": "0",
            "reporter": "drb_ra"
        }
    ],
    "1146619": [
        {
            "ioc_value": "mkbkygbgwcdc.buzz",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-08-02 10:24:58",
            "last_seen_utc": "2026-06-30 11:21:58",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-391144938,KAOPU-HK Kaopu Cloud HK Limited",
            "anonymous": "0",
            "reporter": "drb_ra"
        }
    ],
    "1140114": [
        {
            "ioc_value": "tcessolution.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-07-25 10:17:22",
            "last_seen_utc": "2026-06-30 11:21:55",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "AS202973,CobaltStrike,cs-watermark-587247372",
            "anonymous": "0",
            "reporter": "drb_ra"
        }
    ],
    "1138196": [
        {
            "ioc_value": "rw1.sentrysource.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-07-15 12:48:31",
            "last_seen_utc": "2026-06-30 11:21:51",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-93937751,ROGERS-COMMUNICATIONS",
            "anonymous": "0",
            "reporter": "drb_ra"
        }
    ],
    "1135804": [
        {
            "ioc_value": "pedagogists.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-07-03 15:42:02",
            "last_seen_utc": "2026-06-30 11:22:00",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1135803": [
        {
            "ioc_value": "cdnsupply.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-07-03 15:42:01",
            "last_seen_utc": "2026-06-30 11:22:00",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1134787": [
        {
            "ioc_value": "1.15.248.225:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-06-28 22:51:22",
            "last_seen_utc": "2026-06-30 11:21:41",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-987654321,TENCENT-NET-AP Shenzhen Tencent Computer Systems Company Limited",
            "anonymous": "0",
            "reporter": "drb_ra"
        }
    ],
    "1134128": [
        {
            "ioc_value": "check1.judicical.ml",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-06-26 08:12:17",
            "last_seen_utc": "2026-06-30 10:46:22",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CNSERVERS,CobaltStrike,cs-watermark-100000000",
            "anonymous": "0",
            "reporter": "drb_ra"
        }
    ],
    "1134127": [
        {
            "ioc_value": "check.judicical.ml",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-06-26 08:11:33",
            "last_seen_utc": "2026-06-30 10:46:22",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CNSERVERS,CobaltStrike,cs-watermark-100000000",
            "anonymous": "0",
            "reporter": "drb_ra"
        }
    ],
    "1133505": [
        {
            "ioc_value": "usadevgroup.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-06-22 17:12:29",
            "last_seen_utc": "2026-06-30 11:22:00",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-587247372,WAICORE-TRANSIT",
            "anonymous": "0",
            "reporter": "drb_ra"
        }
    ],
    "1128165": [
        {
            "ioc_value": "heastings.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-06-11 22:26:06",
            "last_seen_utc": "2026-06-30 11:22:00",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-206546002,M247",
            "anonymous": "0",
            "reporter": "drb_ra"
        }
    ],
    "1127715": [
        {
            "ioc_value": "unitechdb.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-06-09 20:00:05",
            "last_seen_utc": "2026-06-30 11:22:01",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1127713": [
        {
            "ioc_value": "cornptia.org",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-06-09 20:00:04",
            "last_seen_utc": "2026-06-30 11:22:01",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1127714": [
        {
            "ioc_value": "eyefinancemonitor.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-06-09 20:00:04",
            "last_seen_utc": "2026-06-30 11:22:01",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1127447": [
        {
            "ioc_value": "surplusofer.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-06-08 16:27:41",
            "last_seen_utc": "2026-06-30 11:22:01",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-206546002,HVC-AS",
            "anonymous": "0",
            "reporter": "drb_ra"
        }
    ],
    "1122048": [
        {
            "ioc_value": "dianqi2.dianqi1.jiayongdianqi.xyz",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-05-25 15:42:02",
            "last_seen_utc": "2026-06-30 10:46:23",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-492498911,XNNET LLC",
            "anonymous": "0",
            "reporter": "drb_ra"
        }
    ],
    "1122047": [
        {
            "ioc_value": "dianqi1.dianqi2.jiayongdianqi.xyz",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-05-25 15:41:46",
            "last_seen_utc": "2026-06-30 10:46:22",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-492498911,XNNET LLC",
            "anonymous": "0",
            "reporter": "drb_ra"
        }
    ],
    "1122046": [
        {
            "ioc_value": "dianqi2.jiayongdianqi.xyz",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-05-25 15:41:31",
            "last_seen_utc": "2026-06-30 10:46:23",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-492498911,XNNET LLC",
            "anonymous": "0",
            "reporter": "drb_ra"
        }
    ],
    "1122045": [
        {
            "ioc_value": "dianqi1.jiayongdianqi.xyz",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-05-25 15:41:10",
            "last_seen_utc": "2026-06-30 10:46:23",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-492498911,XNNET LLC",
            "anonymous": "0",
            "reporter": "drb_ra"
        }
    ],
    "1121460": [
        {
            "ioc_value": "update.microsoftapply.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-05-24 19:35:48",
            "last_seen_utc": "2026-06-30 10:46:27",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-Not Found,DediPath",
            "anonymous": "0",
            "reporter": "drb_ra"
        }
    ],
    "1120772": [
        {
            "ioc_value": "australiansuper.xyz",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-05-23 12:37:36",
            "last_seen_utc": "2026-06-30 11:22:00",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "Amazon.com Inc.,CobaltStrike,cs-watermark-348901740",
            "anonymous": "0",
            "reporter": "drb_ra"
        }
    ],
    "1116637": [
        {
            "ioc_value": "sheersdesigns.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-05-16 10:00:03",
            "last_seen_utc": "2026-06-30 11:22:02",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1116636": [
        {
            "ioc_value": "artmicrodesign.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-05-16 10:00:02",
            "last_seen_utc": "2026-06-30 11:22:02",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1112839": [
        {
            "ioc_value": "situotech.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-05-06 16:13:31",
            "last_seen_utc": "2026-06-30 11:22:01",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-587247372,HARMONYHOSTING-AS",
            "anonymous": "0",
            "reporter": "drb_ra"
        }
    ],
    "1111457": [
        {
            "ioc_value": "35.201.196.246:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pupy",
            "malware_alias": "Patpoopy",
            "malware_printable": "pupy",
            "first_seen_utc": "2023-05-05 12:41:05",
            "last_seen_utc": "2026-06-30 10:45:27",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/35.201.196.246",
            "tags": "GOOGLE-CLOUD-PLATFORM,Pupy RAT",
            "anonymous": "0",
            "reporter": "drb_ra"
        }
    ],
    "1110863": [
        {
            "ioc_value": "39.106.36.96:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.deimos",
            "malware_alias": null,
            "malware_printable": "Deimos",
            "first_seen_utc": "2023-05-04 06:46:43",
            "last_seen_utc": "2026-06-30 10:45:31",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/39.106.36.96",
            "tags": "ALIBABA-CN-NET Hangzhou Alibaba Advertising Co.Ltd.,Deimos",
            "anonymous": "0",
            "reporter": "drb_ra"
        }
    ],
    "1110862": [
        {
            "ioc_value": "36.95.131.171:9091",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.deimos",
            "malware_alias": null,
            "malware_printable": "Deimos",
            "first_seen_utc": "2023-05-04 06:46:41",
            "last_seen_utc": "2026-06-30 10:45:28",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/36.95.131.171",
            "tags": "Deimos,TELKOMNET-AS-AP PT Telekomunikasi Indonesia",
            "anonymous": "0",
            "reporter": "drb_ra"
        }
    ],
    "1110860": [
        {
            "ioc_value": "18.162.155.202:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.deimos",
            "malware_alias": null,
            "malware_printable": "Deimos",
            "first_seen_utc": "2023-05-04 06:46:35",
            "last_seen_utc": "2026-06-30 10:43:55",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/18.162.155.202",
            "tags": "AMAZON-02,Deimos",
            "anonymous": "0",
            "reporter": "drb_ra"
        }
    ],
    "1110859": [
        {
            "ioc_value": "8.218.26.114:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.deimos",
            "malware_alias": null,
            "malware_printable": "Deimos",
            "first_seen_utc": "2023-05-04 06:46:33",
            "last_seen_utc": "2026-06-30 10:46:07",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/8.218.26.114",
            "tags": "ALIBABA-CN-NET Alibaba US Technology Co. Ltd.,Deimos",
            "anonymous": "0",
            "reporter": "drb_ra"
        }
    ],
    "1106335": [
        {
            "ioc_value": "maboloud.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-04-22 18:00:03",
            "last_seen_utc": "2026-06-30 11:22:02",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1106336": [
        {
            "ioc_value": "matong.buzz",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-04-22 18:00:03",
            "last_seen_utc": "2026-06-30 11:22:02",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1105988": [
        {
            "ioc_value": "qw.sveexec.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-04-21 10:20:17",
            "last_seen_utc": "2026-06-30 11:22:03",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-1580103824,GLOBALLAYER",
            "anonymous": "0",
            "reporter": "drb_ra"
        }
    ],
    "1103771": [
        {
            "ioc_value": "77.242.250.36:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-04-15 12:28:52",
            "last_seen_utc": "2026-06-30 11:21:46",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-1416875320",
            "anonymous": "0",
            "reporter": "drb_ra"
        }
    ],
    "1102558": [
        {
            "ioc_value": "lls-rs.org",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-04-12 09:02:56",
            "last_seen_utc": "2026-06-30 11:22:03",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-0,PROSPERO-AS",
            "anonymous": "0",
            "reporter": "drb_ra"
        }
    ],
    "1096685": [
        {
            "ioc_value": "iony.top",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-04-03 07:21:03",
            "last_seen_utc": "2026-06-30 11:22:03",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1096686": [
        {
            "ioc_value": "office36o.online",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-04-03 07:21:03",
            "last_seen_utc": "2026-06-30 11:22:04",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1096683": [
        {
            "ioc_value": "feyrijavac.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-04-03 07:21:02",
            "last_seen_utc": "2026-06-30 11:22:03",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1096684": [
        {
            "ioc_value": "fidelyus.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-04-03 07:21:02",
            "last_seen_utc": "2026-06-30 11:22:03",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1095276": [
        {
            "ioc_value": "jacketsupport.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-03-29 22:27:30",
            "last_seen_utc": "2026-06-30 11:22:03",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-587247372,GLOBALLAYER",
            "anonymous": "0",
            "reporter": "drb_ra"
        }
    ],
    "1095042": [
        {
            "ioc_value": "duckducklive.top",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-03-29 04:51:21",
            "last_seen_utc": "2026-06-30 11:22:03",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://www.virustotal.com/gui/file/b5da1db6d69f2f872e603beb0f121c68f3320ed33a0c9835bfc1a931d177c947",
            "tags": "391144938,Beacon,Cobalt Strike,CobaltStrike",
            "anonymous": "0",
            "reporter": "AndreGironda"
        }
    ],
    "1094484": [
        {
            "ioc_value": "louvree.abudhabe.info",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-03-28 15:52:23",
            "last_seen_utc": "2026-06-30 11:21:59",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-1826426664,EMIRATES-INTERNET Emirates Internet",
            "anonymous": "0",
            "reporter": "drb_ra"
        }
    ],
    "1092077": [
        {
            "ioc_value": "jquerymaingame.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-03-20 17:21:02",
            "last_seen_utc": "2026-06-30 11:22:04",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1092078": [
        {
            "ioc_value": "mail-my-account.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-03-20 17:21:02",
            "last_seen_utc": "2026-06-30 11:22:04",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1092079": [
        {
            "ioc_value": "my-accounts-gooogle.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-03-20 17:21:02",
            "last_seen_utc": "2026-06-30 11:22:05",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1092080": [
        {
            "ioc_value": "pegistrationads.site",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-03-20 17:21:02",
            "last_seen_utc": "2026-06-30 11:22:05",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1092075": [
        {
            "ioc_value": "eaglehardwares.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-03-20 17:21:01",
            "last_seen_utc": "2026-06-30 11:22:04",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1092076": [
        {
            "ioc_value": "information.baby",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-03-20 17:21:01",
            "last_seen_utc": "2026-06-30 11:22:04",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1092009": [
        {
            "ioc_value": "moviegallerys.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-03-20 13:36:29",
            "last_seen_utc": "2026-06-30 11:22:04",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-206546002,UAB Cherry Servers",
            "anonymous": "0",
            "reporter": "drb_ra"
        }
    ],
    "1091575": [
        {
            "ioc_value": "acroserver.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-03-17 22:40:17",
            "last_seen_utc": "2026-06-30 11:22:04",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-674054486,Flyservers S.A.",
            "anonymous": "0",
            "reporter": "drb_ra"
        }
    ],
    "1091535": [
        {
            "ioc_value": "atechniques.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-03-17 19:45:49",
            "last_seen_utc": "2026-06-30 11:22:04",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "AEZA-AS,CobaltStrike,cs-watermark-674054486",
            "anonymous": "0",
            "reporter": "drb_ra"
        }
    ],
    "1091454": [
        {
            "ioc_value": "winsatoom.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-03-17 13:33:15",
            "last_seen_utc": "2026-06-30 11:22:05",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "AS-CHOOPA,CobaltStrike,cs-watermark-668694132",
            "anonymous": "0",
            "reporter": "drb_ra"
        }
    ],
    "1087542": [
        {
            "ioc_value": "devoinnanote.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-03-13 04:47:12",
            "last_seen_utc": "2026-06-30 11:22:04",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-2130772225,SHARKTECH",
            "anonymous": "0",
            "reporter": "drb_ra"
        }
    ],
    "1082976": [
        {
            "ioc_value": "ponzinivek.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-02-26 09:03:09",
            "last_seen_utc": "2026-06-30 11:22:06",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1082977": [
        {
            "ioc_value": "ruplearben.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-02-26 09:03:09",
            "last_seen_utc": "2026-06-30 11:22:06",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1082978": [
        {
            "ioc_value": "talonbilling.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-02-26 09:03:09",
            "last_seen_utc": "2026-06-30 11:22:06",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1082979": [
        {
            "ioc_value": "gorillagaz.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-02-26 09:03:09",
            "last_seen_utc": "2026-06-30 11:22:06",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1082980": [
        {
            "ioc_value": "chanimoblie.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-02-26 09:03:09",
            "last_seen_utc": "2026-06-30 11:22:07",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1082871": [
        {
            "ioc_value": "kbnexc.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-02-25 14:42:02",
            "last_seen_utc": "2026-06-30 11:22:06",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1082870": [
        {
            "ioc_value": "jquerysslx.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-02-25 14:42:01",
            "last_seen_utc": "2026-06-30 11:22:06",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1082838": [
        {
            "ioc_value": "e-servicesolutions.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-02-25 13:15:07",
            "last_seen_utc": "2026-06-30 11:22:04",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "AEZA GROUP Ltd,CobaltStrike,cs-watermark-674054486",
            "anonymous": "0",
            "reporter": "drb_ra"
        }
    ],
    "1082591": [
        {
            "ioc_value": "devsecurityservices.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-02-24 02:30:56",
            "last_seen_utc": "2026-06-30 11:22:05",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-674054486,Flyservers S.A.",
            "anonymous": "0",
            "reporter": "drb_ra"
        }
    ],
    "1082417": [
        {
            "ioc_value": "www.vmware.rest",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-02-23 13:06:07",
            "last_seen_utc": "2026-06-30 11:22:07",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "AS-CHOOPA,CobaltStrike,cs-watermark-1234567890",
            "anonymous": "0",
            "reporter": "drb_ra"
        }
    ],
    "1081018": [
        {
            "ioc_value": "galspost.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-02-17 18:25:01",
            "last_seen_utc": "2026-06-30 11:22:05",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-1101991775,Microsoft Corporation",
            "anonymous": "0",
            "reporter": "drb_ra"
        }
    ],
    "1080735": [
        {
            "ioc_value": "imvcatool.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-02-16 14:54:22",
            "last_seen_utc": "2026-06-30 11:22:05",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "AEZA-AS,CobaltStrike,cs-watermark-674054486",
            "anonymous": "0",
            "reporter": "drb_ra"
        }
    ],
    "1078198": [
        {
            "ioc_value": "aspnetcenter.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-02-04 19:39:46",
            "last_seen_utc": "2026-06-30 11:22:07",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,Web Gostaran Bandar Company PJS",
            "anonymous": "0",
            "reporter": "drb_ra"
        }
    ],
    "1078172": [
        {
            "ioc_value": "audelr.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-02-04 18:42:02",
            "last_seen_utc": "2026-06-30 11:22:07",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1078173": [
        {
            "ioc_value": "csou.link",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-02-04 18:42:02",
            "last_seen_utc": "2026-06-30 11:22:07",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1078174": [
        {
            "ioc_value": "integrated-security.net",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-02-04 18:42:02",
            "last_seen_utc": "2026-06-30 11:22:08",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1078175": [
        {
            "ioc_value": "uranustechsolution.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-02-04 18:42:02",
            "last_seen_utc": "2026-06-30 11:22:08",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1078062": [
        {
            "ioc_value": "getsafeblog.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-02-03 17:24:39",
            "last_seen_utc": "2026-06-30 11:22:07",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,PLI-AS",
            "anonymous": "0",
            "reporter": "drb_ra"
        }
    ],
    "1076907": [
        {
            "ioc_value": "qw.svcshosvt.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-02-02 19:40:26",
            "last_seen_utc": "2026-06-30 11:22:06",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CHERRYSERVERS2-AS,CobaltStrike",
            "anonymous": "0",
            "reporter": "drb_ra"
        }
    ],
    "1076896": [
        {
            "ioc_value": "nxsimdevelop.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-02-02 19:39:18",
            "last_seen_utc": "2026-06-30 11:22:06",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "AEZA-AS,CobaltStrike",
            "anonymous": "0",
            "reporter": "drb_ra"
        }
    ],
    "1075651": [
        {
            "ioc_value": "appdevtechnology.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-02-01 02:21:19",
            "last_seen_utc": "2026-06-30 11:22:05",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "AEZA-AS,CobaltStrike",
            "anonymous": "0",
            "reporter": "drb_ra"
        }
    ],
    "1075540": [
        {
            "ioc_value": "dbx.formsift.io",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-01-31 15:09:13",
            "last_seen_utc": "2026-06-30 11:22:05",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "Amazon.com Inc.,CobaltStrike",
            "anonymous": "0",
            "reporter": "drb_ra"
        }
    ],
    "1075020": [
        {
            "ioc_value": "devcloudpro.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-01-29 11:29:55",
            "last_seen_utc": "2026-06-30 11:22:08",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,FLYSERVERS-ENDCLIENTS",
            "anonymous": "0",
            "reporter": "drb_ra"
        }
    ],
    "1074894": [
        {
            "ioc_value": "164.90.158.199:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2023-01-28 09:40:24",
            "last_seen_utc": "2026-06-30 10:43:43",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/164.90.158.199",
            "tags": "DIGITALOCEAN-ASN,Mythic",
            "anonymous": "0",
            "reporter": "drb_ra"
        }
    ],
    "1074890": [
        {
            "ioc_value": "145.131.8.169:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2023-01-28 09:40:10",
            "last_seen_utc": "2026-06-30 10:43:27",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/145.131.8.169",
            "tags": "Mythic,SENTIA",
            "anonymous": "0",
            "reporter": "drb_ra"
        }
    ],
    "1074833": [
        {
            "ioc_value": "130.61.124.23:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2023-01-28 09:26:29",
            "last_seen_utc": "2026-06-30 10:43:21",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/130.61.124.23",
            "tags": "Covenant,ORACLE-BMC-31898",
            "anonymous": "0",
            "reporter": "drb_ra"
        }
    ],
    "1074144": [
        {
            "ioc_value": "support-wellsfargovis.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-01-25 19:42:03",
            "last_seen_utc": "2026-06-30 11:22:08",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1074141": [
        {
            "ioc_value": "recoverporta1.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-01-25 19:42:02",
            "last_seen_utc": "2026-06-30 11:22:08",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1074142": [
        {
            "ioc_value": "recoverportal2.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-01-25 19:42:02",
            "last_seen_utc": "2026-06-30 11:22:08",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1074143": [
        {
            "ioc_value": "recoveryweb2.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-01-25 19:42:02",
            "last_seen_utc": "2026-06-30 11:22:08",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1073670": [
        {
            "ioc_value": "vd-ntds.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-01-23 20:33:42",
            "last_seen_utc": "2026-06-30 11:22:07",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,PROSPERO-AS",
            "anonymous": "0",
            "reporter": "drb_ra"
        }
    ],
    "1070164": [
        {
            "ioc_value": "hnsxpharm.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-01-20 14:21:02",
            "last_seen_utc": "2026-06-30 11:22:09",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1070165": [
        {
            "ioc_value": "myjqueryss.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-01-20 14:21:02",
            "last_seen_utc": "2026-06-30 11:22:09",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1070167": [
        {
            "ioc_value": "telusmobility-billed.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-01-20 14:21:02",
            "last_seen_utc": "2026-06-30 11:22:10",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1070168": [
        {
            "ioc_value": "thenbkgroup.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-01-20 14:21:02",
            "last_seen_utc": "2026-06-30 11:22:10",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1070137": [
        {
            "ioc_value": "avdev.net",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-01-20 11:23:14",
            "last_seen_utc": "2026-06-30 11:22:08",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,Flyservers S.A.",
            "anonymous": "0",
            "reporter": "drb_ra"
        }
    ],
    "1069980": [
        {
            "ioc_value": "qw.execsvct.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-01-19 19:53:20",
            "last_seen_utc": "2026-06-30 11:22:08",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CHERRYSERVERS2-AS,CobaltStrike",
            "anonymous": "0",
            "reporter": "drb_ra"
        }
    ],
    "1069895": [
        {
            "ioc_value": "azurecloudfire.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-01-19 14:15:53",
            "last_seen_utc": "2026-06-30 11:22:08",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,ITRESHENIYA-AS",
            "anonymous": "0",
            "reporter": "drb_ra"
        }
    ],
    "1069868": [
        {
            "ioc_value": "goupdatemic.online",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-01-19 11:23:42",
            "last_seen_utc": "2026-06-30 11:22:09",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,GOOGLE",
            "anonymous": "0",
            "reporter": "drb_ra"
        }
    ],
    "1069579": [
        {
            "ioc_value": "mwg-update.cloud",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-01-18 02:29:29",
            "last_seen_utc": "2026-06-30 11:22:09",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,HVC-AS",
            "anonymous": "0",
            "reporter": "drb_ra"
        }
    ],
    "1068206": [
        {
            "ioc_value": "goodsport2023.win",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-01-13 17:37:32",
            "last_seen_utc": "2026-06-30 11:22:09",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,VOM",
            "anonymous": "0",
            "reporter": "drb_ra"
        }
    ],
    "1068079": [
        {
            "ioc_value": "blackandwhiteshoose.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-01-12 21:56:23",
            "last_seen_utc": "2026-06-30 11:22:09",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CHERRYSERVERS3-AS,CobaltStrike",
            "anonymous": "0",
            "reporter": "drb_ra"
        }
    ],
    "1068045": [
        {
            "ioc_value": "qw.svcrencst.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-01-12 20:55:06",
            "last_seen_utc": "2026-06-30 11:22:10",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CHERRYSERVERS2-AS,CobaltStrike",
            "anonymous": "0",
            "reporter": "drb_ra"
        }
    ],
    "1067954": [
        {
            "ioc_value": "realsecuritystore.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-01-12 14:45:18",
            "last_seen_utc": "2026-06-30 11:22:09",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,Private Layer INC",
            "anonymous": "0",
            "reporter": "drb_ra"
        }
    ],
    "1067924": [
        {
            "ioc_value": "fixx.sbs",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-01-12 13:04:56",
            "last_seen_utc": "2026-06-30 11:22:06",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,SNEL",
            "anonymous": "0",
            "reporter": "drb_ra"
        }
    ],
    "1067646": [
        {
            "ioc_value": "allowedcloud.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-01-11 10:59:45",
            "last_seen_utc": "2026-06-30 11:22:07",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,HIVELOCITY Inc.",
            "anonymous": "0",
            "reporter": "drb_ra"
        }
    ],
    "1064196": [
        {
            "ioc_value": "freegaysnews.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-31 19:48:39",
            "last_seen_utc": "2026-06-30 11:22:10",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CHERRYSERVERS2-AS,CobaltStrike",
            "anonymous": "0",
            "reporter": "drb_ra"
        }
    ],
    "1064176": [
        {
            "ioc_value": "topgamenetwork.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-31 18:58:09",
            "last_seen_utc": "2026-06-30 11:22:10",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,UAB Cherry Servers",
            "anonymous": "0",
            "reporter": "drb_ra"
        }
    ],
    "1064173": [
        {
            "ioc_value": "zfuxwvouqvnttpsrxe.tech",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-31 16:21:02",
            "last_seen_utc": "2026-06-30 11:22:11",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1064075": [
        {
            "ioc_value": "cloudyspaces.net",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:52",
            "last_seen_utc": "2026-06-30 11:23:13",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1064076": [
        {
            "ioc_value": "666621.xyz",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:52",
            "last_seen_utc": "2026-06-30 11:23:13",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1064069": [
        {
            "ioc_value": "144.217.207.19:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:51",
            "last_seen_utc": "2026-06-30 11:23:12",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1064070": [
        {
            "ioc_value": "allsdone.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:51",
            "last_seen_utc": "2026-06-30 11:23:12",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1064071": [
        {
            "ioc_value": "ipsandwich.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:51",
            "last_seen_utc": "2026-06-30 11:23:13",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1064072": [
        {
            "ioc_value": "cookieholder.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:51",
            "last_seen_utc": "2026-06-30 11:23:13",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1064073": [
        {
            "ioc_value": "pingcheker.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:51",
            "last_seen_utc": "2026-06-30 11:23:13",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1064074": [
        {
            "ioc_value": "wagonovk.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:51",
            "last_seen_utc": "2026-06-30 11:23:13",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1064062": [
        {
            "ioc_value": "microsoftupdateassist.net",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:50",
            "last_seen_utc": "2026-06-30 11:23:11",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1064063": [
        {
            "ioc_value": "qvibova.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:50",
            "last_seen_utc": "2026-06-30 11:23:11",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1064064": [
        {
            "ioc_value": "cloudwebpictures.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:50",
            "last_seen_utc": "2026-06-30 11:23:11",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1064065": [
        {
            "ioc_value": "metalkost.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:50",
            "last_seen_utc": "2026-06-30 11:23:11",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1064066": [
        {
            "ioc_value": "m7r4r2i2.stackpathcdn.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:50",
            "last_seen_utc": "2026-06-30 11:23:11",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1064067": [
        {
            "ioc_value": "online.cloudwebpictures.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:50",
            "last_seen_utc": "2026-06-30 11:23:11",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1064057": [
        {
            "ioc_value": "bartiba.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:49",
            "last_seen_utc": "2026-06-30 11:23:09",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1064058": [
        {
            "ioc_value": "varnart.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:49",
            "last_seen_utc": "2026-06-30 11:23:09",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1064059": [
        {
            "ioc_value": "nsfdfdfdf.xyz",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:49",
            "last_seen_utc": "2026-06-30 11:23:10",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1064060": [
        {
            "ioc_value": "micorsoft.cloud",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:49",
            "last_seen_utc": "2026-06-30 11:23:10",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1064061": [
        {
            "ioc_value": "aigouing.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:49",
            "last_seen_utc": "2026-06-30 11:23:10",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1064046": [
        {
            "ioc_value": "ksplsoft.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:48",
            "last_seen_utc": "2026-06-30 11:23:09",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1064047": [
        {
            "ioc_value": "lastinsuranceteam.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:48",
            "last_seen_utc": "2026-06-30 11:23:09",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1064048": [
        {
            "ioc_value": "msdnsservice.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:48",
            "last_seen_utc": "2026-06-30 11:23:08",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1064049": [
        {
            "ioc_value": "securequoteme.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:48",
            "last_seen_utc": "2026-06-30 11:23:09",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1064050": [
        {
            "ioc_value": "techdevcorp.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:48",
            "last_seen_utc": "2026-06-30 11:23:09",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1064051": [
        {
            "ioc_value": "syncorporation.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:48",
            "last_seen_utc": "2026-06-30 11:23:09",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1064052": [
        {
            "ioc_value": "visualstudioapp.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:48",
            "last_seen_utc": "2026-06-30 11:23:08",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1064053": [
        {
            "ioc_value": "altreeservicellc.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:48",
            "last_seen_utc": "2026-06-30 11:23:08",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1064054": [
        {
            "ioc_value": "discountshadesdirect.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:48",
            "last_seen_utc": "2026-06-30 11:23:09",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1064055": [
        {
            "ioc_value": "setechnowork.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:48",
            "last_seen_utc": "2026-06-30 11:23:09",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1064056": [
        {
            "ioc_value": "technicollit.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:48",
            "last_seen_utc": "2026-06-30 11:23:09",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1064038": [
        {
            "ioc_value": "shiyicaster.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:47",
            "last_seen_utc": "2026-06-30 11:23:07",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1064039": [
        {
            "ioc_value": "cdn-top.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:47",
            "last_seen_utc": "2026-06-30 11:23:10",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1064040": [
        {
            "ioc_value": "onesecondservice.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:47",
            "last_seen_utc": "2026-06-30 11:23:07",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1064041": [
        {
            "ioc_value": "vpnupdaters.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:47",
            "last_seen_utc": "2026-06-30 11:23:07",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1064042": [
        {
            "ioc_value": "rodinscoldly.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:47",
            "last_seen_utc": "2026-06-30 11:23:07",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1064043": [
        {
            "ioc_value": "antariscapital.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:47",
            "last_seen_utc": "2026-06-30 11:23:07",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1064044": [
        {
            "ioc_value": "ftwealthmgt.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:47",
            "last_seen_utc": "2026-06-30 11:23:08",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1064045": [
        {
            "ioc_value": "iconiq-capitel.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:47",
            "last_seen_utc": "2026-06-30 11:23:08",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1064031": [
        {
            "ioc_value": "asset-trades.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:46",
            "last_seen_utc": "2026-06-30 11:23:05",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1064032": [
        {
            "ioc_value": "telemetrin.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:46",
            "last_seen_utc": "2026-06-30 11:23:06",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1064033": [
        {
            "ioc_value": "secupdate4win.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:46",
            "last_seen_utc": "2026-06-30 11:23:06",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1064034": [
        {
            "ioc_value": "cdn-start.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:46",
            "last_seen_utc": "2026-06-30 11:23:06",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1064035": [
        {
            "ioc_value": "capitalmanagementdata.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:46",
            "last_seen_utc": "2026-06-30 11:23:10",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1064036": [
        {
            "ioc_value": "lawsolutions.cloud",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:46",
            "last_seen_utc": "2026-06-30 11:23:06",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1064024": [
        {
            "ioc_value": "diegomaster.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:45",
            "last_seen_utc": "2026-06-30 11:23:04",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1064025": [
        {
            "ioc_value": "dp-test1.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:45",
            "last_seen_utc": "2026-06-30 11:23:04",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1064026": [
        {
            "ioc_value": "cloudkey.digital",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:45",
            "last_seen_utc": "2026-06-30 11:23:05",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1064027": [
        {
            "ioc_value": "updatevpncitrix.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:45",
            "last_seen_utc": "2026-06-30 11:23:05",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1064028": [
        {
            "ioc_value": "classgum.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:45",
            "last_seen_utc": "2026-06-30 11:23:05",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1064029": [
        {
            "ioc_value": "edgeupdater.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:45",
            "last_seen_utc": "2026-06-30 11:23:05",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1064030": [
        {
            "ioc_value": "gfcbm.xyz",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:45",
            "last_seen_utc": "2026-06-30 11:23:05",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1064016": [
        {
            "ioc_value": "barmnava.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:44",
            "last_seen_utc": "2026-06-30 11:23:03",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1064017": [
        {
            "ioc_value": "firewallwithadvancedserurity.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:44",
            "last_seen_utc": "2026-06-30 11:23:03",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1064018": [
        {
            "ioc_value": "lgbtqplusfriendlydomain.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:44",
            "last_seen_utc": "2026-06-30 11:23:03",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1064019": [
        {
            "ioc_value": "market-stats.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:44",
            "last_seen_utc": "2026-06-30 11:23:03",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1064020": [
        {
            "ioc_value": "apabfs.icu",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:44",
            "last_seen_utc": "2026-06-30 11:23:03",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1064021": [
        {
            "ioc_value": "fziomerof.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:44",
            "last_seen_utc": "2026-06-30 11:23:03",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1064022": [
        {
            "ioc_value": "fserd.icu",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:44",
            "last_seen_utc": "2026-06-30 11:23:04",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1064023": [
        {
            "ioc_value": "verofes.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:44",
            "last_seen_utc": "2026-06-30 11:23:04",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1064015": [
        {
            "ioc_value": "postofficeltdc.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:43",
            "last_seen_utc": "2026-06-30 11:22:59",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1064006": [
        {
            "ioc_value": "jarvcza.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:42",
            "last_seen_utc": "2026-06-30 11:22:58",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1064007": [
        {
            "ioc_value": "teystyjeem.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:42",
            "last_seen_utc": "2026-06-30 11:23:07",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1064008": [
        {
            "ioc_value": "faceupfinder.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:42",
            "last_seen_utc": "2026-06-30 11:22:58",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1064009": [
        {
            "ioc_value": "costacancordia.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:42",
            "last_seen_utc": "2026-06-30 11:23:06",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1064010": [
        {
            "ioc_value": "lapsusareskids.world",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:42",
            "last_seen_utc": "2026-06-30 11:22:59",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1064011": [
        {
            "ioc_value": "msupdater.net",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:42",
            "last_seen_utc": "2026-06-30 11:22:59",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1064012": [
        {
            "ioc_value": "dwordname.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:42",
            "last_seen_utc": "2026-06-30 11:22:59",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1064013": [
        {
            "ioc_value": "trademot.finance",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:42",
            "last_seen_utc": "2026-06-30 11:22:59",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1064014": [
        {
            "ioc_value": "agreminj.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:42",
            "last_seen_utc": "2026-06-30 11:22:59",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1063998": [
        {
            "ioc_value": "exchangeallltd.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:41",
            "last_seen_utc": "2026-06-30 11:22:57",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1063999": [
        {
            "ioc_value": "guggenheimpartners-survey.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:41",
            "last_seen_utc": "2026-06-30 11:22:57",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1064000": [
        {
            "ioc_value": "caresalonservices.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:41",
            "last_seen_utc": "2026-06-30 11:22:57",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1064001": [
        {
            "ioc_value": "just-findncall.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:41",
            "last_seen_utc": "2026-06-30 11:22:57",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1064002": [
        {
            "ioc_value": "fluoxi.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:41",
            "last_seen_utc": "2026-06-30 11:22:57",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1064003": [
        {
            "ioc_value": "buynet.digital",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:41",
            "last_seen_utc": "2026-06-30 11:22:57",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1064004": [
        {
            "ioc_value": "everythingchecker.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:41",
            "last_seen_utc": "2026-06-30 11:22:58",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1064005": [
        {
            "ioc_value": "dezword.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:41",
            "last_seen_utc": "2026-06-30 11:22:58",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1063995": [
        {
            "ioc_value": "goksearch.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:40",
            "last_seen_utc": "2026-06-30 11:22:56",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1063996": [
        {
            "ioc_value": "polyhaz.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:40",
            "last_seen_utc": "2026-06-30 11:22:57",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1063997": [
        {
            "ioc_value": "data-protection-test.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:40",
            "last_seen_utc": "2026-06-30 11:22:57",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1063992": [
        {
            "ioc_value": "update04.microsoft-essentials.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:39",
            "last_seen_utc": "2026-06-30 11:22:55",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1063991": [
        {
            "ioc_value": "akaluij.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:38",
            "last_seen_utc": "2026-06-30 11:22:57",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1063989": [
        {
            "ioc_value": "43.129.7.189:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:36",
            "last_seen_utc": "2026-06-30 11:22:49",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1063990": [
        {
            "ioc_value": "82.156.241.148:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:36",
            "last_seen_utc": "2026-06-30 11:22:55",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1063985": [
        {
            "ioc_value": "donormix.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:33",
            "last_seen_utc": "2026-06-30 11:22:44",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1063986": [
        {
            "ioc_value": "hardicki.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:33",
            "last_seen_utc": "2026-06-30 11:23:03",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1063987": [
        {
            "ioc_value": "stfconnect.onthewifi.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:33",
            "last_seen_utc": "2026-06-30 11:22:57",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1063988": [
        {
            "ioc_value": "agsdef.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:33",
            "last_seen_utc": "2026-06-30 11:22:53",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1063978": [
        {
            "ioc_value": "observerinfo.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:32",
            "last_seen_utc": "2026-06-30 11:22:45",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1063979": [
        {
            "ioc_value": "dehikz.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:32",
            "last_seen_utc": "2026-06-30 11:22:44",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1063980": [
        {
            "ioc_value": "cocanewline.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:32",
            "last_seen_utc": "2026-06-30 11:22:44",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1063981": [
        {
            "ioc_value": "rainqor.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:32",
            "last_seen_utc": "2026-06-30 11:22:44",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1063982": [
        {
            "ioc_value": "axelkim.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:32",
            "last_seen_utc": "2026-06-30 11:22:59",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1063983": [
        {
            "ioc_value": "azimurs.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:32",
            "last_seen_utc": "2026-06-30 11:22:57",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1063984": [
        {
            "ioc_value": "innovativesitecreations.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:32",
            "last_seen_utc": "2026-06-30 11:22:44",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1063972": [
        {
            "ioc_value": "creditscore.usbankcreditcards.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:31",
            "last_seen_utc": "2026-06-30 11:22:42",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1063975": [
        {
            "ioc_value": "megumin.tech",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:31",
            "last_seen_utc": "2026-06-30 11:22:43",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1063976": [
        {
            "ioc_value": "loanhelp.support",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:31",
            "last_seen_utc": "2026-06-30 11:22:43",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1063977": [
        {
            "ioc_value": "volsecure.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:31",
            "last_seen_utc": "2026-06-30 11:22:46",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1063966": [
        {
            "ioc_value": "domtern.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:30",
            "last_seen_utc": "2026-06-30 11:22:41",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1063968": [
        {
            "ioc_value": "drakr.icu",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:30",
            "last_seen_utc": "2026-06-30 11:22:45",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1063969": [
        {
            "ioc_value": "devcisco.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:30",
            "last_seen_utc": "2026-06-30 11:22:42",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1063971": [
        {
            "ioc_value": "web-news-blog.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:30",
            "last_seen_utc": "2026-06-30 11:22:42",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1063963": [
        {
            "ioc_value": "bankafrika.org",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:29",
            "last_seen_utc": "2026-06-30 11:22:39",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1063964": [
        {
            "ioc_value": "mssfr.icu",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:29",
            "last_seen_utc": "2026-06-30 11:22:40",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1063965": [
        {
            "ioc_value": "edgekey.tech",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:29",
            "last_seen_utc": "2026-06-30 11:22:40",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1063955": [
        {
            "ioc_value": "webyoutubeshop.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:28",
            "last_seen_utc": "2026-06-30 11:22:38",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1063956": [
        {
            "ioc_value": "extic.icu",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:28",
            "last_seen_utc": "2026-06-30 11:22:38",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1063957": [
        {
            "ioc_value": "reykh.icu",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:28",
            "last_seen_utc": "2026-06-30 11:22:38",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1063959": [
        {
            "ioc_value": "propertynewsclub.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:28",
            "last_seen_utc": "2026-06-30 11:22:39",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1063960": [
        {
            "ioc_value": "afindisc.xyz",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:28",
            "last_seen_utc": "2026-06-30 11:22:39",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1063961": [
        {
            "ioc_value": "propertyinfogroup.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:28",
            "last_seen_utc": "2026-06-30 11:22:39",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1063962": [
        {
            "ioc_value": "topnewscompany.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:28",
            "last_seen_utc": "2026-06-30 11:22:39",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1063950": [
        {
            "ioc_value": "baidenfree.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:27",
            "last_seen_utc": "2026-06-30 11:22:36",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1063951": [
        {
            "ioc_value": "directoryupdate.net",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:27",
            "last_seen_utc": "2026-06-30 11:22:36",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1063952": [
        {
            "ioc_value": "azmnetwork.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:27",
            "last_seen_utc": "2026-06-30 11:22:37",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1063953": [
        {
            "ioc_value": "onevisioncommunications.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:27",
            "last_seen_utc": "2026-06-30 11:22:37",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1063954": [
        {
            "ioc_value": "campioni-imam.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:27",
            "last_seen_utc": "2026-06-30 11:22:37",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1063943": [
        {
            "ioc_value": "serviceapp1.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:26",
            "last_seen_utc": "2026-06-30 11:22:35",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1063944": [
        {
            "ioc_value": "softcloud.digital",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:26",
            "last_seen_utc": "2026-06-30 11:22:35",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1063945": [
        {
            "ioc_value": "appmind.center",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:26",
            "last_seen_utc": "2026-06-30 11:22:35",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1063946": [
        {
            "ioc_value": "ms-data.online",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:26",
            "last_seen_utc": "2026-06-30 11:22:36",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1063947": [
        {
            "ioc_value": "oracleup.cc",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:26",
            "last_seen_utc": "2026-06-30 11:22:36",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1063948": [
        {
            "ioc_value": "topinfocompany.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:26",
            "last_seen_utc": "2026-06-30 11:22:36",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1063949": [
        {
            "ioc_value": "blockchainstartups-crypto.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:26",
            "last_seen_utc": "2026-06-30 11:22:36",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1063934": [
        {
            "ioc_value": "expresssmash.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:25",
            "last_seen_utc": "2026-06-30 11:22:34",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1063935": [
        {
            "ioc_value": "vgroz.icu",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:25",
            "last_seen_utc": "2026-06-30 11:22:36",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1063936": [
        {
            "ioc_value": "baidengop.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:25",
            "last_seen_utc": "2026-06-30 11:22:34",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1063937": [
        {
            "ioc_value": "ofilopex.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:25",
            "last_seen_utc": "2026-06-30 11:22:34",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1063938": [
        {
            "ioc_value": "aabancaa.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:25",
            "last_seen_utc": "2026-06-30 11:22:34",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1063939": [
        {
            "ioc_value": "shermango.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:25",
            "last_seen_utc": "2026-06-30 11:22:35",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1063940": [
        {
            "ioc_value": "nongxinyin.xyz",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:25",
            "last_seen_utc": "2026-06-30 11:22:35",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1063941": [
        {
            "ioc_value": "a6m1n.xyz",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:25",
            "last_seen_utc": "2026-06-30 11:22:35",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1063942": [
        {
            "ioc_value": "emailbox.icu",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:25",
            "last_seen_utc": "2026-06-30 11:22:35",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1063926": [
        {
            "ioc_value": "wxtencent.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:24",
            "last_seen_utc": "2026-06-30 11:22:33",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1063927": [
        {
            "ioc_value": "emergeno.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:24",
            "last_seen_utc": "2026-06-30 11:22:33",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1063928": [
        {
            "ioc_value": "browngreeer.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:24",
            "last_seen_utc": "2026-06-30 11:22:33",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1063929": [
        {
            "ioc_value": "processdec.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:24",
            "last_seen_utc": "2026-06-30 11:22:33",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1063931": [
        {
            "ioc_value": "sndm-sndm.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:24",
            "last_seen_utc": "2026-06-30 11:22:33",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1063932": [
        {
            "ioc_value": "sinergil.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:24",
            "last_seen_utc": "2026-06-30 11:22:34",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1063933": [
        {
            "ioc_value": "vinergil.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:24",
            "last_seen_utc": "2026-06-30 11:22:34",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1063918": [
        {
            "ioc_value": "westtherr.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:23",
            "last_seen_utc": "2026-06-30 11:22:32",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1063919": [
        {
            "ioc_value": "quickaccestwo.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:23",
            "last_seen_utc": "2026-06-30 11:22:32",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1063920": [
        {
            "ioc_value": "usgrim.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:23",
            "last_seen_utc": "2026-06-30 11:22:32",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1063921": [
        {
            "ioc_value": "onelivemusicshop.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:23",
            "last_seen_utc": "2026-06-30 11:22:32",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1063922": [
        {
            "ioc_value": "zomerax.top",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:23",
            "last_seen_utc": "2026-06-30 11:22:32",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1063923": [
        {
            "ioc_value": "fsamon.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:23",
            "last_seen_utc": "2026-06-30 11:22:32",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1063924": [
        {
            "ioc_value": "sscimails.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:23",
            "last_seen_utc": "2026-06-30 11:22:33",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1063925": [
        {
            "ioc_value": "agentrecovery.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:23",
            "last_seen_utc": "2026-06-30 11:22:38",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1063909": [
        {
            "ioc_value": "entertainok.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:22",
            "last_seen_utc": "2026-06-30 11:22:30",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1063910": [
        {
            "ioc_value": "jatafatuna.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:22",
            "last_seen_utc": "2026-06-30 11:22:31",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1063911": [
        {
            "ioc_value": "pluyk.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:22",
            "last_seen_utc": "2026-06-30 11:22:31",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1063912": [
        {
            "ioc_value": "affinm.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:22",
            "last_seen_utc": "2026-06-30 11:22:31",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1063913": [
        {
            "ioc_value": "gijoxupe.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:22",
            "last_seen_utc": "2026-06-30 11:22:31",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1063914": [
        {
            "ioc_value": "vangshares.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:22",
            "last_seen_utc": "2026-06-30 11:22:33",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1063915": [
        {
            "ioc_value": "fudupdate.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:22",
            "last_seen_utc": "2026-06-30 11:22:31",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1063917": [
        {
            "ioc_value": "contemporaryto.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:22",
            "last_seen_utc": "2026-06-30 11:22:31",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1063902": [
        {
            "ioc_value": "ziono.xyz",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:21",
            "last_seen_utc": "2026-06-30 11:22:29",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1063903": [
        {
            "ioc_value": "lolutow.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:21",
            "last_seen_utc": "2026-06-30 11:22:30",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1063904": [
        {
            "ioc_value": "niht12.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:21",
            "last_seen_utc": "2026-06-30 11:22:30",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1063905": [
        {
            "ioc_value": "slfcorporate.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:21",
            "last_seen_utc": "2026-06-30 11:22:30",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1063906": [
        {
            "ioc_value": "baidu-cdn-10.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:21",
            "last_seen_utc": "2026-06-30 11:22:30",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1063907": [
        {
            "ioc_value": "jandoz.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:21",
            "last_seen_utc": "2026-06-30 11:22:30",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1063908": [
        {
            "ioc_value": "casevor.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:21",
            "last_seen_utc": "2026-06-30 11:22:30",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1063897": [
        {
            "ioc_value": "gotroops.online",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:20",
            "last_seen_utc": "2026-06-30 11:22:28",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1063898": [
        {
            "ioc_value": "wtxservice.net",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:20",
            "last_seen_utc": "2026-06-30 11:22:29",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1063899": [
        {
            "ioc_value": "xevayuhace.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:20",
            "last_seen_utc": "2026-06-30 11:22:29",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1063900": [
        {
            "ioc_value": "suppcat.online",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:20",
            "last_seen_utc": "2026-06-30 11:22:29",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1063901": [
        {
            "ioc_value": "softloadup.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:20",
            "last_seen_utc": "2026-06-30 11:22:29",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1063889": [
        {
            "ioc_value": "asbetysh.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:19",
            "last_seen_utc": "2026-06-30 11:22:27",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1063890": [
        {
            "ioc_value": "ascagliarinish.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:19",
            "last_seen_utc": "2026-06-30 11:22:27",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1063891": [
        {
            "ioc_value": "ascasdsh.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:19",
            "last_seen_utc": "2026-06-30 11:22:27",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1063892": [
        {
            "ioc_value": "aschamp79sh.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:19",
            "last_seen_utc": "2026-06-30 11:22:27",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1063893": [
        {
            "ioc_value": "aschnurmansh.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:19",
            "last_seen_utc": "2026-06-30 11:22:27",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1063894": [
        {
            "ioc_value": "aseleeeksh.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:19",
            "last_seen_utc": "2026-06-30 11:22:27",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1063895": [
        {
            "ioc_value": "asensvsh.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:19",
            "last_seen_utc": "2026-06-30 11:22:27",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1063880": [
        {
            "ioc_value": "artist2actresssh.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:18",
            "last_seen_utc": "2026-06-30 11:22:26",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1063881": [
        {
            "ioc_value": "arturprikhodkosh.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:18",
            "last_seen_utc": "2026-06-30 11:22:26",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1063882": [
        {
            "ioc_value": "arvin78sh.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:18",
            "last_seen_utc": "2026-06-30 11:22:26",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1063883": [
        {
            "ioc_value": "arvind567shahsh.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:18",
            "last_seen_utc": "2026-06-30 11:22:26",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1063884": [
        {
            "ioc_value": "arvindkkumsh.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:18",
            "last_seen_utc": "2026-06-30 11:22:26",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1063885": [
        {
            "ioc_value": "arvosash.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:18",
            "last_seen_utc": "2026-06-30 11:22:26",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1063886": [
        {
            "ioc_value": "arwalsersh.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:18",
            "last_seen_utc": "2026-06-30 11:22:26",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1063887": [
        {
            "ioc_value": "aryaarieash.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:18",
            "last_seen_utc": "2026-06-30 11:22:27",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1063888": [
        {
            "ioc_value": "aryalalexsh.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:18",
            "last_seen_utc": "2026-06-30 11:22:27",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1063870": [
        {
            "ioc_value": "dovaxanil.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:17",
            "last_seen_utc": "2026-06-30 11:22:25",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1063871": [
        {
            "ioc_value": "hehegahu.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:17",
            "last_seen_utc": "2026-06-30 11:22:25",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1063872": [
        {
            "ioc_value": "agriculturemachineries.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:17",
            "last_seen_utc": "2026-06-30 11:22:31",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1063873": [
        {
            "ioc_value": "arhipenkolenagenesh.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:17",
            "last_seen_utc": "2026-06-30 11:22:25",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1063874": [
        {
            "ioc_value": "aritmiagenesh.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:17",
            "last_seen_utc": "2026-06-30 11:22:25",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1063875": [
        {
            "ioc_value": "artes911sh.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:17",
            "last_seen_utc": "2026-06-30 11:22:25",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1063876": [
        {
            "ioc_value": "arthas89sh.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:17",
            "last_seen_utc": "2026-06-30 11:22:26",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1063877": [
        {
            "ioc_value": "arthurstevens62sh.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:17",
            "last_seen_utc": "2026-06-30 11:22:26",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1063878": [
        {
            "ioc_value": "arthurtaylor13sh.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:17",
            "last_seen_utc": "2026-06-30 11:22:26",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1063879": [
        {
            "ioc_value": "artis214sh.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:17",
            "last_seen_utc": "2026-06-30 11:22:26",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1063864": [
        {
            "ioc_value": "zipo-cons.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:16",
            "last_seen_utc": "2026-06-30 11:22:24",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1063865": [
        {
            "ioc_value": "fazehotafa.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:16",
            "last_seen_utc": "2026-06-30 11:22:24",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1063866": [
        {
            "ioc_value": "zendriol.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:16",
            "last_seen_utc": "2026-06-30 11:22:24",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1063867": [
        {
            "ioc_value": "sezezapa.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:16",
            "last_seen_utc": "2026-06-30 11:22:25",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1063868": [
        {
            "ioc_value": "sorekipe.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:16",
            "last_seen_utc": "2026-06-30 11:22:25",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1063869": [
        {
            "ioc_value": "zezinuwe.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:16",
            "last_seen_utc": "2026-06-30 11:22:25",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1063858": [
        {
            "ioc_value": "shrekf.art",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:15",
            "last_seen_utc": "2026-06-30 11:22:23",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1063859": [
        {
            "ioc_value": "amaniza.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:15",
            "last_seen_utc": "2026-06-30 11:22:23",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1063860": [
        {
            "ioc_value": "microcloud.pro",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:15",
            "last_seen_utc": "2026-06-30 11:22:23",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1063861": [
        {
            "ioc_value": "anexuss.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:15",
            "last_seen_utc": "2026-06-30 11:22:24",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1063862": [
        {
            "ioc_value": "edictsoft.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:15",
            "last_seen_utc": "2026-06-30 11:22:24",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1063863": [
        {
            "ioc_value": "out1etshops.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:15",
            "last_seen_utc": "2026-06-30 11:22:24",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1063851": [
        {
            "ioc_value": "stepnbayac.net",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:14",
            "last_seen_utc": "2026-06-30 11:22:22",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1063852": [
        {
            "ioc_value": "chickenpoken.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:14",
            "last_seen_utc": "2026-06-30 11:22:22",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1063853": [
        {
            "ioc_value": "hockeysmall.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:14",
            "last_seen_utc": "2026-06-30 11:22:22",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1063854": [
        {
            "ioc_value": "orthodoxok.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:14",
            "last_seen_utc": "2026-06-30 11:22:22",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1063855": [
        {
            "ioc_value": "cocesovo.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:14",
            "last_seen_utc": "2026-06-30 11:22:23",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1063856": [
        {
            "ioc_value": "familyinsurancepartner.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:14",
            "last_seen_utc": "2026-06-30 11:22:32",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1063857": [
        {
            "ioc_value": "senebuvuyi.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:14",
            "last_seen_utc": "2026-06-30 11:22:23",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1063848": [
        {
            "ioc_value": "fincheck.site",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:13",
            "last_seen_utc": "2026-06-30 11:22:21",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1063849": [
        {
            "ioc_value": "svchosst.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:13",
            "last_seen_utc": "2026-06-30 11:22:22",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1063850": [
        {
            "ioc_value": "conhosst.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:13",
            "last_seen_utc": "2026-06-30 11:22:22",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1063843": [
        {
            "ioc_value": "maximumservers.net",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:12",
            "last_seen_utc": "2026-06-30 11:22:29",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1063844": [
        {
            "ioc_value": "conferencedesk.net",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:12",
            "last_seen_utc": "2026-06-30 11:22:21",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1063845": [
        {
            "ioc_value": "bluetechsupply.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:12",
            "last_seen_utc": "2026-06-30 11:23:10",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1063846": [
        {
            "ioc_value": "allgroupservices.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:12",
            "last_seen_utc": "2026-06-30 11:22:22",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1063847": [
        {
            "ioc_value": "acitopram.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:12",
            "last_seen_utc": "2026-06-30 11:22:45",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1063838": [
        {
            "ioc_value": "businessservicesolution.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:11",
            "last_seen_utc": "2026-06-30 11:22:31",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1063839": [
        {
            "ioc_value": "gravyblicus.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:11",
            "last_seen_utc": "2026-06-30 11:23:03",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1063840": [
        {
            "ioc_value": "firmwarekey.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:11",
            "last_seen_utc": "2026-06-30 11:23:10",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1063841": [
        {
            "ioc_value": "updateraccount.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:11",
            "last_seen_utc": "2026-06-30 11:23:10",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1063842": [
        {
            "ioc_value": "mvnetworking.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:11",
            "last_seen_utc": "2026-06-30 11:23:10",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1063832": [
        {
            "ioc_value": "avasecurityservices.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:10",
            "last_seen_utc": "2026-06-30 11:22:24",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1063833": [
        {
            "ioc_value": "extranetserver.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:10",
            "last_seen_utc": "2026-06-30 11:22:24",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1063834": [
        {
            "ioc_value": "clacem.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:10",
            "last_seen_utc": "2026-06-30 11:22:18",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1063835": [
        {
            "ioc_value": "eonline-cdn.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:10",
            "last_seen_utc": "2026-06-30 11:22:18",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1063836": [
        {
            "ioc_value": "cagohufe.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:10",
            "last_seen_utc": "2026-06-30 11:22:18",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1063837": [
        {
            "ioc_value": "vezawahoy.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:10",
            "last_seen_utc": "2026-06-30 11:22:19",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1063826": [
        {
            "ioc_value": "tetafup.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:09",
            "last_seen_utc": "2026-06-30 11:22:17",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1063827": [
        {
            "ioc_value": "api-trend-micro.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:09",
            "last_seen_utc": "2026-06-30 11:22:17",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1063828": [
        {
            "ioc_value": "digital-hardware.net",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:09",
            "last_seen_utc": "2026-06-30 11:22:28",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1063829": [
        {
            "ioc_value": "aboutdatabasesoftware.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:09",
            "last_seen_utc": "2026-06-30 11:22:28",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1063830": [
        {
            "ioc_value": "high-control.net",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:09",
            "last_seen_utc": "2026-06-30 11:22:28",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1063831": [
        {
            "ioc_value": "soft-base.org",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:09",
            "last_seen_utc": "2026-06-30 11:22:28",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1063821": [
        {
            "ioc_value": "iptvr.icu",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:08",
            "last_seen_utc": "2026-06-30 11:22:16",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1063823": [
        {
            "ioc_value": "mingw.icu",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:08",
            "last_seen_utc": "2026-06-30 11:22:16",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1063824": [
        {
            "ioc_value": "transfercloud.net",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:08",
            "last_seen_utc": "2026-06-30 11:22:22",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1063825": [
        {
            "ioc_value": "flashcom.top",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:08",
            "last_seen_utc": "2026-06-30 11:22:22",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1063818": [
        {
            "ioc_value": "sciencelifedata.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:07",
            "last_seen_utc": "2026-06-30 11:22:15",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1063819": [
        {
            "ioc_value": "bookingsupport.online",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:07",
            "last_seen_utc": "2026-06-30 11:22:15",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1063820": [
        {
            "ioc_value": "ateyakima.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:07",
            "last_seen_utc": "2026-06-30 11:22:15",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1063813": [
        {
            "ioc_value": "buy1walmart.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:06",
            "last_seen_utc": "2026-06-30 11:22:13",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1063816": [
        {
            "ioc_value": "drbeat.icu",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:06",
            "last_seen_utc": "2026-06-30 11:22:14",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1063817": [
        {
            "ioc_value": "aialadin.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:06",
            "last_seen_utc": "2026-06-30 11:22:14",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1063810": [
        {
            "ioc_value": "hhkj222.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:05",
            "last_seen_utc": "2026-06-30 11:22:12",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1063811": [
        {
            "ioc_value": "yw2204.shop",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:05",
            "last_seen_utc": "2026-06-30 11:22:13",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1063812": [
        {
            "ioc_value": "nordicqlobal.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:05",
            "last_seen_utc": "2026-06-30 11:22:13",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1063806": [
        {
            "ioc_value": "favls.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:04",
            "last_seen_utc": "2026-06-30 11:22:11",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1063807": [
        {
            "ioc_value": "linkkedin.life",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:04",
            "last_seen_utc": "2026-06-30 11:22:11",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1063808": [
        {
            "ioc_value": "magellanfit.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:04",
            "last_seen_utc": "2026-06-30 11:22:11",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1063805": [
        {
            "ioc_value": "afspd.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:03",
            "last_seen_utc": "2026-06-30 11:22:11",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1063804": [
        {
            "ioc_value": "164.92.70.225:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:46:51",
            "last_seen_utc": "2026-06-30 11:22:46",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1063802": [
        {
            "ioc_value": "abritrum-bridges.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:44:07",
            "last_seen_utc": "2026-06-30 11:22:11",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1063208": [
        {
            "ioc_value": "a.wv2022.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-28 19:56:09",
            "last_seen_utc": "2026-06-30 11:22:11",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,TENCENT-NET-AP-CN Tencent Building Kejizhongyi Avenue",
            "anonymous": "0",
            "reporter": "drb_ra"
        }
    ],
    "1063123": [
        {
            "ioc_value": "apacheorg.wiki",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-28 02:22:09",
            "last_seen_utc": "2026-06-30 11:22:10",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CLOUDIE-AS-AP Cloudie Limited,CobaltStrike",
            "anonymous": "0",
            "reporter": "drb_ra"
        }
    ],
    "1062406": [
        {
            "ioc_value": "updatemicrotok.online",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-24 19:00:50",
            "last_seen_utc": "2026-06-30 11:22:10",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "AS-SERVERION,CobaltStrike",
            "anonymous": "0",
            "reporter": "drb_ra"
        }
    ],
    "1053949": [
        {
            "ioc_value": "eserverx.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-19 21:43:42",
            "last_seen_utc": "2026-06-30 11:22:11",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "AEZA-AS,CobaltStrike",
            "anonymous": "0",
            "reporter": "drb_ra"
        }
    ],
    "1050306": [
        {
            "ioc_value": "cmdatabase.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-19 11:41:44",
            "last_seen_utc": "2026-06-30 11:22:07",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ADM Service Ltd.,CobaltStrike",
            "anonymous": "0",
            "reporter": "drb_ra"
        }
    ],
    "1050198": [
        {
            "ioc_value": "cloudmane.online",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-17 12:12:59",
            "last_seen_utc": "2026-06-30 11:22:11",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,Partner LLC",
            "anonymous": "0",
            "reporter": "drb_ra"
        }
    ],
    "1036758": [
        {
            "ioc_value": "8.212.49.116:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-13 11:43:38",
            "last_seen_utc": "2026-06-30 11:21:47",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "Alibaba (US) Technology Co. Ltd.,CobaltStrike",
            "anonymous": "0",
            "reporter": "drb_ra"
        }
    ],
    "1036111": [
        {
            "ioc_value": "qw.conhoosst.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-12 01:38:31",
            "last_seen_utc": "2026-06-30 11:22:12",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,UAB Cherry Servers",
            "anonymous": "0",
            "reporter": "drb_ra"
        }
    ],
    "1035723": [
        {
            "ioc_value": "expoglobalservice.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-08 20:45:56",
            "last_seen_utc": "2026-06-30 11:22:12",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,TIER-NET",
            "anonymous": "0",
            "reporter": "drb_ra"
        }
    ],
    "1035558": [
        {
            "ioc_value": "www.microsofer.top",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-07 20:05:59",
            "last_seen_utc": "2026-06-30 11:22:16",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,Tencent Building Kejizhongyi Avenue",
            "anonymous": "0",
            "reporter": "drb_ra"
        }
    ],
    "1031731": [
        {
            "ioc_value": "googlecontentuser.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-05 20:03:53",
            "last_seen_utc": "2026-06-30 11:22:12",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://twitter.com/TheDFIRReport/status/1599780643222654976",
            "tags": "CobaltStrike",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1031726": [
        {
            "ioc_value": "test.227api.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-05 19:27:32",
            "last_seen_utc": "2026-06-30 11:21:59",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,YISUCLOUDLTD-HK YISU CLOUD LTD",
            "anonymous": "0",
            "reporter": "drb_ra"
        }
    ],
    "1029025": [
        {
            "ioc_value": "palalto.live",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-05 11:42:38",
            "last_seen_utc": "2026-06-30 11:22:13",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,Private Layer INC",
            "anonymous": "0",
            "reporter": "drb_ra"
        }
    ],
    "1028963": [
        {
            "ioc_value": "esoftwareupdates.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-04 20:18:27",
            "last_seen_utc": "2026-06-30 11:22:12",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ASGHOSTNET,CobaltStrike",
            "anonymous": "0",
            "reporter": "drb_ra"
        }
    ],
    "1028767": [
        {
            "ioc_value": "globalplayservices.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-02 21:28:11",
            "last_seen_utc": "2026-06-30 11:22:12",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CHERRYSERVERS3-AS,CobaltStrike",
            "anonymous": "0",
            "reporter": "drb_ra"
        }
    ],
    "1028737": [
        {
            "ioc_value": "rapidfinact.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-02 20:50:52",
            "last_seen_utc": "2026-06-30 11:22:13",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,SHINJIRU-MY-AS-AP Shinjiru Technology Sdn Bhd",
            "anonymous": "0",
            "reporter": "drb_ra"
        }
    ],
    "1028720": [
        {
            "ioc_value": "globalsteamclub.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-02 20:38:18",
            "last_seen_utc": "2026-06-30 11:22:12",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CHERRYSERVERS3-AS,CobaltStrike",
            "anonymous": "0",
            "reporter": "drb_ra"
        }
    ],
    "1028501": [
        {
            "ioc_value": "get-music-online.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-01 20:32:20",
            "last_seen_utc": "2026-06-30 11:22:12",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CHERRYSERVERS3-AS,CobaltStrike",
            "anonymous": "0",
            "reporter": "drb_ra"
        }
    ],
    "1024554": [
        {
            "ioc_value": "msndla.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-11-27 16:10:54",
            "last_seen_utc": "2026-06-30 11:22:12",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,PONYNET",
            "anonymous": "0",
            "reporter": "drb_ra"
        }
    ],
    "1023854": [
        {
            "ioc_value": "childhealthresources.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-11-24 11:54:46",
            "last_seen_utc": "2026-06-30 11:22:36",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "AMAZON-02,CobaltStrike",
            "anonymous": "0",
            "reporter": "drb_ra"
        }
    ],
    "1023821": [
        {
            "ioc_value": "360safeupdate.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-11-24 11:50:52",
            "last_seen_utc": "2026-06-30 11:22:11",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,Tencent Building Kejizhongyi Avenue",
            "anonymous": "0",
            "reporter": "drb_ra"
        }
    ],
    "1021044": [
        {
            "ioc_value": "aksaholdings.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-11-20 10:32:06",
            "last_seen_utc": "2026-06-30 11:22:13",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "Amazon.com Inc.,CobaltStrike",
            "anonymous": "0",
            "reporter": "drb_ra"
        }
    ],
    "1012628": [
        {
            "ioc_value": "msisfx.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-11-15 06:56:25",
            "last_seen_utc": "2026-06-30 11:22:14",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://twitter.com/malware_traffic/status/1592262598195646464",
            "tags": "CobaltStrike",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "1009773": [
        {
            "ioc_value": "get-smartbuyer.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-11-12 17:46:46",
            "last_seen_utc": "2026-06-30 11:22:13",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,UAB Cherry Servers",
            "anonymous": "0",
            "reporter": "drb_ra"
        }
    ],
    "1000509": [
        {
            "ioc_value": "qw.stakcl.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-11-10 11:51:33",
            "last_seen_utc": "2026-06-30 11:22:13",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,UAB Cherry Servers",
            "anonymous": "0",
            "reporter": "drb_ra"
        }
    ],
    "991420": [
        {
            "ioc_value": "sogouupdate.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-11-08 20:20:30",
            "last_seen_utc": "2026-06-30 11:22:11",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,TENCENT-NET-AP-CN Tencent Building Kejizhongyi Avenue",
            "anonymous": "0",
            "reporter": "drb_ra"
        }
    ],
    "985010": [
        {
            "ioc_value": "dnsupdatecheck.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-11-07 20:10:29",
            "last_seen_utc": "2026-06-30 11:22:13",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CHERRYSERVERS3-AS,CobaltStrike",
            "anonymous": "0",
            "reporter": "drb_ra"
        }
    ],
    "973832": [
        {
            "ioc_value": "ipulsecloud.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-11-04 11:23:08",
            "last_seen_utc": "2026-06-30 11:22:16",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,FLYSERVERS-ENDCLIENTS",
            "anonymous": "0",
            "reporter": "drb_ra"
        }
    ],
    "967402": [
        {
            "ioc_value": "glamspin360.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "win.qakbot",
            "malware_alias": "Oakboat,Pinkslipbot,Qbot,Quakbot",
            "malware_printable": "QakBot",
            "first_seen_utc": "2022-11-03 18:46:15",
            "last_seen_utc": "2026-06-30 06:03:09",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": null,
            "tags": "BB05,BV1,iso,qakbot,qbot,quakbot,tr,zip",
            "anonymous": "0",
            "reporter": "Cryptolaemus1"
        }
    ],
    "964538": [
        {
            "ioc_value": "zadiguser.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-11-03 12:12:17",
            "last_seen_utc": "2026-06-30 11:22:17",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": "",
            "tags": null,
            "anonymous": "1",
            "reporter": "_ik_"
        }
    ],
    "964540": [
        {
            "ioc_value": "wasazokiwo.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-11-03 12:12:17",
            "last_seen_utc": "2026-06-30 11:22:24",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": "",
            "tags": null,
            "anonymous": "1",
            "reporter": "_ik_"
        }
    ],
    "964541": [
        {
            "ioc_value": "yuwajeni.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-11-03 12:12:17",
            "last_seen_utc": "2026-06-30 11:22:18",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": "",
            "tags": null,
            "anonymous": "1",
            "reporter": "_ik_"
        }
    ],
    "964542": [
        {
            "ioc_value": "yavahiyil.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-11-03 12:12:17",
            "last_seen_utc": "2026-06-30 11:22:17",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": "",
            "tags": null,
            "anonymous": "1",
            "reporter": "_ik_"
        }
    ],
    "964543": [
        {
            "ioc_value": "rabihino.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-11-03 12:12:17",
            "last_seen_utc": "2026-06-30 11:22:29",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": "",
            "tags": null,
            "anonymous": "1",
            "reporter": "_ik_"
        }
    ],
    "964545": [
        {
            "ioc_value": "nokevohoh.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-11-03 12:12:17",
            "last_seen_utc": "2026-06-30 11:22:30",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": "",
            "tags": null,
            "anonymous": "1",
            "reporter": "_ik_"
        }
    ],
    "964546": [
        {
            "ioc_value": "rawocav.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-11-03 12:12:17",
            "last_seen_utc": "2026-06-30 11:22:30",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": "",
            "tags": null,
            "anonymous": "1",
            "reporter": "_ik_"
        }
    ],
    "964548": [
        {
            "ioc_value": "deyikurihe.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-11-03 12:12:17",
            "last_seen_utc": "2026-06-30 11:22:30",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": "",
            "tags": null,
            "anonymous": "1",
            "reporter": "_ik_"
        }
    ],
    "957395": [
        {
            "ioc_value": "hamzehkoumakli.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "win.qakbot",
            "malware_alias": "Oakboat,Pinkslipbot,Qbot,Quakbot",
            "malware_printable": "QakBot",
            "first_seen_utc": "2022-11-02 02:18:32",
            "last_seen_utc": "2026-06-30 06:03:07",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": null,
            "tags": "BB05,BV1,iso,qakbot,qbot,quakbot,tr,zip",
            "anonymous": "0",
            "reporter": "Cryptolaemus1"
        }
    ],
    "952862": [
        {
            "ioc_value": "freshuper.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-10-30 19:51:44",
            "last_seen_utc": "2026-06-30 11:22:14",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,tzulo inc.",
            "anonymous": "0",
            "reporter": "drb_ra"
        }
    ],
    "952596": [
        {
            "ioc_value": "reebons.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-10-29 12:32:13",
            "last_seen_utc": "2026-06-30 11:22:14",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,Perviy TSOD LLC",
            "anonymous": "0",
            "reporter": "drb_ra"
        }
    ],
    "952587": [
        {
            "ioc_value": "gaswert.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-10-29 12:23:49",
            "last_seen_utc": "2026-06-30 11:22:14",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,GLOBAL INTERNET SOLUTIONS LLC",
            "anonymous": "0",
            "reporter": "drb_ra"
        }
    ],
    "952582": [
        {
            "ioc_value": "sajij.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-10-29 11:54:42",
            "last_seen_utc": "2026-06-30 11:22:14",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,Perviy TSOD LLC",
            "anonymous": "0",
            "reporter": "drb_ra"
        }
    ],
    "952555": [
        {
            "ioc_value": "asasyz.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-10-29 10:14:36",
            "last_seen_utc": "2026-06-30 11:22:14",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,Partner LLC",
            "anonymous": "0",
            "reporter": "drb_ra"
        }
    ],
    "952552": [
        {
            "ioc_value": "agazud.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-10-29 10:12:26",
            "last_seen_utc": "2026-06-30 11:22:14",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,LLC Baxet",
            "anonymous": "0",
            "reporter": "drb_ra"
        }
    ],
    "952534": [
        {
            "ioc_value": "tuuik.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-10-29 09:57:36",
            "last_seen_utc": "2026-06-30 11:22:15",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,GLOBAL INTERNET SOLUTIONS LLC",
            "anonymous": "0",
            "reporter": "drb_ra"
        }
    ],
    "952528": [
        {
            "ioc_value": "alfuhin.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-10-29 09:56:46",
            "last_seen_utc": "2026-06-30 11:22:15",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,Partner LLC",
            "anonymous": "0",
            "reporter": "drb_ra"
        }
    ],
    "950974": [
        {
            "ioc_value": "amaladin.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-10-27 23:43:27",
            "last_seen_utc": "2026-06-30 11:22:14",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,HOSTKEY-USA",
            "anonymous": "0",
            "reporter": "drb_ra"
        }
    ],
    "949937": [
        {
            "ioc_value": "aualadin.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-10-26 10:09:11",
            "last_seen_utc": "2026-06-30 11:22:14",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,Perviy TSOD LLC",
            "anonymous": "0",
            "reporter": "drb_ra"
        }
    ],
    "916136": [
        {
            "ioc_value": "bthserv.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-10-23 13:42:10",
            "last_seen_utc": "2026-06-30 11:22:15",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,Internet Solutions & Innovations LTD.",
            "anonymous": "0",
            "reporter": "drb_ra"
        }
    ],
    "916115": [
        {
            "ioc_value": "nuesro.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-10-23 13:37:35",
            "last_seen_utc": "2026-06-30 11:22:15",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,Partner LLC",
            "anonymous": "0",
            "reporter": "drb_ra"
        }
    ],
    "916100": [
        {
            "ioc_value": "pasadonline.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-10-23 13:36:50",
            "last_seen_utc": "2026-06-30 11:22:13",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,UAB Cherry Servers",
            "anonymous": "0",
            "reporter": "drb_ra"
        }
    ],
    "915911": [
        {
            "ioc_value": "worldsgates.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-10-22 19:40:40",
            "last_seen_utc": "2026-06-30 11:22:16",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,LUCIDACLOUD LIMITED",
            "anonymous": "0",
            "reporter": "drb_ra"
        }
    ],
    "915908": [
        {
            "ioc_value": "protramal.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-10-22 19:39:30",
            "last_seen_utc": "2026-06-30 11:22:16",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,Perviy TSOD LLC",
            "anonymous": "0",
            "reporter": "drb_ra"
        }
    ],
    "915846": [
        {
            "ioc_value": "spltst.icu",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-10-22 01:11:02",
            "last_seen_utc": "2026-06-30 11:22:15",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,combahton GmbH",
            "anonymous": "0",
            "reporter": "drb_ra"
        }
    ],
    "891477": [
        {
            "ioc_value": "cehocihit.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-10-16 13:10:54",
            "last_seen_utc": "2026-06-30 11:22:25",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,LEASEWEB-USA-PHX",
            "anonymous": "0",
            "reporter": "drb_ra"
        }
    ],
    "891461": [
        {
            "ioc_value": "cloudmicro.pro",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-10-16 12:38:04",
            "last_seen_utc": "2026-06-30 11:22:23",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,PLI-AS",
            "anonymous": "0",
            "reporter": "drb_ra"
        }
    ],
    "887212": [
        {
            "ioc_value": "keycloud.live",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-10-13 21:41:28",
            "last_seen_utc": "2026-06-30 11:22:16",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,PARTNER-AS",
            "anonymous": "0",
            "reporter": "drb_ra"
        }
    ],
    "886703": [
        {
            "ioc_value": "activeservers.net",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-10-13 21:13:41",
            "last_seen_utc": "2026-06-30 11:22:28",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "Amati Foundation,CobaltStrike",
            "anonymous": "0",
            "reporter": "drb_ra"
        }
    ],
    "886693": [
        {
            "ioc_value": "newyearbalance.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-10-13 21:12:51",
            "last_seen_utc": "2026-06-30 11:22:16",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CHERRYSERVERS3-AS,CobaltStrike",
            "anonymous": "0",
            "reporter": "drb_ra"
        }
    ],
    "886516": [
        {
            "ioc_value": "xamayojir.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-10-13 21:02:36",
            "last_seen_utc": "2026-06-30 11:22:18",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,LEASEWEB-USA-PHX",
            "anonymous": "0",
            "reporter": "drb_ra"
        }
    ],
    "886499": [
        {
            "ioc_value": "xicefoga.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-10-13 20:58:25",
            "last_seen_utc": "2026-06-30 11:22:32",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,LEASEWEB-USA-WDC",
            "anonymous": "0",
            "reporter": "drb_ra"
        }
    ],
    "884091": [
        {
            "ioc_value": "ams-prd-cob.nl",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-10-13 19:51:56",
            "last_seen_utc": "2026-06-30 11:22:20",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,DIGITALOCEAN-ASN",
            "anonymous": "0",
            "reporter": "drb_ra"
        }
    ],
    "883488": [
        {
            "ioc_value": "tagujog.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-10-13 19:35:22",
            "last_seen_utc": "2026-06-30 11:22:19",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,LEASEWEB-USA-PHX",
            "anonymous": "0",
            "reporter": "drb_ra"
        }
    ],
    "883412": [
        {
            "ioc_value": "mysqlserver.org",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-10-13 19:32:23",
            "last_seen_utc": "2026-06-30 11:22:28",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,ICME",
            "anonymous": "0",
            "reporter": "drb_ra"
        }
    ],
    "883142": [
        {
            "ioc_value": "xuluxetas.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-10-13 19:23:44",
            "last_seen_utc": "2026-06-30 11:22:18",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,LEASEWEB-USA-NYC",
            "anonymous": "0",
            "reporter": "drb_ra"
        }
    ],
    "880419": [
        {
            "ioc_value": "hadujaza.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-10-12 17:16:11",
            "last_seen_utc": "2026-06-30 11:22:22",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://www.trendmicro.com/en_us/research/22/j/black-basta-infiltrates-networks-via-qakbot-brute-ratel-and-coba.html",
            "tags": "CobaltStrike",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "871733": [
        {
            "ioc_value": "softsupdate.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-10-05 18:54:33",
            "last_seen_utc": "2026-06-30 11:22:16",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://twitter.com/1ZRR4H/status/1577718910652129280",
            "tags": "CobaltStrike",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "871734": [
        {
            "ioc_value": "anushl.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-10-05 18:54:33",
            "last_seen_utc": "2026-06-30 11:22:16",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://twitter.com/1ZRR4H/status/1577718910652129280",
            "tags": "CobaltStrike",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "858399": [
        {
            "ioc_value": "anbush.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-09-29 08:45:45",
            "last_seen_utc": "2026-06-30 11:22:19",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://twitter.com/1ZRR4H/status/1575364140285267970",
            "tags": "CobaltStrike",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "858402": [
        {
            "ioc_value": "get-topservice.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-09-29 08:45:45",
            "last_seen_utc": "2026-06-30 11:22:17",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://twitter.com/1ZRR4H/status/1575364140285267970",
            "tags": "CobaltStrike",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "858403": [
        {
            "ioc_value": "msoftupdate.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-09-29 08:45:45",
            "last_seen_utc": "2026-06-30 11:22:17",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://twitter.com/1ZRR4H/status/1575364140285267970",
            "tags": "CobaltStrike",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "858404": [
        {
            "ioc_value": "pregabas.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-09-29 08:45:45",
            "last_seen_utc": "2026-06-30 11:22:17",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://twitter.com/1ZRR4H/status/1575364140285267970",
            "tags": "CobaltStrike",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "851096": [
        {
            "ioc_value": "34.92.131.12:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-09-22 11:26:18",
            "last_seen_utc": "2026-06-30 11:22:21",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,Google LLC",
            "anonymous": "0",
            "reporter": "drb_ra"
        }
    ],
    "850706": [
        {
            "ioc_value": "87.246.7.38:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-09-20 16:58:14",
            "last_seen_utc": "2026-06-30 11:22:21",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://twitter.com/1ZRR4H/status/1572261285139714051",
            "tags": "CobaltStrike",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "850701": [
        {
            "ioc_value": "cloudmicro.tech",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-09-20 16:57:02",
            "last_seen_utc": "2026-06-30 11:22:19",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://twitter.com/1ZRR4H/status/1572261285139714051",
            "tags": "CobaltStrike",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "850702": [
        {
            "ioc_value": "fregiyu.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-09-20 16:57:02",
            "last_seen_utc": "2026-06-30 11:22:20",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://twitter.com/1ZRR4H/status/1572261285139714051",
            "tags": "CobaltStrike",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "850704": [
        {
            "ioc_value": "microcloud.live",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-09-20 16:57:02",
            "last_seen_utc": "2026-06-30 11:22:19",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://twitter.com/1ZRR4H/status/1572261285139714051",
            "tags": "CobaltStrike",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "850260": [
        {
            "ioc_value": "154.22.117.31:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-09-17 21:24:41",
            "last_seen_utc": "2026-06-30 11:22:21",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,Cogent Communications",
            "anonymous": "0",
            "reporter": "drb_ra"
        }
    ],
    "849761": [
        {
            "ioc_value": "198.98.53.34:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-09-14 22:07:14",
            "last_seen_utc": "2026-06-30 11:22:21",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,PONYNET",
            "anonymous": "0",
            "reporter": "drb_ra"
        }
    ],
    "847988": [
        {
            "ioc_value": "globallookclub.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-09-05 19:10:52",
            "last_seen_utc": "2026-06-30 11:22:38",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": null,
            "anonymous": "0",
            "reporter": "_ik_"
        }
    ],
    "847986": [
        {
            "ioc_value": "realfunsolutions.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-09-05 19:10:50",
            "last_seen_utc": "2026-06-30 11:22:40",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": null,
            "anonymous": "0",
            "reporter": "_ik_"
        }
    ],
    "847972": [
        {
            "ioc_value": "www.service1app.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-09-05 19:10:48",
            "last_seen_utc": "2026-06-30 11:22:37",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": null,
            "anonymous": "0",
            "reporter": "_ik_"
        }
    ],
    "847975": [
        {
            "ioc_value": "youronlinesports.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-09-05 19:10:48",
            "last_seen_utc": "2026-06-30 11:22:37",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": null,
            "anonymous": "0",
            "reporter": "_ik_"
        }
    ],
    "847976": [
        {
            "ioc_value": "yourinfosolutions.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-09-05 19:10:48",
            "last_seen_utc": "2026-06-30 11:22:37",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": null,
            "anonymous": "0",
            "reporter": "_ik_"
        }
    ],
    "847978": [
        {
            "ioc_value": "login.onemusic24.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-09-05 19:10:48",
            "last_seen_utc": "2026-06-30 11:22:39",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": null,
            "anonymous": "0",
            "reporter": "_ik_"
        }
    ],
    "847981": [
        {
            "ioc_value": "zx.jacollans.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-09-05 19:10:48",
            "last_seen_utc": "2026-06-30 11:22:38",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": null,
            "anonymous": "0",
            "reporter": "_ik_"
        }
    ],
    "847942": [
        {
            "ioc_value": "satorkar.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-09-05 19:10:47",
            "last_seen_utc": "2026-06-30 11:22:29",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": null,
            "anonymous": "0",
            "reporter": "_ik_"
        }
    ],
    "847943": [
        {
            "ioc_value": "er.theinfoinc.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-09-05 19:10:47",
            "last_seen_utc": "2026-06-30 11:22:31",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": null,
            "anonymous": "0",
            "reporter": "_ik_"
        }
    ],
    "847957": [
        {
            "ioc_value": "realmacnow.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-09-05 19:10:47",
            "last_seen_utc": "2026-06-30 11:22:34",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": null,
            "anonymous": "0",
            "reporter": "_ik_"
        }
    ],
    "847958": [
        {
            "ioc_value": "onemusicllc.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-09-05 19:10:47",
            "last_seen_utc": "2026-06-30 11:22:34",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": null,
            "anonymous": "0",
            "reporter": "_ik_"
        }
    ],
    "847959": [
        {
            "ioc_value": "ateliernow.net",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-09-05 19:10:47",
            "last_seen_utc": "2026-06-30 11:22:34",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": null,
            "anonymous": "0",
            "reporter": "_ik_"
        }
    ],
    "847960": [
        {
            "ioc_value": "er.dropklant.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-09-05 19:10:47",
            "last_seen_utc": "2026-06-30 11:22:33",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": null,
            "anonymous": "0",
            "reporter": "_ik_"
        }
    ],
    "847929": [
        {
            "ioc_value": "sprinthunter.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-09-05 19:10:46",
            "last_seen_utc": "2026-06-30 11:22:24",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": null,
            "anonymous": "0",
            "reporter": "_ik_"
        }
    ],
    "847930": [
        {
            "ioc_value": "newstamagavk.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-09-05 19:10:46",
            "last_seen_utc": "2026-06-30 11:22:23",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": null,
            "anonymous": "0",
            "reporter": "_ik_"
        }
    ],
    "847934": [
        {
            "ioc_value": "www.onestepstar.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-09-05 19:10:46",
            "last_seen_utc": "2026-06-30 11:22:28",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": null,
            "anonymous": "0",
            "reporter": "_ik_"
        }
    ],
    "847124": [
        {
            "ioc_value": "115.75.66.68:7707",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2022-09-01 06:45:17",
            "last_seen_utc": "2026-06-30 10:43:18",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://bazaar.abuse.ch/sample/8f7649bc068b21404fe08229026859aaa468634963eca11cc64b661fa64a6880/",
            "tags": "asyncrat",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "847123": [
        {
            "ioc_value": "115.75.66.68:6821",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2022-09-01 06:45:16",
            "last_seen_utc": "2026-06-30 10:43:18",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://bazaar.abuse.ch/sample/8f7649bc068b21404fe08229026859aaa468634963eca11cc64b661fa64a6880/",
            "tags": "asyncrat",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "847122": [
        {
            "ioc_value": "115.75.66.68:6606",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2022-09-01 06:45:14",
            "last_seen_utc": "2026-06-30 10:43:18",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://bazaar.abuse.ch/sample/8f7649bc068b21404fe08229026859aaa468634963eca11cc64b661fa64a6880/",
            "tags": "asyncrat",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "847121": [
        {
            "ioc_value": "115.75.66.68:8808",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2022-09-01 06:40:24",
            "last_seen_utc": "2026-06-30 10:43:18",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,RAT",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "847028": [
        {
            "ioc_value": "barabezo.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-08-31 18:29:19",
            "last_seen_utc": "2026-06-30 11:22:25",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://bazaar.abuse.ch/sample/08ec3f13e8637a08dd763af6ccb46ff8516bc46efaacb1e5f052ada634a90c0e/",
            "tags": "CobaltStrike",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "847018": [
        {
            "ioc_value": "alojun.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-08-31 16:32:01",
            "last_seen_utc": "2026-06-30 11:22:23",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": null,
            "anonymous": "0",
            "reporter": "_ik_"
        }
    ],
    "847019": [
        {
            "ioc_value": "asdder.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-08-31 16:32:01",
            "last_seen_utc": "2026-06-30 11:22:23",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": null,
            "anonymous": "0",
            "reporter": "_ik_"
        }
    ],
    "847020": [
        {
            "ioc_value": "www.zominoz.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-08-31 16:32:01",
            "last_seen_utc": "2026-06-30 11:22:24",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": null,
            "anonymous": "0",
            "reporter": "_ik_"
        }
    ],
    "846258": [
        {
            "ioc_value": "jevomukif.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-08-30 06:22:11",
            "last_seen_utc": "2026-06-30 11:22:29",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://raw.githubusercontent.com/pan-unit42/tweets/master/2022-08-29-IOCs-for-Monster-Libra-TA551-IcedID-with-Cobalt-Stike.txt",
            "tags": "CobaltStrike",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "844214": [
        {
            "ioc_value": "msdnupdate.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-08-20 06:53:07",
            "last_seen_utc": "2026-06-30 11:22:29",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "CobaltStrike",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "844215": [
        {
            "ioc_value": "msdupdate.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-08-20 06:53:07",
            "last_seen_utc": "2026-06-30 11:22:30",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "CobaltStrike",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "843958": [
        {
            "ioc_value": "caxoxc.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-08-18 12:15:06",
            "last_seen_utc": "2026-06-30 11:22:31",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "CobaltStrike",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "843546": [
        {
            "ioc_value": "47.108.180.121:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-08-16 11:38:21",
            "last_seen_utc": "2026-06-30 11:21:45",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,Hangzhou Alibaba Advertising Co.Ltd.",
            "anonymous": "0",
            "reporter": "drb_ra"
        }
    ],
    "842464": [
        {
            "ioc_value": "jahojahi.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-08-11 06:03:19",
            "last_seen_utc": "2026-06-30 11:22:24",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://raw.githubusercontent.com/pan-unit42/tweets/master/2022-08-10-IOCs-for-IcedID-and-Cobalt-Strike.txt",
            "tags": "CobaltStrike",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "841613": [
        {
            "ioc_value": "zambeziz.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-08-06 07:00:06",
            "last_seen_utc": "2026-06-30 11:22:32",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "CobaltSrike",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "839793": [
        {
            "ioc_value": "zuyonijobo.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-07-27 08:49:04",
            "last_seen_utc": "2026-06-30 11:22:32",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://isc.sans.edu/diary/28884",
            "tags": "Cobalt Strike",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "802793": [
        {
            "ioc_value": "digerm.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-07-06 05:36:04",
            "last_seen_utc": "2026-06-30 11:22:35",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": null,
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "796822": [
        {
            "ioc_value": "chitozx.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-07-05 05:12:06",
            "last_seen_utc": "2026-06-30 11:22:35",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": null,
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "750750": [
        {
            "ioc_value": "42.192.21.181:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-07-02 13:06:49",
            "last_seen_utc": "2026-06-30 11:22:21",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike",
            "anonymous": "0",
            "reporter": "drb_ra"
        }
    ],
    "730561": [
        {
            "ioc_value": "18.117.254.165:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-06-28 08:57:21",
            "last_seen_utc": "2026-06-30 11:22:48",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "Amazon.com Inc.,CobaltStrike",
            "anonymous": "0",
            "reporter": "drb_ra"
        }
    ],
    "729038": [
        {
            "ioc_value": "blinkinuf.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-06-26 10:56:33",
            "last_seen_utc": "2026-06-30 11:22:35",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "Cobalt Strike",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "729037": [
        {
            "ioc_value": "malrok.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-06-26 10:56:32",
            "last_seen_utc": "2026-06-30 11:22:36",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "Cobalt Strike",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "720823": [
        {
            "ioc_value": "trumpiko.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-06-23 17:11:58",
            "last_seen_utc": "2026-06-30 11:22:37",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "Cobalt Strike",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "720824": [
        {
            "ioc_value": "freygor.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-06-23 17:11:58",
            "last_seen_utc": "2026-06-30 11:22:36",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "Cobalt Strike",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "720826": [
        {
            "ioc_value": "sinjoan.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-06-23 17:11:58",
            "last_seen_utc": "2026-06-30 11:22:39",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "Cobalt Strike",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "720827": [
        {
            "ioc_value": "afluix.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-06-23 17:11:58",
            "last_seen_utc": "2026-06-30 11:22:39",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "Cobalt Strike",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "720273": [
        {
            "ioc_value": "www.edge-chrome.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-06-23 10:54:20",
            "last_seen_utc": "2026-06-30 11:22:56",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": null,
            "tags": "Cobalt Strike",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "720276": [
        {
            "ioc_value": "www.hellomrsone.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-06-23 10:54:20",
            "last_seen_utc": "2026-06-30 11:23:11",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": null,
            "tags": "Cobalt Strike",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "720260": [
        {
            "ioc_value": "we.topsmartservice.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-06-23 10:54:19",
            "last_seen_utc": "2026-06-30 11:22:41",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": null,
            "tags": "Cobalt Strike",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "720263": [
        {
            "ioc_value": "wpsserver.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-06-23 10:54:19",
            "last_seen_utc": "2026-06-30 11:22:43",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": null,
            "tags": "Cobalt Strike",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "720248": [
        {
            "ioc_value": "thedaily-news.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-06-23 10:54:18",
            "last_seen_utc": "2026-06-30 11:22:41",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": null,
            "tags": "Cobalt Strike",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "720239": [
        {
            "ioc_value": "sevenhungredbucks.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-06-23 10:54:17",
            "last_seen_utc": "2026-06-30 11:22:38",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": null,
            "tags": "Cobalt Strike",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "720241": [
        {
            "ioc_value": "snccoupr-int.cf",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-06-23 10:54:17",
            "last_seen_utc": "2026-06-30 11:22:37",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": null,
            "tags": "Cobalt Strike",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "720247": [
        {
            "ioc_value": "telembank.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-06-23 10:54:17",
            "last_seen_utc": "2026-06-30 11:22:56",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": null,
            "tags": "Cobalt Strike",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "720230": [
        {
            "ioc_value": "ppew.au",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-06-23 10:54:16",
            "last_seen_utc": "2026-06-30 11:22:54",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": null,
            "tags": "Cobalt Strike",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "720231": [
        {
            "ioc_value": "pretunz.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-06-23 10:54:16",
            "last_seen_utc": "2026-06-30 11:22:41",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": null,
            "tags": "Cobalt Strike",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "720236": [
        {
            "ioc_value": "rss.top-business-blog.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-06-23 10:54:16",
            "last_seen_utc": "2026-06-30 11:22:42",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": null,
            "tags": "Cobalt Strike",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "720237": [
        {
            "ioc_value": "scarfaceserver.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-06-23 10:54:16",
            "last_seen_utc": "2026-06-30 11:22:40",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": null,
            "tags": "Cobalt Strike",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "720226": [
        {
            "ioc_value": "outlet-studio.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-06-23 10:54:15",
            "last_seen_utc": "2026-06-30 11:22:39",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": null,
            "tags": "Cobalt Strike",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "720208": [
        {
            "ioc_value": "js.msedgeupdate.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-06-23 10:54:14",
            "last_seen_utc": "2026-06-30 11:21:47",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": null,
            "tags": "Cobalt Strike",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "720198": [
        {
            "ioc_value": "harborfreight.delivery",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-06-23 10:54:13",
            "last_seen_utc": "2026-06-30 11:23:09",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": null,
            "tags": "Cobalt Strike",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "720201": [
        {
            "ioc_value": "hityok.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-06-23 10:54:13",
            "last_seen_utc": "2026-06-30 11:22:41",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": null,
            "tags": "Cobalt Strike",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "720203": [
        {
            "ioc_value": "jiguz.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-06-23 10:54:13",
            "last_seen_utc": "2026-06-30 11:22:40",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": null,
            "tags": "Cobalt Strike",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "720204": [
        {
            "ioc_value": "jijuanjo.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-06-23 10:54:13",
            "last_seen_utc": "2026-06-30 11:22:38",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": null,
            "tags": "Cobalt Strike",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "720206": [
        {
            "ioc_value": "jqueryupdatenow.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-06-23 10:54:13",
            "last_seen_utc": "2026-06-30 11:22:40",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": null,
            "tags": "Cobalt Strike",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "720207": [
        {
            "ioc_value": "jqueryupneed.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-06-23 10:54:13",
            "last_seen_utc": "2026-06-30 11:22:40",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": null,
            "tags": "Cobalt Strike",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "720188": [
        {
            "ioc_value": "fifacud.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-06-23 10:54:12",
            "last_seen_utc": "2026-06-30 11:22:38",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": null,
            "tags": "Cobalt Strike",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "720189": [
        {
            "ioc_value": "filaspo.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-06-23 10:54:12",
            "last_seen_utc": "2026-06-30 11:22:42",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": null,
            "tags": "Cobalt Strike",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "720193": [
        {
            "ioc_value": "gasienda.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-06-23 10:54:12",
            "last_seen_utc": "2026-06-30 11:22:42",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": null,
            "tags": "Cobalt Strike",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "720185": [
        {
            "ioc_value": "dreamkoks.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-06-23 10:54:11",
            "last_seen_utc": "2026-06-30 11:22:37",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": null,
            "tags": "Cobalt Strike",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "720176": [
        {
            "ioc_value": "democrazzy.net",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-06-23 10:54:10",
            "last_seen_utc": "2026-06-30 11:22:27",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": null,
            "tags": "Cobalt Strike",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "720156": [
        {
            "ioc_value": "cloud.sovarermscloud.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-06-23 10:53:31",
            "last_seen_utc": "2026-06-30 11:22:42",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": null,
            "tags": "Cobalt Strike",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "720136": [
        {
            "ioc_value": "backupcreds.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-06-23 10:53:28",
            "last_seen_utc": "2026-06-30 11:22:44",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": null,
            "tags": "Cobalt Strike",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "720140": [
        {
            "ioc_value": "biohazzzard.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-06-23 10:53:28",
            "last_seen_utc": "2026-06-30 11:22:41",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": null,
            "tags": "Cobalt Strike",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "720141": [
        {
            "ioc_value": "bksfinance.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-06-23 10:53:28",
            "last_seen_utc": "2026-06-30 11:22:59",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": null,
            "tags": "Cobalt Strike",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "720143": [
        {
            "ioc_value": "boronab.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-06-23 10:53:28",
            "last_seen_utc": "2026-06-30 11:22:40",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": null,
            "tags": "Cobalt Strike",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "720132": [
        {
            "ioc_value": "araizx.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-06-23 10:53:27",
            "last_seen_utc": "2026-06-30 11:22:37",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": null,
            "tags": "Cobalt Strike",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "720133": [
        {
            "ioc_value": "arminext.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-06-23 10:53:27",
            "last_seen_utc": "2026-06-30 11:22:42",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": null,
            "tags": "Cobalt Strike",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "720058": [
        {
            "ioc_value": "121.41.101.90:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-06-23 10:47:03",
            "last_seen_utc": "2026-06-30 10:46:41",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "Cobalt Strike",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "719898": [
        {
            "ioc_value": "aginij.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-06-22 18:35:13",
            "last_seen_utc": "2026-06-30 11:22:38",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "Cobalt Strike",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "606362": [
        {
            "ioc_value": "criobob.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-05-19 18:01:58",
            "last_seen_utc": "2026-06-30 11:22:43",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "cobaltstrike,emotet",
            "anonymous": "0",
            "reporter": "Cryptolaemus1"
        }
    ],
    "606363": [
        {
            "ioc_value": "prozakx.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-05-19 18:01:58",
            "last_seen_utc": "2026-06-30 11:22:43",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "cobaltstrike,emotet",
            "anonymous": "0",
            "reporter": "Cryptolaemus1"
        }
    ],
    "606364": [
        {
            "ioc_value": "terroklo.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-05-19 18:01:58",
            "last_seen_utc": "2026-06-30 11:22:42",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "cobaltstrike,emotet",
            "anonymous": "0",
            "reporter": "Cryptolaemus1"
        }
    ],
    "606360": [
        {
            "ioc_value": "microdozz.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-05-19 18:01:57",
            "last_seen_utc": "2026-06-30 11:22:43",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "cobaltstrike,emotet",
            "anonymous": "0",
            "reporter": "Cryptolaemus1"
        }
    ],
    "549372": [
        {
            "ioc_value": "us189-hpgsgae5dva9fzch.z01.azurefd.net",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-05-10 18:53:07",
            "last_seen_utc": "2026-06-30 11:22:53",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "cobaltstrike,threatview.io",
            "anonymous": "0",
            "reporter": "Malwar3Ninja"
        }
    ],
    "548951": [
        {
            "ioc_value": "artidomain.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-05-08 16:20:03",
            "last_seen_utc": "2026-06-30 11:22:45",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://twitter.com/ian_kenefick/status/1523288477559062529",
            "tags": "Cobalt Strike",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "544836": [
        {
            "ioc_value": "116.62.185.223:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-04-30 19:45:18",
            "last_seen_utc": "2026-06-30 11:22:46",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ALIBABA-CN-NET Hangzhou Alibaba Advertising Co.Ltd.,CobaltStrike",
            "anonymous": "0",
            "reporter": "drb_ra"
        }
    ],
    "540702": [
        {
            "ioc_value": "165.227.180.6:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-04-29 19:30:18",
            "last_seen_utc": "2026-06-30 11:22:51",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,DIGITALOCEAN-ASN",
            "anonymous": "0",
            "reporter": "drb_ra"
        }
    ],
    "532916": [
        {
            "ioc_value": "120.26.240.21:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-04-25 12:31:07",
            "last_seen_utc": "2026-06-30 11:22:55",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ALIBABA-CN-NET Hangzhou Alibaba Advertising Co.Ltd.,CobaltStrike",
            "anonymous": "0",
            "reporter": "drb_ra"
        }
    ],
    "530098": [
        {
            "ioc_value": "193.29.13.216:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-04-23 16:42:50",
            "last_seen_utc": "2026-06-30 11:22:56",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "***************************************,CobaltStrike",
            "anonymous": "0",
            "reporter": "drb_ra"
        }
    ],
    "523516": [
        {
            "ioc_value": "45.8.158.25:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-04-21 16:54:57",
            "last_seen_utc": "2026-06-30 11:22:47",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ASBAXETN,CobaltStrike",
            "anonymous": "0",
            "reporter": "drb_ra"
        }
    ],
    "521565": [
        {
            "ioc_value": "115.29.171.175:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-04-19 13:44:33",
            "last_seen_utc": "2026-06-30 11:22:55",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CNNIC-ALIBABA-CN-NET-AP Hangzhou Alibaba Advertising Co.Ltd.,CobaltStrike",
            "anonymous": "0",
            "reporter": "drb_ra"
        }
    ],
    "521083": [
        {
            "ioc_value": "84.32.188.190:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-04-18 18:01:52",
            "last_seen_utc": "2026-06-30 11:22:46",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,UAB Cherry Servers",
            "anonymous": "0",
            "reporter": "drb_ra"
        }
    ],
    "520317": [
        {
            "ioc_value": "137.184.42.85:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-04-15 22:57:51",
            "last_seen_utc": "2026-06-30 11:22:53",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,DIGITALOCEAN-ASN",
            "anonymous": "0",
            "reporter": "drb_ra"
        }
    ],
    "519914": [
        {
            "ioc_value": "84.32.188.104:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-04-14 16:59:25",
            "last_seen_utc": "2026-06-30 11:22:48",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,UAB Cherry Servers",
            "anonymous": "0",
            "reporter": "drb_ra"
        }
    ],
    "519792": [
        {
            "ioc_value": "furfen.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-04-14 10:30:57",
            "last_seen_utc": "2026-06-30 11:22:44",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "BumbleBee,Cobalt Strike",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "519116": [
        {
            "ioc_value": "175.41.21.29:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-04-13 16:57:52",
            "last_seen_utc": "2026-06-30 11:22:50",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,XLC-AS-AP XLC GLOBAL",
            "anonymous": "0",
            "reporter": "drb_ra"
        }
    ],
    "518853": [
        {
            "ioc_value": "175.41.16.98:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-04-12 16:50:58",
            "last_seen_utc": "2026-06-30 11:22:56",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,XLC-AS-AP XLC GLOBAL",
            "anonymous": "0",
            "reporter": "drb_ra"
        }
    ],
    "518404": [
        {
            "ioc_value": "138.68.110.227:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-04-10 17:05:31",
            "last_seen_utc": "2026-06-30 11:22:51",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,DIGITALOCEAN-ASN",
            "anonymous": "0",
            "reporter": "drb_ra"
        }
    ],
    "516676": [
        {
            "ioc_value": "13.55.118.253:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-04-06 22:59:35",
            "last_seen_utc": "2026-06-30 11:22:47",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "AMAZON-02,CobaltStrike",
            "anonymous": "0",
            "reporter": "drb_ra"
        }
    ],
    "493695": [
        {
            "ioc_value": "185.186.143.111:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-04-05 22:55:20",
            "last_seen_utc": "2026-06-30 11:22:47",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ASKONTEL,CobaltStrike",
            "anonymous": "0",
            "reporter": "drb_ra"
        }
    ],
    "492845": [
        {
            "ioc_value": "194.37.97.153:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-04-05 16:53:16",
            "last_seen_utc": "2026-06-30 11:23:12",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,M247 Ltd",
            "anonymous": "0",
            "reporter": "drb_ra"
        }
    ],
    "466600": [
        {
            "ioc_value": "blopik.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-03-30 09:51:36",
            "last_seen_utc": "2026-06-30 11:22:59",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "Cobalt Strike",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "461231": [
        {
            "ioc_value": "borizhog.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-03-29 08:36:59",
            "last_seen_utc": "2026-06-30 11:22:59",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": "0",
            "reporter": "stoerchl"
        }
    ],
    "448027": [
        {
            "ioc_value": "37.72.172.110:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-03-24 22:55:12",
            "last_seen_utc": "2026-06-30 11:22:48",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,HVC-AS",
            "anonymous": "0",
            "reporter": "drb_ra"
        }
    ],
    "446029": [
        {
            "ioc_value": "1.14.76.111:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-03-24 10:56:07",
            "last_seen_utc": "2026-06-30 11:22:52",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike",
            "anonymous": "0",
            "reporter": "drb_ra"
        }
    ],
    "443786": [
        {
            "ioc_value": "139.60.160.8:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-03-23 20:44:05",
            "last_seen_utc": "2026-06-30 11:22:49",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,HOSTKEY-USA",
            "anonymous": "0",
            "reporter": "drb_ra"
        }
    ],
    "443190": [
        {
            "ioc_value": "apeduze.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-03-23 16:44:21",
            "last_seen_utc": "2026-06-30 11:22:45",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": "0",
            "reporter": "stoerchl"
        }
    ],
    "438442": [
        {
            "ioc_value": "drimzis.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-03-22 10:51:28",
            "last_seen_utc": "2026-06-30 11:23:04",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": "0",
            "reporter": "stoerchl"
        }
    ],
    "438443": [
        {
            "ioc_value": "blinkij.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-03-22 10:51:28",
            "last_seen_utc": "2026-06-30 11:22:58",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": "0",
            "reporter": "stoerchl"
        }
    ],
    "398650": [
        {
            "ioc_value": "152.136.178.142:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-03-17 22:47:07",
            "last_seen_utc": "2026-06-30 11:22:56",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike",
            "anonymous": "0",
            "reporter": "drb_ra"
        }
    ],
    "396104": [
        {
            "ioc_value": "dunclikf.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-03-17 12:19:46",
            "last_seen_utc": "2026-06-30 11:23:06",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "Cobalt Strike",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "393426": [
        {
            "ioc_value": "sifgu.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-03-10 15:29:52",
            "last_seen_utc": "2026-06-30 11:22:58",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": "0",
            "reporter": "stoerchl"
        }
    ],
    "393427": [
        {
            "ioc_value": "gfsert.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-03-10 15:29:52",
            "last_seen_utc": "2026-06-30 11:22:58",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": "0",
            "reporter": "stoerchl"
        }
    ],
    "393429": [
        {
            "ioc_value": "shizij.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-03-10 15:29:52",
            "last_seen_utc": "2026-06-30 11:23:05",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": "0",
            "reporter": "stoerchl"
        }
    ],
    "393430": [
        {
            "ioc_value": "zxerm.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-03-10 15:29:52",
            "last_seen_utc": "2026-06-30 11:23:06",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": "0",
            "reporter": "stoerchl"
        }
    ],
    "393431": [
        {
            "ioc_value": "korunder.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-03-10 15:29:52",
            "last_seen_utc": "2026-06-30 11:23:06",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": "0",
            "reporter": "stoerchl"
        }
    ],
    "393424": [
        {
            "ioc_value": "chesft.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-03-10 15:29:51",
            "last_seen_utc": "2026-06-30 11:23:04",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": "0",
            "reporter": "stoerchl"
        }
    ],
    "393425": [
        {
            "ioc_value": "uktyl.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-03-10 15:29:51",
            "last_seen_utc": "2026-06-30 11:22:58",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": "0",
            "reporter": "stoerchl"
        }
    ],
    "393312": [
        {
            "ioc_value": "defenr.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-03-09 17:18:35",
            "last_seen_utc": "2026-06-30 11:23:04",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "Cobalt Strike",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "393313": [
        {
            "ioc_value": "fedij.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-03-09 17:18:35",
            "last_seen_utc": "2026-06-30 11:23:04",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "Cobalt Strike",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "393314": [
        {
            "ioc_value": "kejimn.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-03-09 17:18:35",
            "last_seen_utc": "2026-06-30 11:23:05",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "Cobalt Strike",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "393311": [
        {
            "ioc_value": "brikeb.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-03-09 17:18:34",
            "last_seen_utc": "2026-06-30 11:23:04",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "Cobalt Strike",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "393046": [
        {
            "ioc_value": "kapuleti.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-03-08 17:09:32",
            "last_seen_utc": "2026-06-30 11:23:04",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "Cobalt Strike",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "392705": [
        {
            "ioc_value": "45.12.1.24:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-03-06 16:43:33",
            "last_seen_utc": "2026-06-30 11:22:54",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,YURTEH-AS",
            "anonymous": "0",
            "reporter": "drb_ra"
        }
    ],
    "392630": [
        {
            "ioc_value": "45.12.1.25:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-03-05 16:45:53",
            "last_seen_utc": "2026-06-30 11:22:46",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,YURTEH-AS",
            "anonymous": "0",
            "reporter": "drb_ra"
        }
    ],
    "392595": [
        {
            "ioc_value": "45.12.1.26:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-03-05 16:43:28",
            "last_seen_utc": "2026-06-30 11:22:47",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CLOUDNETWORKS-AS,CobaltStrike",
            "anonymous": "0",
            "reporter": "drb_ra"
        }
    ],
    "391528": [
        {
            "ioc_value": "defegh.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-03-01 07:06:28",
            "last_seen_utc": "2026-06-30 11:23:05",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "Cobalt Strike",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "391530": [
        {
            "ioc_value": "klycnmik.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-03-01 07:06:28",
            "last_seen_utc": "2026-06-30 11:23:05",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "Cobalt Strike",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "391531": [
        {
            "ioc_value": "ngrety.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-03-01 07:06:28",
            "last_seen_utc": "2026-06-30 11:23:05",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "Cobalt Strike",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "391111": [
        {
            "ioc_value": "lifegothistory.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-02-27 06:03:58",
            "last_seen_utc": "2026-06-30 11:23:06",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://twitter.com/1ZRR4H/status/1497771037718724612",
            "tags": "Cobalt Strike",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "390123": [
        {
            "ioc_value": "192.241.133.130:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-02-22 16:44:41",
            "last_seen_utc": "2026-06-30 11:23:01",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,DIGITALOCEAN-ASN",
            "anonymous": "0",
            "reporter": "drb_ra"
        }
    ],
    "390104": [
        {
            "ioc_value": "159.65.246.188:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-02-22 16:42:29",
            "last_seen_utc": "2026-06-30 11:23:01",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,DIGITALOCEAN-ASN",
            "anonymous": "0",
            "reporter": "drb_ra"
        }
    ],
    "389873": [
        {
            "ioc_value": "68.183.200.63:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-02-21 16:58:18",
            "last_seen_utc": "2026-06-30 11:23:00",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,DIGITALOCEAN-ASN",
            "anonymous": "0",
            "reporter": "drb_ra"
        }
    ],
    "389866": [
        {
            "ioc_value": "138.68.227.71:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-02-21 16:57:13",
            "last_seen_utc": "2026-06-30 11:23:00",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,DIGITALOCEAN-ASN",
            "anonymous": "0",
            "reporter": "drb_ra"
        }
    ],
    "389865": [
        {
            "ioc_value": "165.227.219.211:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-02-21 16:56:32",
            "last_seen_utc": "2026-06-30 11:23:00",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,DIGITALOCEAN-ASN",
            "anonymous": "0",
            "reporter": "drb_ra"
        }
    ],
    "389864": [
        {
            "ioc_value": "165.232.154.73:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-02-21 16:55:44",
            "last_seen_utc": "2026-06-30 11:23:01",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,DIGITALOCEAN-ASN",
            "anonymous": "0",
            "reporter": "drb_ra"
        }
    ],
    "389861": [
        {
            "ioc_value": "143.198.110.248:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-02-21 16:54:53",
            "last_seen_utc": "2026-06-30 11:23:00",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,DIGITALOCEAN-ASN",
            "anonymous": "0",
            "reporter": "drb_ra"
        }
    ],
    "389860": [
        {
            "ioc_value": "178.128.171.206:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-02-21 16:54:15",
            "last_seen_utc": "2026-06-30 11:23:02",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,DIGITALOCEAN-ASN",
            "anonymous": "0",
            "reporter": "drb_ra"
        }
    ],
    "389853": [
        {
            "ioc_value": "165.227.23.218:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-02-21 16:53:10",
            "last_seen_utc": "2026-06-30 11:23:00",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,DIGITALOCEAN-ASN",
            "anonymous": "0",
            "reporter": "drb_ra"
        }
    ],
    "389850": [
        {
            "ioc_value": "161.35.137.163:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-02-21 16:52:19",
            "last_seen_utc": "2026-06-30 11:23:01",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,DIGITALOCEAN-ASN",
            "anonymous": "0",
            "reporter": "drb_ra"
        }
    ],
    "389847": [
        {
            "ioc_value": "64.227.0.177:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-02-21 16:51:26",
            "last_seen_utc": "2026-06-30 11:23:02",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,DIGITALOCEAN-ASN",
            "anonymous": "0",
            "reporter": "drb_ra"
        }
    ],
    "389656": [
        {
            "ioc_value": "45.55.36.143:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-02-20 16:42:59",
            "last_seen_utc": "2026-06-30 11:23:00",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,DIGITALOCEAN-ASN",
            "anonymous": "0",
            "reporter": "drb_ra"
        }
    ],
    "384626": [
        {
            "ioc_value": "168.61.180.98:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-02-09 22:36:37",
            "last_seen_utc": "2026-06-30 11:23:12",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,MICROSOFT-CORP-MSN-AS-BLOCK",
            "anonymous": "0",
            "reporter": "drb_ra"
        }
    ],
    "373668": [
        {
            "ioc_value": "bornometa.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-02-01 10:45:03",
            "last_seen_utc": "2026-06-30 11:23:07",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://twitter.com/1ZRR4H/status/1488311508652204037",
            "tags": "Cobalt Strike",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "373671": [
        {
            "ioc_value": "jenevabaiden.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-02-01 10:45:03",
            "last_seen_utc": "2026-06-30 11:23:13",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://twitter.com/1ZRR4H/status/1488311508652204037",
            "tags": "Cobalt Strike",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "373673": [
        {
            "ioc_value": "sbronm.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-02-01 10:45:03",
            "last_seen_utc": "2026-06-30 11:23:07",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://twitter.com/1ZRR4H/status/1488311508652204037",
            "tags": "Cobalt Strike",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "362296": [
        {
            "ioc_value": "101.34.182.130:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-01-29 22:33:30",
            "last_seen_utc": "2026-06-30 11:22:56",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike",
            "anonymous": "0",
            "reporter": "drb_ra"
        }
    ],
    "332687": [
        {
            "ioc_value": "192.227.155.185:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-01-25 22:30:16",
            "last_seen_utc": "2026-06-30 11:22:49",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "AS-COLOCROSSING,CobaltStrike",
            "anonymous": "0",
            "reporter": "drb_ra"
        }
    ],
    "332653": [
        {
            "ioc_value": "146.70.29.233:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-01-25 22:29:00",
            "last_seen_utc": "2026-06-30 11:22:50",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,M247",
            "anonymous": "0",
            "reporter": "drb_ra"
        }
    ],
    "313943": [
        {
            "ioc_value": "107.172.219.129:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-01-22 22:25:42",
            "last_seen_utc": "2026-06-30 11:22:50",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "AS-COLOCROSSING,CobaltStrike",
            "anonymous": "0",
            "reporter": "drb_ra"
        }
    ],
    "299262": [
        {
            "ioc_value": "193.201.9.229:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-01-18 22:32:52",
            "last_seen_utc": "2026-06-30 11:23:12",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,SELECTEL",
            "anonymous": "0",
            "reporter": "drb_ra"
        }
    ],
    "298501": [
        {
            "ioc_value": "citrixseruritys.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-01-18 13:51:16",
            "last_seen_utc": "2026-06-30 11:23:11",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://twitter.com/MichalKoczwara/status/1483137082465865729",
            "tags": "Cobalt Strike",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "298505": [
        {
            "ioc_value": "milanvar.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-01-18 13:51:16",
            "last_seen_utc": "2026-06-30 11:23:13",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://twitter.com/MichalKoczwara/status/1483137082465865729",
            "tags": "Cobalt Strike",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "295525": [
        {
            "ioc_value": "23.227.198.246:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-01-15 22:26:20",
            "last_seen_utc": "2026-06-30 11:23:11",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,HVC-AS",
            "anonymous": "0",
            "reporter": "drb_ra"
        }
    ],
    "295436": [
        {
            "ioc_value": "217.79.243.148:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-01-15 10:32:22",
            "last_seen_utc": "2026-06-30 11:23:11",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,HVC-AS",
            "anonymous": "0",
            "reporter": "drb_ra"
        }
    ],
    "295353": [
        {
            "ioc_value": "149.255.35.131:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-01-14 22:28:25",
            "last_seen_utc": "2026-06-30 11:23:12",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,HVC-AS",
            "anonymous": "0",
            "reporter": "drb_ra"
        }
    ],
    "294999": [
        {
            "ioc_value": "81.68.225.136:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-01-13 22:28:33",
            "last_seen_utc": "2026-06-30 11:22:49",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike",
            "anonymous": "0",
            "reporter": "drb_ra"
        }
    ],
    "292303": [
        {
            "ioc_value": "39.98.48.153:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-01-10 16:24:49",
            "last_seen_utc": "2026-06-30 11:21:09",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ALIBABA-CN-NET Hangzhou Alibaba Advertising Co.Ltd.,CobaltStrike",
            "anonymous": "0",
            "reporter": "drb_ra"
        }
    ],
    "291740": [
        {
            "ioc_value": "39.104.25.164:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-01-07 10:30:52",
            "last_seen_utc": "2026-06-30 11:22:52",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ALIBABA-CN-NET Hangzhou Alibaba Advertising Co.Ltd.,CobaltStrike",
            "anonymous": "0",
            "reporter": "drb_ra"
        }
    ],
    "276593": [
        {
            "ioc_value": "77.83.36.54:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2021-12-16 10:42:30",
            "last_seen_utc": "2026-06-30 11:22:55",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,ISI-ASN",
            "anonymous": "0",
            "reporter": "drb_ra"
        }
    ],
    "275144": [
        {
            "ioc_value": "101.32.204.81:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2021-12-13 10:06:28",
            "last_seen_utc": "2026-06-30 11:22:54",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,TENCENT-NET-AP-CN Tencent Building Kejizhongyi Avenue",
            "anonymous": "0",
            "reporter": "drb_ra"
        }
    ],
    "252110": [
        {
            "ioc_value": "62.113.255.12:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2021-11-22 16:01:01",
            "last_seen_utc": "2026-06-30 11:22:51",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,TTM",
            "anonymous": "0",
            "reporter": "drb_ra"
        }
    ],
    "242948": [
        {
            "ioc_value": "107.173.89.148:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2021-11-04 17:48:48",
            "last_seen_utc": "2026-06-30 11:22:53",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "AS-COLOCROSSING,CobaltStrike",
            "anonymous": "0",
            "reporter": "drb_ra"
        }
    ],
    "240983": [
        {
            "ioc_value": "104.128.92.144:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2021-10-31 17:43:37",
            "last_seen_utc": "2026-06-30 11:23:12",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,IT7NET",
            "anonymous": "0",
            "reporter": "drb_ra"
        }
    ],
    "238207": [
        {
            "ioc_value": "fivepointschiro.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2021-10-27 09:58:20",
            "last_seen_utc": "2026-06-30 11:23:07",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://twitter.com/mojoesec/status/1453040284686770185",
            "tags": "CobaltStrike",
            "anonymous": "0",
            "reporter": "abuse_ch"
        }
    ],
    "236436": [
        {
            "ioc_value": "111.230.196.200:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2021-10-22 12:07:15",
            "last_seen_utc": "2026-06-30 11:22:52",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike",
            "anonymous": "0",
            "reporter": "drb_ra"
        }
    ],
    "233476": [
        {
            "ioc_value": "23.224.152.139:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2021-10-13 17:43:22",
            "last_seen_utc": "2026-06-30 11:22:50",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CNSERVERS,CobaltStrike",
            "anonymous": "0",
            "reporter": "drb_ra"
        }
    ],
    "232821": [
        {
            "ioc_value": "139.198.183.44:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2021-10-11 23:27:10",
            "last_seen_utc": "2026-06-30 11:22:52",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,YUNIFY-NET Yunify Technologies Inc.",
            "anonymous": "0",
            "reporter": "drb_ra"
        }
    ],
    "232263": [
        {
            "ioc_value": "121.37.255.60:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2021-10-09 23:36:53",
            "last_seen_utc": "2026-06-30 11:22:56",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,HWCSNET Huawei Cloud Service data center",
            "anonymous": "0",
            "reporter": "drb_ra"
        }
    ],
    "223357": [
        {
            "ioc_value": "47.95.207.79:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2021-09-18 17:39:24",
            "last_seen_utc": "2026-06-30 11:22:54",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CNNIC-ALIBABA-CN-NET-AP Hangzhou Alibaba Advertising Co.Ltd.,CobaltStrike",
            "anonymous": "0",
            "reporter": "drb_ra"
        }
    ]
}